Agent skill

Gstack Cso

by LING71671 in LING71671/Open-ClaudeCode

Security audit workflow for OPC code, providers, plugins, Electron surfaces, local HTTP bridges, filesystem access, and command execution.

Custom licenceAuto-check: notesSecurity

Install Gstack Cso

skills CLI
$ npx skills add LING71671/Open-ClaudeCode --skill gstack-cso -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LING71671/Open-ClaudeCode gstack-cso --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LING71671/Open-ClaudeCode.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/gstack-workflows/skills/gstack-cso .claude/skills/gstack-cso && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gstack-cso
GitHub stars
960
Token cost
~321 tokens
SKILL.md length
140 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
Custom licence

At a glance

Security audit workflow for OPC code, providers, plugins, Electron surfaces, local HTTP bridges, filesystem access, and command execution.

  • Works in 5 steps: Map the trust boundaries and data flows. → Identify assets: secrets, filesystem… → Review entrypoints that cross boundaries. → …
  • Tasks that involve Security review
  • SKILL.md covers Scope, Workflow and Output
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Gstack Cso is an agent skill from LING71671/Open-ClaudeCode. Security audit workflow for OPC code, providers, plugins, Electron surfaces, local HTTP bridges, filesystem access, and command execution.

Its SKILL.md is about 320 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review. The repository describes itself as: Research archive of Claude Code source and runtime artifacts reconstructed from published npm source maps.

When your agent uses it

  • Tasks that involve Security review

Example prompts

  • “/gstack-cso”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Map the trust boundaries and data flows.
  2. Identify assets: secrets, filesystem access, provider credentials, session state, command execution, and user prompts.
  3. Review entrypoints that cross boundaries.
  4. Test high-confidence concerns with direct code evidence.
  5. Ignore speculative issues unless there is a concrete exploit path.

What it can do on your machine

Read from SKILL.md and the folder at commit 2980105. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gstack Cso loads about 321 tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 140 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~321

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 140 words (~321 tokens).

“Use this skill for a security review with OWASP and STRIDE lenses.”

— opening of SKILL.md by LING71671, Custom licence
name
gstack-cso
allowed-tools
Read, Grep, Glob, Bash

Read the full SKILL.md on GitHub

Files

Just SKILL.md in plugins/gstack-workflows/skills/gstack-cso of LING71671/Open-ClaudeCode.

Open the folder on GitHubat commit 2980105

Compare with similar skills

Gstack Cso next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gstack Cso compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gstack Cso this skillLING71671/Open-ClaudeCode960—~321Automated safety check: NotesCustom licence
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Skillward AuditFangcun-AI/SkillWard143—~2.9kAutomated safety check: PassCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated 6 days ago
    SecurityAuto-check: notes
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes

More from LING71671/Open-ClaudeCode

  • Gstack Document Release

    LING71671/Open-ClaudeCode

    Brings project documentation back in line with shipped behavior by reading the current diff for user-visible changes and updating only the docs they affect.

    960 GitHub stars~282 tokensUpdated 2 mo ago
    Auto-check: notes
  • Root-Cause Investigation Workflow

    LING71671/Open-ClaudeCode

    Diagnoses a bug, crash, regression or flaky behavior by reproducing it and testing several causes before applying the smallest fix.

    960 GitHub stars~322 tokensUpdated 2 mo ago
    Auto-check: notes
  • Gstack QA Only

    LING71671/Open-ClaudeCode

    Read-only QA report for an OPC desktop flow, CLI command, local URL, staging URL, or documented user journey.

    960 GitHub stars~282 tokensUpdated 2 mo ago
    Auto-check: notes
  • Gstack Pre-Landing Review

    LING71671/Open-ClaudeCode

    Runs a staff-engineer style review over the current diff before merging, listing findings by severity with file, impact and a suggested fix.

    960 GitHub stars~316 tokensUpdated 2 mo ago
    Auto-check: notes

Categories

Questions about Gstack Cso

What does Gstack Cso do?

Security audit workflow for OPC code, providers, plugins, Electron surfaces, local HTTP bridges, filesystem access, and command execution. Gstack Cso is an agent skill from LING71671/Open-ClaudeCode. Security audit workflow for OPC code, providers, plugins, Electron surfaces, local HTTP bridges, filesystem access, and command execution.

When should I use Gstack Cso?

Gstack Cso fits situations like: tasks that involve Security review.

How do I install Gstack Cso in Claude Code?

Run `npx skills add LING71671/Open-ClaudeCode --skill gstack-cso -a claude-code`. Or copy the skill folder (plugins/gstack-workflows/skills/gstack-cso in LING71671/Open-ClaudeCode) into .claude/skills/gstack-cso in your project. Claude Code loads it when a task matches its description.

How do I install Gstack Cso in Codex?

Run `npx skills add LING71671/Open-ClaudeCode --skill gstack-cso -a codex`. Or copy the skill folder (plugins/gstack-workflows/skills/gstack-cso in LING71671/Open-ClaudeCode) into .agents/skills/gstack-cso in your project. Codex loads it when a task matches its description.

Can I use Gstack Cso in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LING71671/Open-ClaudeCode --skill gstack-cso -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gstack-cso, .gemini/skills/gstack-cso, .github/skills/gstack-cso and .opencode/skills/gstack-cso in your project.

What does Gstack Cso need to run?

SKILL.md names no scripts, command-line tools or credentials: Gstack Cso is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash.

Does Gstack Cso access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Gstack Cso safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Gstack Cso use?

Gstack Cso has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Gstack Cso use?

About 321 tokens (SKILL.md is roughly 1.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Gstack Cso?

Skills that share tags, products or a category with Gstack Cso: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Semgrep Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gstack Cso?

LING71671 (a GitHub user) maintains it in LING71671/Open-ClaudeCode, which has 960 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on July 22, 2026.

Source: LING71671/Open-ClaudeCode on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.