Official agent skill

ONNX Runtime Shape Inference Safety Audit

by microsoft in microsoft/onnxruntime

Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs.

OfficialMITAuto-check passedSecurity

Install ONNX Runtime Shape Inference Safety Audit

skills CLI
$ npx skills add microsoft/onnxruntime --skill contrib-op-shape-inference-memory-safety -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/onnxruntime contrib-op-shape-inference-memory-safety --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/onnxruntime.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/contrib-op-shape-inference-memory-safety .claude/skills/contrib-op-shape-inference-memory-safety && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
contrib-op-shape-inference-memory-safety
GitHub stars
22k
Token cost
~3.3k tokens
SKILL.md length
1,339 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs.

  • Works in 7 steps: The pattern → The sink (why the write is not caught) → Audit technique — always sweep siblings → …
  • Reviewing a contrib op's shape inference for output index bugs
  • SKILL.md covers 1. The pattern, 2. The sink (why the write is…, 3. Audit technique — always… and 4. Fix patterns, plus 4 more sections
  • Calls git, cmake and python3

What it does

The skill targets one bug class: a TypeAndShapeInference function that guards a write with getNumOutputs() > N but then writes an output index greater than N. Because trailing outputs can be declared optional, a node with fewer outputs is schema-valid and passes the model checker, yet the write lands past the end of the inference context's output vector. A table lists affected attention operators such as DecoderAttention and MultiHeadAttention.

The scope is schema-level shape inference in onnxruntime/core/graph/contrib_ops and shape_inference_functions.cc, which runs once during Graph::Resolve at model load and does not depend on the execution provider. Operator kernels allocate outputs through a bounds-safe call and are a separate concern. The skill also explains why the bad write is not caught, since the context's output type vector is sized to the node's actual outputs.

When your agent uses it

  • Reviewing a contrib op's shape inference for output index bugs
  • Fixing a guard that allows fewer outputs than the code writes
  • Auditing optional trailing outputs in ONNX Runtime operator schemas

Example prompts

  • “Audit the shape inference for MultiHeadAttention for writes past the declared outputs.”
  • “This TypeAndShapeInference checks getNumOutputs() > 1 but writes output index 2. Fix it.”
  • “Scan bert_defs.cc for output-index guards that do not match the indices they write.”

Requirements

  • A checkout of the ONNX Runtime repository

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. The pattern
  2. The sink (why the write is not caught)
  3. Audit technique — always sweep siblings
  4. Fix patterns
  5. Test recipe
  6. Process / wording conventions
  7. Audit checklist (per-operator review)

What it can do on your machine

Read from SKILL.md and the folder at commit a477eff. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • cmake
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

ONNX Runtime Shape Inference Safety Audit loads about 3.3k tokens when it runs. Until then it costs about 109 tokens; SKILL.md has 1,339 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~109
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/onnxruntime at commit a477eff, republished under its MIT licence (© microsoft). 1,339 words, ~3,288 tokens.

Download SKILL.mdSave it as .claude/skills/contrib-op-shape-inference-memory-safety/SKILL.md (or your agent's skills folder).
name
contrib-op-shape-inference-memory-safety
description
Audit and fix out-of-range output writes in ONNX Runtime operator shape-inference functions. Use when reviewing or fixing a contrib (or standard) op TypeAndShapeInference where a getNumOutputs() guard precedes a write to a higher output index - optional trailing outputs make a smaller output count schema-valid, so getOutputType(index) can run one past the declared outputs at Graph::Resolve.

Contrib-Op Shape-Inference Output-Index Safety

Reusable method for finding and fixing the bug class where an operator's TypeAndShapeInference function guards an output write with getNumOutputs() > N but then writes an output index greater than N. For a node that declares fewer outputs, the written index is past the end of the inference context's output vector.

Scope: schema-level shape inference in onnxruntime/core/graph/contrib_ops/*.cc and shape_inference_functions.cc. This runs once during Graph::Resolve (model-load time), EP-agnostic - there is no per-EP (CPU/CUDA/ROCm) kernel duplicate of this code to chase. Op kernels allocate outputs via the bounds-safe OpKernelContext::Output(index) and are a separate concern.

