ONNX Runtime Shape Inference Safety Audit
microsoft/onnxruntime
Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs.
Perform a systematic code review of all source files, focusing on security, performance, backwards compatibility, and design principles.
$ npx skills add MichaelGrafnetter/DSInternals --skill code-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install MichaelGrafnetter/DSInternals code-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/MichaelGrafnetter/DSInternals.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/code-review .claude/skills/code-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "code-review" agent skill from https://github.com/MichaelGrafnetter/DSInternals/tree/master/.agents/skills/code-review into .claude/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/MichaelGrafnetter/DSInternals/tree/master/.agents/skills/code-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add MichaelGrafnetter/DSInternals --skill code-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install MichaelGrafnetter/DSInternals code-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MichaelGrafnetter/DSInternals.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/code-review .agents/skills/code-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "code-review" agent skill from https://github.com/MichaelGrafnetter/DSInternals/tree/master/.agents/skills/code-review into .agents/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add MichaelGrafnetter/DSInternals --skill code-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install MichaelGrafnetter/DSInternals code-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MichaelGrafnetter/DSInternals.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/code-review .cursor/skills/code-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "code-review" agent skill from https://github.com/MichaelGrafnetter/DSInternals/tree/master/.agents/skills/code-review into .cursor/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/MichaelGrafnetter/DSInternals.git --path .agents/skills/code-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add MichaelGrafnetter/DSInternals --skill code-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install MichaelGrafnetter/DSInternals code-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MichaelGrafnetter/DSInternals.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/code-review .gemini/skills/code-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/MichaelGrafnetter/DSInternals/tree/master/.agents/skills/code-review into .gemini/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install MichaelGrafnetter/DSInternals code-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add MichaelGrafnetter/DSInternals --skill code-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/MichaelGrafnetter/DSInternals.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/code-review .github/skills/code-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/MichaelGrafnetter/DSInternals/tree/master/.agents/skills/code-review into .github/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add MichaelGrafnetter/DSInternals --skill code-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install MichaelGrafnetter/DSInternals code-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MichaelGrafnetter/DSInternals.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/code-review .opencode/skills/code-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/MichaelGrafnetter/DSInternals/tree/master/.agents/skills/code-review into .opencode/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
code-reviewPerform a systematic code review of all source files, focusing on security, performance, backwards compatibility, and design principles.
Code Review is an agent skill from MichaelGrafnetter/DSInternals. Perform a systematic code review of all source files, focusing on security, performance, backwards compatibility, and design principles.
Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Code review. It works with PowerShell and C++. The repository describes itself as: Directory Services Internals (DSInternals) PowerShell Module and Framework. The licence is MIT.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 917bc84. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Code Review loads about 4k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 1,920 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from MichaelGrafnetter/DSInternals at commit 917bc84, republished under its MIT licence (© MichaelGrafnetter). 1,920 words, ~4,047 tokens.
.claude/skills/code-review/SKILL.md (or your agent's skills folder).These instructions guide code reviews for the DSInternals repository, which contains C#, C++/CLI, and PowerShell code for Active Directory security auditing, offline database manipulation, and password management. Focus on higher-level concerns that require expert judgment rather than stylistic or syntactic issues handled by automated tooling.
If there are no code changes to review, perform a review of the entire codebase based on these guidelines to identify potential improvements or issues. Do not rely solely on targeted searches for specific artefacts. Systematically read all source files to ensure comprehensive coverage. For each file read, apply all the review priorities documented below. Do not skip files even if they appear simple—security issues often hide in seemingly innocuous code.
