Vercel Composition Patterns
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
Operate CC Safety Net: explain why a command was blocked, triage false positives, configure custom rulebooks, manage agent CLI integrations, and diagnose protection.
$ npx skills add kenryu42/cc-safety-net --skill cc-safety-net -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kenryu42/cc-safety-net cc-safety-net --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kenryu42/cc-safety-net.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cc-safety-net .claude/skills/cc-safety-net && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cc-safety-net" agent skill from https://github.com/kenryu42/cc-safety-net/tree/main/skills/cc-safety-net into .claude/skills/cc-safety-net/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cc-safety-net", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kenryu42/cc-safety-net/tree/main/skills/cc-safety-netType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kenryu42/cc-safety-net --skill cc-safety-net -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kenryu42/cc-safety-net cc-safety-net --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kenryu42/cc-safety-net.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cc-safety-net .agents/skills/cc-safety-net && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cc-safety-net" agent skill from https://github.com/kenryu42/cc-safety-net/tree/main/skills/cc-safety-net into .agents/skills/cc-safety-net/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cc-safety-net", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kenryu42/cc-safety-net --skill cc-safety-net -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kenryu42/cc-safety-net cc-safety-net --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kenryu42/cc-safety-net.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cc-safety-net .cursor/skills/cc-safety-net && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cc-safety-net" agent skill from https://github.com/kenryu42/cc-safety-net/tree/main/skills/cc-safety-net into .cursor/skills/cc-safety-net/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cc-safety-net", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kenryu42/cc-safety-net.git --path skills/cc-safety-net--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kenryu42/cc-safety-net --skill cc-safety-net -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kenryu42/cc-safety-net cc-safety-net --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kenryu42/cc-safety-net.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cc-safety-net .gemini/skills/cc-safety-net && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cc-safety-net" agent skill from https://github.com/kenryu42/cc-safety-net/tree/main/skills/cc-safety-net into .gemini/skills/cc-safety-net/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cc-safety-net", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kenryu42/cc-safety-net cc-safety-netInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kenryu42/cc-safety-net --skill cc-safety-net -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kenryu42/cc-safety-net.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cc-safety-net .github/skills/cc-safety-net && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cc-safety-net" agent skill from https://github.com/kenryu42/cc-safety-net/tree/main/skills/cc-safety-net into .github/skills/cc-safety-net/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cc-safety-net", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kenryu42/cc-safety-net --skill cc-safety-net -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kenryu42/cc-safety-net cc-safety-net --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kenryu42/cc-safety-net.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cc-safety-net .opencode/skills/cc-safety-net && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cc-safety-net" agent skill from https://github.com/kenryu42/cc-safety-net/tree/main/skills/cc-safety-net into .opencode/skills/cc-safety-net/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cc-safety-net", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cc-safety-netOperate CC Safety Net: explain why a command was blocked, triage false positives, configure custom rulebooks, manage agent CLI integrations, and diagnose protection.
Cc Safety Net is an agent skill from kenryu42/cc-safety-net. Operate CC Safety Net: explain why a command was blocked, triage false positives, configure custom rulebooks, manage agent CLI integrations, and diagnose protection.
Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Development. The repository describes itself as: A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports… The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 2615848. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxgitnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, git and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cc Safety Net loads about 4.4k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 2,431 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
exact file name (for example `~/code/**/.env.local`; theAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from kenryu42/cc-safety-net at commit 2615848, republished under its MIT licence (© kenryu42). 2,431 words, ~4,442 tokens.
.claude/skills/cc-safety-net/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.CC Safety Net hooks into coding agent CLIs (Claude Code, Codex, Cursor, Gemini CLI, and others)
and blocks destructive commands and secret access before they run. The cc-safety-net CLI
inspects and controls that protection. Run it as npx -y cc-safety-net.
The installed CLI is the authority for command syntax. Do not guess flags.
npx -y cc-safety-net --help
npx -y cc-safety-net help <command>Run npx -y cc-safety-net rule doc and treat that output as the complete source of truth for
rulebook schema, paths, GitHub sources, matching behavior, and validation.
