Openai Security Ownership Map
trailofbits/skills-curated
Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization.
Generate an interactive local HTML review page for a large PR or diff, grouping the changed files by logical concern (not just by file) so a reviewer can go through one theme at a time instead of a…
$ npx skills add meain/dotfiles --skill concern-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install meain/dotfiles concern-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/meain/dotfiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/.agents/skills/concern-review .claude/skills/concern-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "concern-review" agent skill from https://github.com/meain/dotfiles/tree/master/agents/.agents/skills/concern-review into .claude/skills/concern-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "concern-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/meain/dotfiles/tree/master/agents/.agents/skills/concern-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add meain/dotfiles --skill concern-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install meain/dotfiles concern-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/meain/dotfiles.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agents/.agents/skills/concern-review .agents/skills/concern-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "concern-review" agent skill from https://github.com/meain/dotfiles/tree/master/agents/.agents/skills/concern-review into .agents/skills/concern-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "concern-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add meain/dotfiles --skill concern-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install meain/dotfiles concern-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/meain/dotfiles.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agents/.agents/skills/concern-review .cursor/skills/concern-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "concern-review" agent skill from https://github.com/meain/dotfiles/tree/master/agents/.agents/skills/concern-review into .cursor/skills/concern-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "concern-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/meain/dotfiles.git --path agents/.agents/skills/concern-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add meain/dotfiles --skill concern-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install meain/dotfiles concern-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/meain/dotfiles.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agents/.agents/skills/concern-review .gemini/skills/concern-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "concern-review" agent skill from https://github.com/meain/dotfiles/tree/master/agents/.agents/skills/concern-review into .gemini/skills/concern-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "concern-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install meain/dotfiles concern-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add meain/dotfiles --skill concern-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/meain/dotfiles.git skills-src && mkdir -p .github/skills && cp -r skills-src/agents/.agents/skills/concern-review .github/skills/concern-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "concern-review" agent skill from https://github.com/meain/dotfiles/tree/master/agents/.agents/skills/concern-review into .github/skills/concern-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "concern-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add meain/dotfiles --skill concern-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install meain/dotfiles concern-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/meain/dotfiles.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agents/.agents/skills/concern-review .opencode/skills/concern-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "concern-review" agent skill from https://github.com/meain/dotfiles/tree/master/agents/.agents/skills/concern-review into .opencode/skills/concern-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "concern-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
concern-reviewGenerate an interactive local HTML review page for a large PR or diff, grouping the changed files by logical concern (not just by file) so a reviewer can go through one theme at a time instead of a…
Concern Review is an agent skill from meain/dotfiles. Generate an interactive local HTML review page for a large PR or diff, grouping the changed files by logical concern (not just by file) so a reviewer can go through one theme at a time instead of a flat file list. Each concern gets its own section with a description, per-file summaries, the real diff (sliced to just the hunks relevant to that concern when a file serves more than one), and callouts for anything genuinely non-obvious. Triggers: /concern-review, "review this PR by concern", "review this large PR"…
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts (for example `scripts/build_review.py`, `scripts/diffsplit.py` and `scripts/list_hunks.py`).
It sits in Development, covering CSV and tabular files. The repository describes itself as: If there is a shell, there is a way! The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 3e336e2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3gitnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Concern Review loads about 2.2k tokens when it runs. Until then it costs about 158 tokens; SKILL.md has 1,068 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from meain/dotfiles at commit 3e336e2, republished under its MIT licence (© meain). 1,068 words, ~2,215 tokens.
.claude/skills/concern-review/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Large PRs are easier to review grouped by what the change is doing (e.g. "new retry logic", "bug fix", "reporting additions") than by a flat list of files — a file that serves two purposes should show up, sliced, in both places. This skill produces that as a static HTML page: a left sidebar to jump between concerns, one concern's files shown at a time as a single scrolling list, real unified diffs with GitHub-style coloring, and a short summary above each file's diff.
Your output is a small JSON blob — never the diff content itself. You decide which hunks belong to which concern and write short summaries; a Python script pulls the actual diff text from the real diff file and builds the HTML. This means:
Do not paste diff hunks into the JSON. Reference them by index instead.
