Cyberowlai
karimhabush/cyberowl
Check if recent cybersecurity alerts from 10 international CERTs affect your current project.
Audit SkiaSharp's native dependencies for security vulnerabilities and CVEs, including Component Governance (CG) alerts from the combined skiasharp-package Azure DevOps pipeline.
$ npx skills add mono/SkiaSharp --skill security-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mono/SkiaSharp security-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mono/SkiaSharp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-audit .claude/skills/security-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-audit" agent skill from https://github.com/mono/SkiaSharp/tree/main/.agents/skills/security-audit into .claude/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mono/SkiaSharp/tree/main/.agents/skills/security-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mono/SkiaSharp --skill security-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mono/SkiaSharp security-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mono/SkiaSharp.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/security-audit .agents/skills/security-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-audit" agent skill from https://github.com/mono/SkiaSharp/tree/main/.agents/skills/security-audit into .agents/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mono/SkiaSharp --skill security-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mono/SkiaSharp security-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mono/SkiaSharp.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/security-audit .cursor/skills/security-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-audit" agent skill from https://github.com/mono/SkiaSharp/tree/main/.agents/skills/security-audit into .cursor/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mono/SkiaSharp.git --path .agents/skills/security-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mono/SkiaSharp --skill security-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mono/SkiaSharp security-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mono/SkiaSharp.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/security-audit .gemini/skills/security-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/mono/SkiaSharp/tree/main/.agents/skills/security-audit into .gemini/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mono/SkiaSharp security-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mono/SkiaSharp --skill security-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mono/SkiaSharp.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/security-audit .github/skills/security-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/mono/SkiaSharp/tree/main/.agents/skills/security-audit into .github/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mono/SkiaSharp --skill security-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mono/SkiaSharp security-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mono/SkiaSharp.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/security-audit .opencode/skills/security-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/mono/SkiaSharp/tree/main/.agents/skills/security-audit into .opencode/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-auditAudit SkiaSharp's native dependencies for security vulnerabilities and CVEs, including Component Governance (CG) alerts from the combined skiasharp-package Azure DevOps pipeline.
Security Audit is an agent skill from mono/SkiaSharp. Audit SkiaSharp's native dependencies for security vulnerabilities and CVEs, including Component Governance (CG) alerts from the combined skiasharp-package Azure DevOps pipeline. Read-only investigation that produces a status report with recommendations. Use when user asks to: - Audit security issues or CVEs - Check CVE status across dependencies - Find security-related issues and their PR coverage - Get an overview of open vulnerabilities - See what security work is pending - Check Component Governance alerts -…
Its SKILL.md is about 5.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files, including scripts and reference files (for example `evals/evals.json`, `references/cg-alerts.md` and `references/chrome-releases.md`).
It sits in Security, covering Vulnerability scanning, Security review and Dependency management. It works with Azure DevOps. The repository describes itself as: SkiaSharp is a cross-platform 2D graphics API for .NET platforms based on Google's Skia Graphics Library. It provides a comprehensive 2D API that can be used across mobile… The licence is MIT.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit a74f7f9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 7 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
gitpython3azFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Audit loads about 5.7k tokens when it runs, and up to ~26k if it reads all its reference files. Until then it costs about 227 tokens; SKILL.md has 2,339 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mono/SkiaSharp at commit a74f7f9, republished under its MIT licence (© mono). 2,339 words, ~5,704 tokens.
.claude/skills/security-audit/SKILL.md (or your agent's skills folder). This skill also uses 16 other files; get the full folder from GitHub.Investigate the security status of SkiaSharp's native dependencies. Skia core is treated as the product itself (not just a dependency) and gets a deeper, commit-level resolution process. Third-party deps and Component Governance alerts are audited alongside it and combined into a single unified report.
ℹ️ This skill is read-only. To create PRs and fix issues, use the
native-dependency-updateskill.
main vs Beta milestone coverage, channel milestones + Skia commitsrender-security-audit-md.py)query-chrome-releases.py) — see Chrome Releasesquery-milestone-schedule.py) — main vs Beta heads-up + release-notes support-tier drift, see Milestone Schedulevalidate-security-audit.py)render-security-audit.py)Search mono/SkiaSharp open issues for:
Search PRs in both mono/SkiaSharp and mono/skia for dependency updates already in flight.
🔍 The Chrome Releases blog often discloses Skia CVEs before NVD processes them. This step provides early detection and cross-validation.
See references/chrome-releases.md for full details on the data source, script usage, and AI review instructions.
python3 .agents/skills/security-audit/scripts/query-chrome-releases.py \
--verbose --output output/ai/chrome-releases-cache.jsonThis takes ~10-30 seconds (fetches RSS feed pages). Cache is reused if < 24 hours old.
Deterministic (regex): Read structured_cves[] from the JSON output. These are
high-confidence CVEs extracted from the known blog format. Each has a CVE ID, severity,
component, bug ID, and milestone already parsed.