These commands are read-only and safe to run for discovery: --help, --version, status,
doctor, logs (without --prune-legacy), explain, rule list, rule verify, rule doc,
policy check, help. Every other command mutates configuration or installed integrations; run
those only as part of a workflow below.
rule.json) list rulebook sources. Rule definitions live in rulebook.json,
not directly in rule.json..cc-safety-net/rules/<rulebook-name>/rulebook.json in a repository.rulebook.json on every tool call, so a saved
edit applies to the next command with no sync step.policy.json sets the safety level, per-feature toggles, per-rule overrides, and path lists. It
has two scopes: the project file .cc-safety-net/policy.json, committed and shared with the
team, layered on the user file that applies to every project.standard, strict, or paranoid, set per session with the
CC_SAFETY_NET_LEVEL environment variable.BLOCKED by CC Safety Net message:
explain a decision.explain and
rule doc show: answer from the source.npx -y cc-safety-net logs (narrow with --project ., --agent <name>, or --since <days>).npx -y cc-safety-net explain as one literal argument. Prefer an
argv-capable tool; when invoking through a shell, shell-escape the whole command as one
argument. Never interpolate raw command text into double quotes: $(), backticks, and
variables would expand before explain receives it. Add --cwd <path> when the decision
depends on the working directory. Once received, explain analyzes the string and never
executes it.explain exits 0 for both allowed and blocked verdicts; read the verdict from the
output, not the exit status.git stash before git reset --hard.npx -y cc-safety-net logs --suspect --since 7, or fetch
one entry with npx -y cc-safety-net logs --id <id>.explain and read which rule fired.explain to confirm the new verdict.CC_SAFETY_NET_WORKTREE=1 for local git discards in linked worktrees (git
discards in a temp-root repository outside the workspace are already allowed), or
rule wrapper add when a trusted transparent wrapper hid the real command from the analyzer.
Pass the wrapper name as a separate argv value, or shell-escape it as one argument. If the
user explicitly wants that built-in rule off, read its id from the ruleId field of
explain --json and propose a per-rule policy override (see configure the policy). Otherwise
explain the risk the rule guards against and suggest reporting the case at
https://github.com/kenryu42/cc-safety-net/issues.Use information already provided in the user's prompt. Ask only when the scope, action, rule intent, merge behavior, or target command is unclear.
npx -y cc-safety-net rule verifynpx -y cc-safety-net rule listrule doc.rule.json and
<rulebook-name>/rulebook.json..cc-safety-net/rules/<rulebook-name>/rulebook.json in the
current repository.owner/repo; installing rules from a GitHub
source is outside this workflow.npx -y cc-safety-net rule add owner/repo --only <rulebook...>; omit --only only
when they want every rulebook, and add --ref <ref> only when they name a non-default ref.
rule add --only <rulebook...> with no source selects from the official
cc-safety-net/rulebooks repository, whose curated rulebooks block destructive Terraform,
AWS, gcloud, and Azure CLI operations; prefer installing one of those over authoring when it
already covers the request.npx -y cc-safety-net rule wrapper add with the trusted
wrapper name passed as a separate argv value, or shell-escaped as one argument, over editing
rule.json by hand..cc-safety-net/rules/<rulebook-name>/rulebook.json, and ensure the source name, directory
name, and rulebook name match exactly.npx -y cc-safety-net rule verify and npx -y cc-safety-net rule list. Both commands cover every scope, so neither takes --global.npx -y cc-safety-net rule verify. Run list only
if the rulebook is also installed in local rule.json.Rule invariants:
.safety-net.json or ~/.cc-safety-net/config.json rules. Convert
existing legacy files with npx -y cc-safety-net rule migrate.allowed_commands. The tests fixtures are optional;
rule verify evaluates rulebook_version 2 fixtures against the rulebook's own rules, and
fixture commands are analyzer input that CC Safety Net never executes.rule, and that rule must exist in
the rulebook.project-rules; do not put filesystem paths in
rules.rule.json makes every source in its scope inactive: those rules stop applying while other
custom rules and built-in protections stay active. Fix the file named in the diagnostic.npx -y cc-safety-net rule add owner/repo fetches remote rulebooks, validates them, and vendors
each one into <rulebook-name>/rulebook.json; npx -y cc-safety-net rule update [source]
re-fetches and overwrites those copies and prints what changed. The runtime never fetches, and a
remote source with no vendored file reports that rule update has to vendor it first.rule sync is deprecated: it only migrates lock and cache leftovers from an earlier version.