1. The pattern

cpp
// onnxruntime/core/graph/contrib_ops/bert_defs.cc  (before)
propagateElemTypeFromInputToOutput(ctx, 0, 0);
if (ctx.getNumOutputs() > 1) {                       // guard says "> 1"
  propagateElemTypeFromInputToOutput(ctx, 0, 1);
  propagateElemTypeFromInputToOutput(ctx, 0, 2);     // but writes index 2
}

The guard getNumOutputs() > 1 admits a node with exactly 2 outputs (indices 0, 1), yet the body writes index 2. The implication "> 1 ⇒ index 2 exists" is false: > 1 only guarantees indices 0 and 1.

Why a smaller output count is valid

Trailing outputs declared OpSchema::Optional lower min_output. ONNX derives min_output = number of required outputs, max_output = total declared. The model checker (checker::check_node) only enforces min_output <= N <= max_output.

OpOutput declsmin / maxA 2-output node?
DecoderAttentionout (req), new_key_cache (Opt), new_value_cache (Opt)1 / 3passes checker
MultiHeadAttentionout (req), present_key (Opt), present_value (Opt), qk (Opt)1 / 4passes checker
DecoderMaskedMultiHeadAttentionout (req) + 3 Optional1 / 4passes checker

So a node with output=['out','present_key'] is schema-valid, passes the checker, and then reaches the index-2 write. A passing checker is not a guarantee the index is in range.

2. The sink (why the write is not caught)

cpp
// onnxruntime/core/graph/graph.cc  -  InferenceContextImpl
const TypeProto* getInputType(size_t index) const override {
  return node_.InputDefs().at(index)->TypeAsProto();   // .at()  -> bounds-checked
}
TypeProto* getOutputType(size_t index) override {
  return &node_output_types_[index];                   // operator[]  -> NOT bounds-checked
}
  • node_output_types_ is sized to node.OutputDefs().size() in the InferenceContextImpl ctor, so for a 2-output node it has 2 elements; getOutputType(2) returns one past the end.
  • getInputType uses .at() (would throw on a bad index); getOutputType uses raw operator[] (no check) - the asymmetry is the root cause.
  • The call runs at Graph::Resolve → InferAndVerifyTypeMatch → RunInferencing. The surrounding ORT_TRY/ORT_CATCH(const std::exception&) only catches thrown fail_shape_inference; a raw out-of-range operator[] does not throw, so the catch does not help.
  • Because this is schema-level inference, it is EP-independent - no CUDA/ROCm copy.

3. Audit technique — always sweep siblings

Do not stop at the reported function. Grep every shape-inference guard and compare its threshold against the highest output index written before the next guard.

bash
git grep -n 'getNumOutputs' -- \
  onnxruntime/core/graph/contrib_ops/*.cc \
  onnxruntime/core/graph/contrib_ops/shape_inference_functions.cc

For each if (ctx.getNumOutputs() > N) block, find the largest index passed to propagateElemTypeFromInputToOutput(ctx, _, index) / updateOutputShape(ctx, index, _) / getOutputType(index) inside it. Rule: the guard must require strictly more outputs than the highest index written (write index k ⇒ guard must ensure getNumOutputs() > k).

Correct exemplars already in the tree to copy:

ExemplarPatternWhy it is safe
BaseGroupQueryAttention...if (getNumOutputs() >= 3) then writes idx 2guard covers highest index
PagedAttention...nested > 1 + inner if (getNumOutputs() != 3) fail_shape_inferencefails before any write
EmbedLayerNormalizationShapeInference> 2 then writes idx 2fixed by PR #28176 (precedent)
SkipLayerNormalizationShapeInferenceeach idx k guarded by > kper-index guard

Gotcha — conditional writes can hide a vacuous audit. A write may sit behind an inner condition (e.g. hasInputShape(past_key_index) before writing index 2). The site is still a bug, but you can only observe it when that inner condition is also satisfied. Keep this in mind both for the audit and for tests (§5).

4. Fix patterns

Point fix (required): raise the guard to cover the highest index written.

cpp
// before
if (ctx.getNumOutputs() > 1) { ... writes idx 2 ... }
// after
if (ctx.getNumOutputs() > 2) {  // both present_key (idx 1) AND present_value (idx 2)
  ...
}

Justify the threshold with the op's output semantics. For these attention ops the two trailing outputs - present_key (idx 1) and present_value (idx 2) for MultiHeadAttention, new_key_cache / new_value_cache for DecoderAttention (see the §1 table for each op's exact output names) - are a both-or-neither pair: there is no valid configuration that emits one without the other, so requiring all three outputs before populating indices 1 and 2 is behavior-preserving. (PagedAttention encodes the same invariant via its nested != 3 check.)

