Clawdbot Backup
sundial-org/awesome-openclaw-skills
Backup and restore ClawdBot configuration, skills, commands, and settings.
Source control and artifact exposure (.git, .svn, .hg, backups, .env).
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill insecure-source-code-management -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC insecure-source-code-management --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/insecure-source-code-management .claude/skills/insecure-source-code-management && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "insecure-source-code-management" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/insecure-source-code-management into .claude/skills/insecure-source-code-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "insecure-source-code-management", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/insecure-source-code-managementType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill insecure-source-code-management -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC insecure-source-code-management --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/insecure-source-code-management .agents/skills/insecure-source-code-management && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "insecure-source-code-management" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/insecure-source-code-management into .agents/skills/insecure-source-code-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "insecure-source-code-management", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill insecure-source-code-management -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC insecure-source-code-management --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/insecure-source-code-management .cursor/skills/insecure-source-code-management && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "insecure-source-code-management" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/insecure-source-code-management into .cursor/skills/insecure-source-code-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "insecure-source-code-management", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/langbyyi/CyberStrikeAI-SRC.git --path skills/insecure-source-code-management--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill insecure-source-code-management -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC insecure-source-code-management --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/insecure-source-code-management .gemini/skills/insecure-source-code-management && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "insecure-source-code-management" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/insecure-source-code-management into .gemini/skills/insecure-source-code-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "insecure-source-code-management", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install langbyyi/CyberStrikeAI-SRC insecure-source-code-managementInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill insecure-source-code-management -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/insecure-source-code-management .github/skills/insecure-source-code-management && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "insecure-source-code-management" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/insecure-source-code-management into .github/skills/insecure-source-code-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "insecure-source-code-management", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill insecure-source-code-management -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC insecure-source-code-management --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/insecure-source-code-management .opencode/skills/insecure-source-code-management && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "insecure-source-code-management" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/insecure-source-code-management into .opencode/skills/insecure-source-code-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "insecure-source-code-management", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
insecure-source-code-managementSource control and artifact exposure (.git, .svn, .hg, backups, .env).
Insecure Source Code Management is an agent skill from langbyyi/CyberStrikeAI-SRC. Source control and artifact exposure (.git, .svn, .hg, backups, .env). Use when recon finds VCS paths, 403 on hidden dirs, or backup/config leaks during authorized testing.
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Backup and disaster recovery and Git workflow. It works with Git. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 166ee1c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are http).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Insecure Source Code Management loads about 1.3k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 472 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
fact exposure (.git, .svn, .hg, backups, .env). Use when recon finds VCS paths, 403 on hidden dirs, or backup/config lea/.env/.env*Parallel**: fetch **`/.DS_Store`**, **`/.env`**, common **backup extensions** on app root and parent paths.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from langbyyi/CyberStrikeAI-SRC at commit 166ee1c, republished under its Apache-2.0 licence (© langbyyi). 472 words, ~1,273 tokens.
.claude/skills/insecure-source-code-management/SKILL.md (or your agent's skills folder).AI LOAD INSTRUCTION: This skill covers detection and recovery of exposed version-control metadata, common backup artifacts, and related misconfigurations. Use only in authorized assessments. Treat recovered credentials and URLs as sensitive; do not exfiltrate real data beyond scope. For broad discovery workflow, cross-load recon-for-sec and recon-and-methodology when those skills exist in the workspace.
High-value paths to probe first (GET or HEAD, respect rate limits):
/.git/HEAD
/.git/config
/.svn/entries
/.svn/wc.db
/.hg/requires
/.bzr/README
/.DS_Store
/.env中文路由提示:快速扫这些路径;若需完整侦察流程,从 recon-for-sec、recon-and-methodology 技能载入方法论后再深入。
/.git/HEAD — valid repo often returns plain text like:ref: refs/heads/main/.git/config — may expose remote.origin.url, user identity, or embedded credentials./.git/index, /.git/objects/ — partial object store access enables reconstruction with the right tools.404 — path likely absent or fully blocked at the edge.403 on /.git/ — directory may exist but listing is denied; still try direct file URLs:/.git/HEAD
/.git/config
/.git/logs/HEAD
/.git/refs/heads/mainA 403 on the directory plus 200 on HEAD strongly indicates exposure.