Never run it as a validation or activation step.Both policy.json files are protected: you propose the change, the user applies it. Reading them
is allowed, writing them is not.
policy.json fields, all optional except version: 1 (policy check reports every schema
error, so validate against it rather than guessing further fields):
safety.level: standard, strict, or paranoid. safety.overrides: booleans for
fail_closed, paranoid_rm, and paranoid_interpreters that pin one capability apart from
the level.workflow.worktree_mode: boolean, allows local git discards in linked worktrees; discards in a
temp-root repository outside the workspace need no toggle.destructive_command_protection and secret_protection: an enabled boolean, and per-rule
overrides mapping a built-in rule id (git.reset-hard, secret.basename.env) to "on" or
"off". Get the id for a blocked command from the ruleId field of explain --json.destructive_command_protection.allow_paths: absolute or ~/ paths where recursive delete
targets are permitted. secret_protection.allow_paths: exact user-managed files or directories,
or a folder followed by **/ and an exact file name (for example ~/code/**/.env.local; the
folder cannot be home or above it), exempted from built-in secret patterns. Deny paths and
Coding CLI protections still win. Other glob forms are rejected.
secret_protection.deny_paths: extra paths protected like built-in secrets.audit.retention_days: days of audit history to keep, user scope only.npx -y cc-safety-net status for the effective policy and the file
paths it loaded, npx -y cc-safety-net rule list for custom rules, plus whatever project
context the request depends on. Read an existing policy.json before proposing changes to it.policy-proposal.json. For
project scope, set only the fields the team intends to control; an unset field inherits
from the user policy, and apply writes only the fields the proposal sets.
Applying replaces the target file, so the proposal is the complete policy, not a patch. Audit
settings are user scope only; a project proposal cannot set them.npx -y cc-safety-net policy check policy-proposal.json and show the user the printed
diff. Add --global to target the user policy instead of the project one. Fix every reported
error and re-check until it passes.npx -y cc-safety-net policy apply policy-proposal.json (with --global when that is the
scope). It confirms interactively, there is no --yes flag, and agent invocations of
policy apply are blocked by design, so never run it, wrap it, or write the file yourself.npx -y cc-safety-net status and report the
effective policy, including any project scope deltas it prints.npx -y cc-safety-net doctor first. It reports each supported platform as detected,
configured, and verified, and names outdated installs with the exact repair command.npx -y cc-safety-net install --claude-code.
Run npx -y cc-safety-net help install for the full target list. Bare install opens an
interactive picker; leave that for the user's own terminal.npx -y cc-safety-net@latest update to update every installed integration at once.doctor again and confirm the affected platform
rows read as verified.npx -y cc-safety-net status shows what the runtime enforces right now, including a degraded
policy.json that rule list does not report.npx -y cc-safety-net doctor verifies the installation: platform detection and hook config,
a synthetic guard self-test, and configuration scopes. Use --json when parsing the result.rule verify, rule list, then re-test the
command with explain.For questions the CLI output cannot settle, such as why the analyzer treats a construct a certain way or whether a gap is a known limitation, read the source code of the installed version.
Get <version> from npx -y cc-safety-net --version.
Locate the repository. Plugin installs ship the full repository, and this skill file lives
at <repo>/skills/cc-safety-net/SKILL.md inside it, so the repository root is two
directories above the skill file. Use the candidate only if its package.json has
"name": "cc-safety-net" and version <version>, and a src/ directory exists next to it.
If the package version differs, run doctor to report the outdated integration, then treat
the candidate as unavailable and continue to the next step.
If no matching local root exists (skill-only installs, a mismatched plugin, or guidance
without a file path), resolve the immutable commit recorded with the published package using
npm view "cc-safety-net@<version>" gitHead. Require a 40-character lowercase hexadecimal
commit and fetch that exact commit into a fresh owner-only temporary directory:
set -euo pipefail
git_head=$(npm view "cc-safety-net@<version>" gitHead)
[[ $git_head =~ ^[0-9a-f]{40}$ ]] || { echo "Invalid published gitHead" >&2; exit 1; }
source_dir=$(mktemp -d "${TMPDIR:-/tmp}/cc-safety-net-v<version>-XXXXXXXX")
trap 'rm -rf -- "$source_dir"' EXIT
chmod 700 "$source_dir"
git -c init.templateDir= init "$source_dir"
git -c core.hooksPath=/dev/null -C "$source_dir" fetch --depth 1 https://github.com/kenryu42/cc-safety-net "$git_head"
git -c core.hooksPath=/dev/null -C "$source_dir" checkout --detach "$git_head"
[[ $(git -C "$source_dir" rev-parse HEAD) == "$git_head" ]] || { echo "Source checkout mismatch" >&2; exit 1; }
printf 'Source checkout: %s\n' "$source_dir"
trap - EXITNever answer from main; it can contain unreleased behavior the installed version does not
have.