AI review (broad): Scan posts[].text_content for anything the regex missed:
After the NVD query in Step 5, compare results:
| Chrome Releases | NVD | Interpretation |
|---|---|---|
| ✅ Found | ✅ Found | Normal — use NVD CVSS, Chrome Releases for milestone |
| ✅ Found | ❌ Not found | Early disclosure — NVD may be delayed. Use Chrome severity. |
| ❌ Not found | ✅ Found | Vendor bulletin CVE (Android/Huawei) — not in Chrome stable |
Set the source field on each CVE object: "both", "chrome_releases", or "nvd".
🗓️ Scheduling + channel context, not a security check on its own. It tells us whether
mainis keeping up with the Chrome Beta milestone and how much lead time remains before the next milestone reaches stable.
main is the SkiaSharp front line and tracks the Chrome Beta milestone; as milestones
graduate Beta → Stable → Extended stable, a release/<major>.<M>.x line is cut from a main that
was already on M. So "where we are" = main's milestone, and the signal that matters is
main_milestone >= beta_channel_milestone. See
references/milestone-schedule.md for the model, endpoints,
and flags.
python3 .agents/skills/security-audit/scripts/query-milestone-schedule.py \
--output output/ai/milestone-schedule-cache.jsonThis reads main's milestone + major from scripts/VERSIONS.txt, fetches the live channels and the
upcoming schedule, and prints prioritized heads-up alerts:
| Level | Meaning |
|---|---|
🔴 critical | main < Beta and a newer milestone already ships on a stable-class channel — the bump is overdue and reaching non-preview users. |
🟠 urgent | main < Beta — the front line is behind; bump main to the Beta milestone. |
❓ unknown | The Beta milestone couldn't be read (Chromium Dash down) — signal not evaluated. Don't treat as OK; re-run. |
🟡 watch | A milestone past main branches within the window — start preparing. |
🟢 ok | main >= Beta — front line current. |
support block)The same run also drift-checks the release-notes support paths in
scripts/infra/docs/versions.json (two hand-maintained lists, stable + preview) against
the live channels — detection only, the fix is a manual edit of that file (spec §3.5). The
verdict is in the support object of the JSON (status: ok | warn | drift | absent)
and printed under "Support tiers (versions.json)":
support.status | Meaning | Audit action |
|---|---|---|
🟢 ok | stable covers Chrome Stable (or Extended-stable during the promotion gap) and preview tracks Beta-or-newer. | None. |
🟡 warn | Plausible but worth noting (e.g. stable ahead of Chrome Stable, preview empty or trailing Beta). | Mention in the prose summary. |
🔴 drift | stable is behind/off-channel, or preview is not a real preview. | Raise a finding in nextSteps: edit versions.json support to the milestones we actually ship. |
This is a docs-grouping check, not a CVE — but a drift verdict means the website is
mis-stating what is supported, so treat it as a finding.
meta.status + the upcoming table answer it directly.nextSteps when status == "behind" (or a watch
milestone) also carries HIGH/CRITICAL CVEs from the Chrome Releases / NVD passes; cite the
target milestone's stable date as the deadline. Treat a critical heads-up as a finding
even with no GitHub issue filed.release/*.x line is missing a within-milestone Skia backport, use the
Skia CVE resolution process (merge-base ancestry) — the
schedule tool only covers milestone alignment.⚠️ CRITICAL: Never trust
cgmanifest.jsonblindly. Always verify versions against the actual submodule, DEPS file, and source headers. cgmanifest.json is manually maintained and can drift. Report any mismatches as findings.
🛑 MANDATORY: Fetching the upstream
google/skiabranch is required, not optional. Adding a git remote and fetching is read-only — it does not modify any tracked files. Without independent verification of the upstream merge point, the audit would trust cgmanifest.json circularly, defeating the purpose of verification.
# 1. Get the actual submodule commit
git submodule status externals/skia
# Output: 8c99e432... externals/skia (the mono/skia fork commit)
# 2. Read the REAL milestone from the source
cat externals/skia/include/core/SkMilestone.h
# Look for: #define SK_MILESTONE NNN
# 3. Find the upstream google/skia merge point
cd externals/skia
git log --oneline --merges --grep="chrome/m" -5 HEAD
# Find the merge commit that brought in chrome/mNNN
# 4. Add the upstream remote and fetch (read-only)
git remote add upstream https://github.com/google/skia.git 2>/dev/null || \
git remote set-url upstream https://github.com/google/skia.git
git fetch upstream chrome/mNNN
git log --format="%H %s" -1 FETCH_HEAD
# This gives the independently-verified upstream_merge_commit
# 5. Confirm upstream is ancestor of our fork
git merge-base --is-ancestor FETCH_HEAD <merge-parent> && echo "VERIFIED"Compare against cgmanifest.json and report mismatches:
| Field | Source of truth | cgmanifest.json field |
|---|---|---|
| Milestone | SkMilestone.h in submodule | chrome_milestone |
| Fork commit | git submodule status | git entry commitHash |
| Upstream commit | git fetch upstream chrome/mNNN tip | upstream_merge_commit |
See references/third-party-deps.md for the full table of
header files and the googlesource mirror URL pattern. In short: read pinned commit hashes
from externals/skia/DEPS, then fetch each dependency's version header at that commit and
parse the version string.