Defense-in-depth (recommended): bound the sink so a future author cannot reintroduce the class.

cpp
// onnxruntime/core/graph/graph.cc  -  InferenceContextImpl::getOutputType
TypeProto* getOutputType(size_t index) override {
  if (index >= node_output_types_.size()) {
    fail_type_inference("output index ", index, " is out of range; node has ",
                        node_output_types_.size(), " outputs");
  }
  return &node_output_types_[index];
}

This mirrors getInputType's .at() and the existing bounds checks in the sibling DataPropagationContextImpl. Placing it at the base layer transitively protects the NHWC and quantization wrapper contexts. After the point fix this branch is unreachable through a normal model (the guard already prevents the out-of-range index), so it is pure defense-in-depth. Its failure mode is build-dependent: with exceptions enabled, fail_type_inference raises InferenceError (a std::exception), caught by the existing ORT_CATCH(const std::exception&) around RunInferencing and surfaced as a clean load-time error; under ORT_NO_EXCEPTIONS it is not compiled out - ONNX's no-exceptions path prints the message to std::cerr and calls abort(), a deterministic fail-fast (consistent with getInputType's .at(), which likewise terminates under no-exceptions). Either way the result is a controlled failure rather than an out-of-range write.

Show full SKILL.md (603 more words)Show less

5. Test recipe

Tests live in onnxruntime/test/contrib_ops/*.cc and are auto-globbed into the onnxruntime_provider_test target by cmake/onnxruntime_unittests.cmake (test/contrib_ops/*.cc pattern) - no cmake edit needed for a new file. See the ort-test skill for the executable taxonomy (onnxruntime_provider_test vs onnxruntime_test_all).

Rules that make the regression test actually guard the fix:

  1. Drive through Model + Graph::Resolve, not ONNX's standalone TestShapeInference. Only the full resolve path constructs the real InferenceContextImpl and hits the getOutputType sink described in §2. A standalone ONNX shape-inference helper uses a different context and bypasses the sink, so it cannot reproduce the bug.
  2. Negative tests must be NON-VACUOUS - they must actually enter the write branch on pre-fix source. If a write is gated by an inner condition (§3 gotcha), satisfy it: e.g. for MultiHeadAttention/DecoderMaskedMultiHeadAttention, supply a shaped past_key (and past_sequence_length / past_present_share_buffer as the op requires) so the index-2 block runs. A negative test that only supplies query skips the block and passes even on pre-fix source - regression-proof in name only.
  3. Add positive (all-outputs) cases: a node with every output present must still infer the trailing output types - proves the tightened guard did not over-restrict.
  4. Keep tests throw-free post-fix so they are valid under ORT_NO_EXCEPTIONS. Any case that is expected to fail_shape_inference (throws) must be excluded with #ifndef ORT_NO_EXCEPTIONS. The "2 outputs must not go out of range" case is throw-free after the point fix and is safe in all builds.

Verify the negative test is non-vacuous (sanitizer A/B) - the most reliable way to prove a negative test enters the previously-out-of-range branch: build the test at the pre-fix commit with AddressSanitizer and confirm it flags the out-of-range output access; then confirm it is clean after the fix.

bash
# Functional run (any Debug build):
cmake --build build/Linux/Debug --target onnxruntime_provider_test -j"$(nproc)"
./build/Linux/Debug/onnxruntime_provider_test \
  --gtest_filter='AttentionOptionalOutputsShapeInferenceTest.*'

# A/B proof (isolated worktree at the pre-fix commit, CPU-only Debug + sanitizer):
git worktree add --detach ../ort-prefix-check <fix_commit>~1
# copy the new test file in, then:
python3 tools/ci_build/build.py --build_dir build/asan --config Debug --parallel \
  --skip_tests --enable_address_sanitizer --skip_submodule_sync \
  --cmake_generator Ninja --target onnxruntime_provider_test
# Pre-fix: the negative tests fail (the sanitizer flags the out-of-range output access).
# Post-fix (cherry-pick the guard fix): all tests pass, no sanitizer report.