Read docs/ first; residual-risk.md and secret-protection-known-limitations.md exist to
answer whether something is a known gap. For behavior questions, continue into
src/analyzer, src/guards, and src/rules.
State in the answer which version the source came from. Treat the located source as read-only reference; do not edit, build, or run it.
Remove a temporary checkout after the source inspection: rm -rf -- "<source_dir>".
hook; it is the integration entry point that reads hook JSON from stdin, not a
user-facing command.logs --prune-legacy permanently deletes legacy logs. Run it only on an explicit request, and
run it with --dry-run first.rule remove --delete-source deletes the local source directory. Ask before using it.gui --no-open and give the user the URL instead of opening a browser from a session.UPDATE_AVAILABLE: line, ask the user once whether to run
npx -y cc-safety-net@latest update, continue the workflow without waiting either way, and do
not raise it again.© kenryu42, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/cc-safety-net of kenryu42/cc-safety-net.
Open the folder on GitHubat commit 2615848
Cc Safety Net next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cc Safety Net this skillkenryu42/cc-safety-net | 1.6k | — | ~4.4k | Automated safety check: Notes | MIT | |
| Vercel Composition Patternssupabase/supabase | 111k | 59 repos | ~726 | Automated safety check: Pass | MIT | |
| Finishing a Development Branchobra/superpowers | 296k | 5 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Typescript Advanced Typesrolling-scopes/rsschool-app | 10k | 25 repos | ~4.2k | Automated safety check: Pass | MPL-2.0 | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT |
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
rolling-scopes/rsschool-app
Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
onyx-dot-app/onyx
Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.
kenryu42/cc-safety-net
Generate and publish concise, evidence-based notes in the body of the latest existing GitHub Release.
kenryu42/cc-safety-net
Launch and drive the real cc-safety-net CLI — the hook decision path, explain, status/doctor, logs, and the local policy GUI — against an isolated home, capturing evidence.
kenryu42/cc-safety-net
A skill your agent uses when working in the cc-safety-net repo to find non-obvious simplification candidates: dead, duplicated, speculative, over-built, or contract-exceeding surfaces in the shell…
kenryu42/cc-safety-net
Use in the cc-safety-net repo when bun run lint:comments or bun run check reports a comment, a stale comment-allowlist entry, or a file it cannot parse, and before writing a code comment there.
Categories
Operate CC Safety Net: explain why a command was blocked, triage false positives, configure custom rulebooks, manage agent CLI integrations, and diagnose protection. Cc Safety Net is an agent skill from kenryu42/cc-safety-net. Operate CC Safety Net: explain why a command was blocked, triage false positives, configure custom rulebooks, manage agent CLI integrations, and diagnose protection.
Cc Safety Net fits situations like: development work in your project.
Run `npx skills add kenryu42/cc-safety-net --skill cc-safety-net -a claude-code`. Or copy the skill folder (skills/cc-safety-net in kenryu42/cc-safety-net) into .claude/skills/cc-safety-net in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kenryu42/cc-safety-net --skill cc-safety-net -a codex`. Or copy the skill folder (skills/cc-safety-net in kenryu42/cc-safety-net) into .agents/skills/cc-safety-net in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kenryu42/cc-safety-net --skill cc-safety-net -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cc-safety-net, .gemini/skills/cc-safety-net, .github/skills/cc-safety-net and .opencode/skills/cc-safety-net in your project.
Going by SKILL.md and its folder, Cc Safety Net needs the command-line tools its instructions call (npx, git and npm). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npx, git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Cc Safety Net is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cc Safety Net: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kenryu42 (a GitHub user) maintains it in kenryu42/cc-safety-net, which has 1,582 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 8, 2026.
Source: kenryu42/cc-safety-net on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.