Pick whichever applies:
# GitHub PR (set GIT_DIR if the repo uses jj)
GIT_DIR=$(jj git root 2>/dev/null || echo .git) gh pr diff <number> > /tmp/<slug>.diff
# local working diff (jj)
jj diff --git -r <revision> > /tmp/<slug>.diff
# local working diff (git)
git diff <base>...<head> > /tmp/<slug>.diffUse a short <slug> you'll reuse for the other temp files (e.g. pr5276).
python3 ~/.claude/skills/concern-review/scripts/list_hunks.py /tmp/<slug>.diff [optional-path-substring-filter]This prints, per file, every hunk's 0-based index, its @@ ... @@ header, and
its +/- line count. These indices are what you'll reference in the JSON —
don't hand-count @@ lines from the raw diff, use this output. Filter by a
path substring if the diff is huge and you want one file at a time.
Read /tmp/<slug>.diff (or grep/sed specific line ranges for very large
files) to actually understand what changed — the hunk map from step 2 tells
you where things are, not what they do. This is normal input-token
reading; the efficiency goal is about what you write, not what you read.
Aim for 2-6 concerns that are genuinely distinct themes — not "misc" or one concern per file. Good concerns read like a PR description's bullet points: "new retry logic for X", "bug fix: Y", "reporting/logging additions". Each concern needs:
key: short kebab-slug, used in DOM ids/anchors (e.g. "vpn-retry")title: human title, shown as the section headingdesc: one or two sentencesFor each file touched by a concern, add an entry:
{ "path": "exact/path/as/printed/by/list_hunks.py", "summary": "...", "hunks": "all" }"hunks": "all"
(or omit the key — that's the default)."hunks": [0, 1, 4, 5]. Every
hunk in the file must be assigned to exactly one concern — check the total
hunk count from list_hunks.py against your combined lists so none are
silently dropped or duplicated.summary: one to three sentences on what changed in this file, for this
concern and why — not a restatement of the diff. Write it like you're
telling a colleague what to look for.Each concern may have a "notes" array (rendered as an amber "Might be
confusing" callout). Reserve these for things a careful reviewer could easily
miss or misjudge: a hidden invariant, duplicated logic that could drift, an
intentional-looking tradeoff, a migration/compatibility implication, two call
sites solving the same problem differently. Do not add navigational notes
like "the rest of this file is in another section" — the UI already makes
that obvious (files are listed per-concern in the sidebar), and a prior user
explicitly asked for these to be removed. If nothing is genuinely confusing,
omit notes or leave it empty.
{
"pr": { "label": "org/repo #123", "subtitle": "TICKET-123 — short title" },
"pathPrefix": "optional/common/path/prefix/to/strip/in/the/sidebar/",
"categories": [
{
"key": "vpn-retry",
"title": "VPN-resilience (new)",
"desc": "One or two sentences.",
"notes": ["Non-obvious point worth flagging.", "..."],
"files": [
{ "path": "internal/cosmosretry/retry.go", "summary": "...", "hunks": "all" },
{ "path": "main.go", "summary": "...", "hunks": [0, 1, 4, 5] }
]
}
]
}Save it to /tmp/<slug>-concerns.json. pathPrefix is optional — set it to
whatever common prefix (e.g. a monorepo module path) should be stripped when
showing filenames in the sidebar, so internal/foo/bar.go shows instead of
tools/some-service/internal/foo/bar.go.
python3 ~/.claude/skills/concern-review/scripts/build_review.py \
--diff /tmp/<slug>.diff \
--concerns /tmp/<slug>-concerns.json \
--out /tmp/<slug>-review.htmlThe script errors out with a clear message (and the list of valid paths) if a
path doesn't match anything in the diff, or if a hunks index is out of
range — fix the JSON and re-run rather than guessing.
open /tmp/<slug>-review.html(use dangerouslyDisableSandbox: true for the open call). Tell the user
how many concerns/files it covers in a sentence or two — don't re-narrate the
whole PR in chat, the page is the review surface now.
You never touch template.html's CSS/JS — it already implements everything
validated across real review sessions:
If you modify template.html or the scripts, verify with a headless browser
before considering it done — a static review of the JS isn't enough to catch
layout bugs (this skill's design went through several rounds of exactly that
kind of bug). Playwright works well for this (npm install playwright in a
scratch dir, then drive it with a small node script); screenshot at least the
default concern and one concern with a long file path, and check for errors
via page.on("console", ...) and page.on("pageerror", ...).