6. Process / wording conventions

  • Run lintrunner -a before pushing so the CLANGFORMAT / Python-format gate passes. See the ort-lint skill.
  • Use correctness/robustness framing in code, comments, commit messages, and the PR body
    • describe the change as fixing an optional-output guard, not as a security fix. This matches repo convention (compare python-kwargs-setattr-security) and keeps the PR neutral.

7. Audit checklist (per-operator review)

When reviewing or hardening any operator implementation or its shape inference:

  • Read the op's spec - ONNX standard op page, or for a contrib op its OpSchema registration (.Input/.Output/.Attr, and Optional/Variadic markers). A local ONNX checkout has the standard-op spec pages; contrib ops are defined only in ORT.
  • Enumerate all inputs, attributes, and outputs, noting which are optional and the resulting min/max input and output counts.
  • Validate every input/attribute before indexing into it, to avoid out-of-range reads (which can cascade into worse failures). Match each output-index write to a guard that guarantees the index is in range (§3 rule).
  • Prefer ORT_RETURN_IF / ORT_RETURN_IF_NOT for validation; use ORT_ENFORCE in constructors. In shape inference use fail_shape_inference / fail_type_inference.
  • Use SafeInt<> / narrow<>() for index and size arithmetic and casts to avoid overflow or truncation that yields a wrong index. See core/common/safeint.h and docs/Coding_Conventions_and_Standards.md.
  • Ensure tests build and pass under no-exceptions builds; #ifndef ORT_NO_EXCEPTIONS around any case expected to throw.
  • Exclude EPs known not to support the op, with a comment explaining why.
  • Check whether other EPs (notably CUDA/ROCm) implement the same op and whether the same issue exists there. (For shape inference specifically, the logic is EP-agnostic and single-source - confirm there is no kernel-side analogue.)

References

  • PR #28176 - "Fix ... in EmbedLayerNormalizationShapeInference": the precedent that fixed the identical > 1 → > 2 primitive in one site; the sibling attention sites were missed, motivating the sweep in §3.
  • PR #29268 - this fix: guards corrected in DecoderAttention / MultiHeadAttention / DecoderMaskedMultiHeadAttention shape inference, plus the getOutputType bounds check and non-vacuous regression tests.
  • Sibling skill: ort-test (test executables, --gtest_filter, contrib-op test layout); ort-lint (lintrunner -a); ort-build (build flags, ASan).

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/contrib-op-shape-inference-memory-safety of microsoft/onnxruntime.

Open the folder on GitHubat commit a477eff

Compare with similar skills

ONNX Runtime Shape Inference Safety Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

ONNX Runtime Shape Inference Safety Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
ONNX Runtime Shape Inference Safety Audit this skillmicrosoft/onnxruntime22k—~3.3kAutomated safety check: PassMIT
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Thorough Code Reviewpretend1111/claude-desktop-app4961 repos~502Automated safety check: PassCustom licence
Code ReviewMichaelGrafnetter/DSInternals2k—~4kAutomated safety check: PassMIT
WordPress Code GuardamElnagdy/guard-skills1.3k—~2.4kAutomated safety check: PassMIT
Zeroization Audittrailofbits/skills7.4k4 repos~5.9kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Thorough Code Review

    pretend1111/claude-desktop-app

    Reviews code or recent changes for bugs, security issues, performance problems and maintainability, reporting findings by severity with the reason and a fix.

    496 GitHub starsUsed in 1 repo~502 tokens
    DevelopmentAuto-check passed
  • Code Review

    MichaelGrafnetter/DSInternals

    Perform a systematic code review of all source files, focusing on security, performance, backwards compatibility, and design principles.

    2k GitHub stars~4k tokensUpdated 27 days ago
    DevelopmentAuto-check passed
  • WordPress Code Guard

    amElnagdy/guard-skills

    Reviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries.

    1.3k GitHub stars~2.4k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Zeroization Audit

    trailofbits/skills

    Official

    Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis.

    7.4k GitHub starsUsed in 4 repos~5.9k tokens
    SecurityAuto-check: notes
  • Constant-Time Analysis

    trailofbits/skills

    Official

    Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

    7.4k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check: notes

More from microsoft/onnxruntime

All 14 skills in this repo
  • Official

    Explains why editing CUTLASS fused-MHA headers in ONNX Runtime can leave stale CUDA kernels after an incremental build, and how to force and verify a real rebuild.