arthaud/git-dumper — dumps reachable .git tree when individual files are fetchable.internetwache/GitTools — Dumper, Extractor, Finder modules for partial/corrupt dumps.WangYihang/GitHacker — alternative recovery when standard dumpers miss edge cases.| Path | Why it matters |
|---|---|
.git/config | Remotes, credentials, hooks paths |
.git/logs/HEAD | Commit history, reflog-style leakage |
.git/refs/heads/* | Branch tips, commit SHAs |
.git/packed-refs | Packed branch/tag refs |
.git/objects/** | Object blobs for reconstruction |
/.svn/entries — XML or text metadata listing paths and revisions./.svn/wc.db — SQLite working copy database (PRAGMA table_info after download).Example probe:
GET /.svn/entries HTTP/1.1
GET /.svn/wc.db HTTP/1.1anantshri/svn-extractor — automated extraction from exposed .svn.wc.db, query with sqlite3 for file paths and checksums, then request /.svn/pristine/ blobs if exposed./.hg/requires — small text file listing repository features; confirms Mercurial metadata.GET /.hg/requires HTTP/1.1
GET /.hg/store/ HTTP/1.1sahildhar/mercurial_source_code_dumper — dumps repository when store paths are reachable./.bzr/README and /.bzr/branch-format for Bazaar metadata..DS_Store/.DS_Store can encode directory and filename listings.gehaxelt/ds-store, lijiejie/ds_store_exp — parse .DS_Store offline.Probe (adjust for app root and naming conventions):
/.env
/backup.zip
/backup.tar.gz
/wwwroot.rar
/backup.sql
/config.php.bak
/.config.php.swplocation /.git { deny all; } — may return 403 for /.git/ while still allowing or denying specific subpaths depending on rules./.git/HEAD → ref: refs/heads/ pattern? → run git-dumper / GitTools / GitHacker; review config and logs/HEAD for secrets./.svn/wc.db or entries → success? → svn-extractor or manual wc.db + pristine recovery./.hg/requires → success? → mercurial dumper./.bzr/README → Bazaar tooling or manual path walk./.DS_Store, /.env, common backup extensions on app root and parent paths.中文:与侦察类技能联动——先定范围与速率,再针对 VCS/备份做定向验证。
© langbyyi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/insecure-source-code-management of langbyyi/CyberStrikeAI-SRC.
Open the folder on GitHubat commit 166ee1c
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in langbyyi/CyberStrikeAI-SRC, which our catalogue first saw on October 7, 2026.
Insecure Source Code Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Insecure Source Code Management this skilllangbyyi/CyberStrikeAI-SRC | 134 | 1 repos | ~1.3k | Automated safety check: Notes | Apache-2.0 | |
| Clawdbot Backupsundial-org/awesome-openclaw-skills | 663 | 1 repos | ~4.5k | Automated safety check: Pass | None | |
| Git Crypt Backupsundial-org/awesome-openclaw-skills | 663 | — | ~727 | Automated safety check: Notes | None | |
| CI Automationjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.4k | Automated safety check: Notes | MIT | |
| Ssh Skillbadseal/ssh-skill | 536 | — | ~2.4k | Automated safety check: Notes | None | |
| GreptimeDB Release RunbookGreptimeTeam/greptimedb | 6.7k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 |
sundial-org/awesome-openclaw-skills
Backup and restore ClawdBot configuration, skills, commands, and settings.
sundial-org/awesome-openclaw-skills
Backup Clawdbot workspace and config to GitHub with git-crypt encryption.
jeremylongshore/tons-of-skills-marketplace
A skill your agent uses when running GitHub Actions locally, creating task runner recipes, generating changelogs from git history, managing GitHub PRs/issues/releases programmatically, or creating…
badseal/ssh-skill
A skill your agent uses when a task requires SSH or SCP/SFTP behavior, a remote server, server alias/IP/hostname/user@host, bastion or jump-host access, remote command execution, upload/download…
GreptimeTeam/greptimedb
Runbook for publishing a GreptimeDB version: pick the release branch, verify the Cargo version, then tag, create the GitHub release and open the docs note PR.
sopaco/deepwiki-rs
A skill your agent uses when running shell commands that produce verbose output (git, test, build, lint, package managers, docker).
langbyyi/CyberStrikeAI-SRC
Automate low-impact web vulnerability verification through Burp MCP.
langbyyi/CyberStrikeAI-SRC
Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC.
langbyyi/CyberStrikeAI-SRC
HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.
langbyyi/CyberStrikeAI-SRC
PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC.
langbyyi/CyberStrikeAI-SRC
WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.
langbyyi/CyberStrikeAI-SRC
XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces.
Works with
Categories
Source control and artifact exposure (.git, .svn, .hg, backups, .env). Insecure Source Code Management is an agent skill from langbyyi/CyberStrikeAI-SRC.env).
Insecure Source Code Management fits situations like: recon finds VCS paths; 403 on hidden dirs; backup/config leaks during authorized testing.
Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill insecure-source-code-management -a claude-code`. Or copy the skill folder (skills/insecure-source-code-management in langbyyi/CyberStrikeAI-SRC) into .claude/skills/insecure-source-code-management in your project. Claude Code loads it when a task matches its description.
Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill insecure-source-code-management -a codex`. Or copy the skill folder (skills/insecure-source-code-management in langbyyi/CyberStrikeAI-SRC) into .agents/skills/insecure-source-code-management in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbyyi/CyberStrikeAI-SRC --skill insecure-source-code-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/insecure-source-code-management, .gemini/skills/insecure-source-code-management, .github/skills/insecure-source-code-management and .opencode/skills/insecure-source-code-management in your project.
SKILL.md names no scripts, command-line tools or credentials: Insecure Source Code Management is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Insecure Source Code Management is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Insecure Source Code Management: Clawdbot Backup (sundial-org/awesome-openclaw-skills, 663 stars), Git Crypt Backup (sundial-org/awesome-openclaw-skills, 663 stars), CI Automation (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Ssh Skill (badseal/ssh-skill, 536 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
langbyyi (a GitHub user) maintains it in langbyyi/CyberStrikeAI-SRC, which has 134 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 7, 2026.
Source: langbyyi/CyberStrikeAI-SRC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.