Critical Security Concerns (Especially Important for AD Security Tooling):
SecureString where appropriate for password inputArray.Clear() or CryptographicOperations.ZeroMemory() in finally blocksRandomNumberGenerator for cryptographically secure random bytes, never System.RandomCryptographicOperations.FixedTimeEquals() to prevent timing attacksPath.GetFullPath() and validate paths are within expected directoriesToString() overrides don't expose sensitive fieldsCryptographicException appropriately; avoid leaking information about why decryption failedPerformance Considerations:
Span<T>, stackalloc, or object pooling where appropriateConfigureAwait(false) in library code (DSInternals Framework) to avoid deadlocks and improve performanceasync void except for event handlers; use async Task insteadCancellationToken for long-running operations (database enumeration, RPC calls)ValueTask over Task for hot paths that often complete synchronously.Result, .Wait(), or .GetAwaiter().GetResult() in async contexts)Task.Run() to wrap synchronous code in library methods; let the caller decideCompatibility Requirements:
Integration Points:
Code Correctness:
Design Quality:
Test Quality:
Native Code Quality:
std::unique_ptr and std::vector over raw pointers and C-style arrays where possibleSecureZeroMemory() to clear sensitive data before freeingMIDL_user_allocate() with MIDL_user_free()__try/__except) for Win32 exceptions where appropriateC++/CLI Security:
/GS (Buffer Security Check) compiler flag is enabledSafeInt<T> or check for overflow before arithmetic operations on sizes/lengths_s suffixed functions (strcpy_s, memcpy_s, sprintf_s) over unsafe versionsprintf-family functions_alloca() or prefer heap allocation for variable-sized buffersCmdlet Quality:
Documentation:
The following are handled by automated tooling and don't need review comments:
.editorconfig and analyzers)© MichaelGrafnetter, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/code-review of MichaelGrafnetter/DSInternals.
Open the folder on GitHubat commit 917bc84
Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Code Review this skillMichaelGrafnetter/DSInternals | 2k | — | ~4k | Automated safety check: Pass | MIT | |
| ONNX Runtime Shape Inference Safety Auditmicrosoft/onnxruntime | 22k | — | ~3.3k | Automated safety check: Pass | MIT | |
| Qt C++ Code Reviewx-tools-author/x-tools | 1.1k | 2 repos | ~4.3k | Automated safety check: Pass | BSD-3-Clause | |
| Qt Cpp ReviewSerial-Studio/Serial-Studio | 7.2k | — | ~4.3k | Automated safety check: Pass | Custom licence | |
| SeekDB Code Reviewoceanbase/seekdb | 3.1k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| OpenROAD PR ReviewThe-OpenROAD-Project/OpenROAD | 3.2k | — | ~1.4k | Automated safety check: Pass | BSD-3-Clause |
microsoft/onnxruntime
Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs.
x-tools-author/x-tools
Read-only review of Qt6 C++ code that combines a deterministic lint script with six parallel analysis agents and reports only high-confidence issues.
Serial-Studio/Serial-Studio
Qt6/C++ deep code review for Serial Studio. An agent skill from Serial-Studio/Serial-Studio.
oceanbase/seekdb
Reviews seekdb pull requests and diffs for real defects in correctness, resources, concurrency, security and tests, reporting only Blocker or Major findings.
The-OpenROAD-Project/OpenROAD
Reviews an OpenROAD pull request in the project's priority order and prints draft review notes for a human reviewer to inspect and post.
hpcc-systems/HPCC-Platform
Code review checklist for the HPCC Platform. An agent skill from hpcc-systems/HPCC-Platform.
MichaelGrafnetter/DSInternals
Ensure that C and C++/CLI types are documented with XML comments and follow best practices for documentation.
MichaelGrafnetter/DSInternals
Prepare the DSInternals project for a new release by updating version numbers, release notes, and changelog.
MichaelGrafnetter/DSInternals
Update copyright year references across the project at the beginning of each calendar year.
Works with
Categories
Perform a systematic code review of all source files, focusing on security, performance, backwards compatibility, and design principles. Code Review is an agent skill from MichaelGrafnetter/DSInternals. Perform a systematic code review of all source files, focusing on security, performance, backwards compatibility, and design principles.
Code Review fits situations like: tasks that involve Code review.
Run `npx skills add MichaelGrafnetter/DSInternals --skill code-review -a claude-code`. Or copy the skill folder (.agents/skills/code-review in MichaelGrafnetter/DSInternals) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add MichaelGrafnetter/DSInternals --skill code-review -a codex`. Or copy the skill folder (.agents/skills/code-review in MichaelGrafnetter/DSInternals) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MichaelGrafnetter/DSInternals --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.
SKILL.md names no scripts, command-line tools or credentials: Code Review is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Code Review: ONNX Runtime Shape Inference Safety Audit (microsoft/onnxruntime, 22k stars), Qt C++ Code Review (x-tools-author/x-tools, 1.1k stars), Qt Cpp Review (Serial-Studio/Serial-Studio, 7.2k stars) and SeekDB Code Review (oceanbase/seekdb, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
MichaelGrafnetter (a GitHub user) maintains it in MichaelGrafnetter/DSInternals, which has 1,968 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 11, 2026.
Source: MichaelGrafnetter/DSInternals on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.