    22k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • ONNX Runtime Source Build

    microsoft/onnxruntime

    Official

    Builds ONNX Runtime from source with its build scripts, explaining the update, build and test phases, key flags and where the build output lands.

    22k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • ONNX Runtime CI Management

    microsoft/onnxruntime

    Official

    Triggers, re-runs and unblocks the CI checks on an ONNX Runtime pull request, after diagnosing whether a failure is transient or needs a code change.

    22k GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • ONNX Runtime Release Notes

    microsoft/onnxruntime

    Official

    Drafts ONNX Runtime release notes from commit history and contributor metadata using named presets for the full runtime or a scoped component.

    22k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • ONNX Runtime Test Runner

    microsoft/onnxruntime

    Official

    Runs and debugs ONNX Runtime tests: Google Test executables for C++ and unittest or pytest for Python, with filters and build-directory guidance.

    22k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Official

    Runs the ONNX Runtime transformers Python tests against a GPU wheel and proves the cuDNN flash attention path was used rather than a silent fallback.

    22k GitHub stars~2.9k tokensUpdated today
    Auto-check passed

Works with

Questions about ONNX Runtime Shape Inference Safety Audit

What does ONNX Runtime Shape Inference Safety Audit do?

Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs. The skill targets one bug class: a TypeAndShapeInference function that guards a write with getNumOutputs() > N but then writes an output index greater than N. Because trailing outputs can be declared optional, a node with fewer outputs is schema-valid and passes the model checker, yet the write lands past the end of the inference context's output vector.

When should I use ONNX Runtime Shape Inference Safety Audit?

ONNX Runtime Shape Inference Safety Audit fits situations like: reviewing a contrib op's shape inference for output index bugs; fixing a guard that allows fewer outputs than the code writes; auditing optional trailing outputs in ONNX Runtime operator schemas.

How do I install ONNX Runtime Shape Inference Safety Audit in Claude Code?

Run `npx skills add microsoft/onnxruntime --skill contrib-op-shape-inference-memory-safety -a claude-code`. Or copy the skill folder (.github/skills/contrib-op-shape-inference-memory-safety in microsoft/onnxruntime) into .claude/skills/contrib-op-shape-inference-memory-safety in your project. Claude Code loads it when a task matches its description.

How do I install ONNX Runtime Shape Inference Safety Audit in Codex?

Run `npx skills add microsoft/onnxruntime --skill contrib-op-shape-inference-memory-safety -a codex`. Or copy the skill folder (.github/skills/contrib-op-shape-inference-memory-safety in microsoft/onnxruntime) into .agents/skills/contrib-op-shape-inference-memory-safety in your project. Codex loads it when a task matches its description.

Can I use ONNX Runtime Shape Inference Safety Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/onnxruntime --skill contrib-op-shape-inference-memory-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/contrib-op-shape-inference-memory-safety, .gemini/skills/contrib-op-shape-inference-memory-safety, .github/skills/contrib-op-shape-inference-memory-safety and .opencode/skills/contrib-op-shape-inference-memory-safety in your project.

What does ONNX Runtime Shape Inference Safety Audit need to run?

Going by SKILL.md and its folder, ONNX Runtime Shape Inference Safety Audit needs the command-line tools its instructions call (git, cmake and python3). Our summary lists: A checkout of the ONNX Runtime repository.

Does ONNX Runtime Shape Inference Safety Audit access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is ONNX Runtime Shape Inference Safety Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does ONNX Runtime Shape Inference Safety Audit use?

ONNX Runtime Shape Inference Safety Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does ONNX Runtime Shape Inference Safety Audit use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to ONNX Runtime Shape Inference Safety Audit?

Skills that share tags, products or a category with ONNX Runtime Shape Inference Safety Audit: CodeQL Security Scan (trailofbits/skills, 7.4k stars), Thorough Code Review (pretend1111/claude-desktop-app, 496 stars), Code Review (MichaelGrafnetter/DSInternals, 2k stars) and WordPress Code Guard (amElnagdy/guard-skills, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains ONNX Runtime Shape Inference Safety Audit?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/onnxruntime, which has 22,039 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 9, 2026.

Source: microsoft/onnxruntime on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.