Note when scripting clicks: data-cat-select="<key>" appears on every
file link in a concern's sidebar list, not just once on the concern's header
link — that's intentional (clicking any file jumps to it within that
concern), but it means a plain page.click('[data-cat-select="..."]') or an
nth-match click can silently hit the same concern twice instead of switching.
Scope the selector to the header when you want an unambiguous single click:
.cat-link[data-cat-select="<key>"].
© meain, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts) in agents/.agents/skills/concern-review of meain/dotfiles.
Open the folder on GitHubat commit 3e336e2
Concern Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Concern Review this skillmeain/dotfiles | 285 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Openai Security Ownership Maptrailofbits/skills-curated | 513 | 5 repos | ~2.2k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Add To Dependabot CSVlangfuse/langfuse | 36k | — | ~1.5k | Automated safety check: Pass | Custom licence | |
| Taskmasterlili-luo/aicoding-cookbook | 687 | — | ~2.9k | Automated safety check: Pass | None | |
| Deadline Prepdavila7/claude-code-templates | 33k | — | ~739 | Automated safety check: Pass | MIT | |
| Portaljs Add Datasetdatopian/portaljs | 2.4k | 1 repos | ~1.6k | Automated safety check: Pass | MIT |
trailofbits/skills-curated
Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization.
langfuse/langfuse
Append GitHub Dependabot or Snyk/code-scanning alerts to an existing vulnerability CSV after verifying their API metadata.
lili-luo/aicoding-cookbook
Unified task execution protocol for Codex-only work. An agent skill from lili-luo/aicoding-cookbook.
davila7/claude-code-templates
Generate a structured demo outline from your session's change log and git history.
datopian/portaljs
Add a dataset (CSV, TSV, JSON, or GeoJSON) to an existing PortalJS portal.
shencangsheng/easydb_app
Resolve pull request code review comments end-to-end. An agent skill from shencangsheng/easydb_app.
meain/dotfiles
Search past Claude Code and Codex sessions. An agent skill from meain/dotfiles.
meain/dotfiles
Grilling session that challenges your plan against the existing domain model, sharpens terminology, and updates documentation (CONTEXT.md, ADRs) inline as decisions crystallise.
meain/dotfiles
Daily backlog management — full planning review OR add a single entry from a URL.
meain/dotfiles
Generate a concise weekly status update in team format. An agent skill from meain/dotfiles.
meain/dotfiles
Search the web using lynx and DuckDuckGo. An agent skill from meain/dotfiles.
meain/dotfiles
Explain test code changes as a side-by-side HTML page — real test code on the left, a short note on the right saying which case that code covers.
Categories
Generate an interactive local HTML review page for a large PR or diff, grouping the changed files by logical concern (not just by file) so a reviewer can go through one theme at a time instead of a…. Concern Review is an agent skill from meain/dotfiles. Generate an interactive local HTML review page for a large PR or diff, grouping the changed files by logical concern (not just by file) so a reviewer can go through one theme at a time instead of a flat file list.
Concern Review fits situations like: tasks that involve CSV and tabular files.
Run `npx skills add meain/dotfiles --skill concern-review -a claude-code`. Or copy the skill folder (agents/.agents/skills/concern-review in meain/dotfiles) into .claude/skills/concern-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add meain/dotfiles --skill concern-review -a codex`. Or copy the skill folder (agents/.agents/skills/concern-review in meain/dotfiles) into .agents/skills/concern-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add meain/dotfiles --skill concern-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/concern-review, .gemini/skills/concern-review, .github/skills/concern-review and .opencode/skills/concern-review in your project.
Going by SKILL.md and its folder, Concern Review needs Python for the scripts in its folder and the command-line tools its instructions call (python3, git and npm). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Concern Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Concern Review: Openai Security Ownership Map (trailofbits/skills-curated, 513 stars), Add To Dependabot CSV (langfuse/langfuse, 36k stars), Taskmaster (lili-luo/aicoding-cookbook, 687 stars) and Deadline Prep (davila7/claude-code-templates, 33k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
meain (a GitHub user) maintains it in meain/dotfiles, which has 285 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on October 8, 2026.
Source: meain/dotfiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.