ANGLE is a separate native component (Windows-only, for WinUI). It is NOT part of the Skia submodule.
grep ANGLE scripts/VERSIONS.txt
# Output: ANGLE release chromium/NNNNANGLE has its own submodules (third_party/zlib, jsoncpp, vulkan-deps,
astc-encoder/src) that must also be tracked. See
references/third-party-deps.md
for details. Flag any missing from cgmanifest.json as a coverage gap.
The versionVerification array in the JSON report must include ALL dependencies from
ALL sources:
| Source | What to include |
|---|---|
"Skia DEPS" | All deps from externals/skia/DEPS + Skia itself |
"ANGLE" | ANGLE itself (version from VERSIONS.txt) |
"ANGLE submodule" | ANGLE's submodules (zlib, jsoncpp, vulkan-deps, astc-encoder) |
"GPU/Graphics" | VulkanMemoryAllocator, SPIRV-Cross, D3D12Allocator from DEPS |
"Supporting" | piex, wuffs, dng_sdk, buildtools from DEPS |
Each entry must have a source field and a cgmanifestVersion field (null if missing).
Report mismatches as findings.
🛑 Skia is the product, not just a dependency. Every Skia CVE must be resolved to a specific fix commit, branch, cherry-pick test, and reachability assessment. Classification by milestone alone is INCOMPLETE.
See references/skia-cve-resolution.md for the full process, including:
keywordSearch=Skia)issues.chromium.org/issues/NNNNN referencesgit fetch upstream chrome/mNNN + git log --grep=<bug_id> to find fix commitsFor libpng, freetype, harfbuzz, libexpat, brotli, zlib, libjpeg-turbo, libwebp, ANGLE submodules, etc.
See references/third-party-deps.md for:
git merge-base --is-ancestor)CG scans Docker container images and build-time dependencies from the combined
skiasharp-package ADO pipeline. CG alerts are invisible to GitHub Issues and
NVD searches alone.
🛑 THIS STEP TAKES 5–7 MINUTES. The CG script queries 60+ jobs across 8+ builds. This is NORMAL and NON-NEGOTIABLE. Use
initial_wait: 600(or higher). Do NOT skip, fabricate empty results, or write placeholder data because it's "taking too long." The validator will reject reports with emptypipelinesor fabricated timestamps.
See references/cg-alerts.md for:
scripts/query-cg-alerts.py) — run ONCE, cache to fileaz devops approach for debuggingalerts array in the report (do NOT summarize)Before flagging anything, verify the CVE actually affects SkiaSharp.
General false positives (apply to any dependency):
Dependency-specific false positives:
🛑 MANDATORY: The audit MUST produce a JSON file conforming to references/report-schema.md. This is the machine-readable output used by dashboards and CI.
Build the JSON object with these top-level keys:
meta — Date, schema version, Skia commit hashes, milestone, upstream verification statussummary — Counts by status category, total CVEs, highest severityversionVerification — One entry per dependency with DEPS commit, verified version, cgmanifest version, match booleanfindings — Array of finding objects sorted by priority then severity. ONE object per dependency (e.g., one "skia" finding containing ALL Skia CVEs regardless of status). Each has dependency, status, cves[], nonChromeCves[], action, notes. The status reflects the WORST-case status among the CVEs.cgAlerts — The complete raw JSON from query-cg-alerts.py (full alerts array, do not summarize)chromeReleases — Chrome Releases blog data. Transform the script's snake_case output (cve_id→cveId, bug_id→bugId, blog_post_url→blogPostUrl) into structuredCves[]. Also copy blogPostUrl onto matching CVEs in findings[].cves[]. See report-schema.md for the full field mapping.nextSteps — Prioritized action items with severity, command, and reason🛑 COMPLETENESS REQUIREMENT: The
findingsarray MUST include every CVE returned by the NVD query (Step 1 of skia-cve-resolution.md). CVEs that are verified as already fixed in our tree are classified as"already_fixed"or"false_positive"— they are NOT dropped from the report. An audit that finds 15 CVEs in NVD but only reports 7 in the JSON is INCOMPLETE and will fail review. The total CVE count insummary.totalCvesmust match the number of CVE objects across all findings.
🛑 ONE FINDING PER DEPENDENCY: Do NOT create multiple finding objects for the same dependency. All CVEs for "skia" go in ONE finding. All CVEs for "libpng" go in ONE finding. Use each CVE's
assessmentfield to distinguish affected/fixed/false_positive. The finding's top-levelstatusreflects the worst-case among its CVEs (e.g., if 3 CVEs are already_fixed but 2 are needs_attention, the finding status is"needs_attention").
Save as output/ai/security-audit-{date}.json.
🛑 MANDATORY: Always validate before rendering. Fix any errors reported.
python3 .agents/skills/security-audit/scripts/validate-security-audit.py \
output/ai/security-audit-{date}.jsonExit codes: 0 = valid, 1 = fixable errors (fix and retry), 2 = fatal.
Warnings are informational — errors must be fixed before proceeding.
🛑 MANDATORY: Always generate both reports.
python3 .agents/skills/security-audit/scripts/render-security-audit.py \
output/ai/security-audit-{date}.json
python3 .agents/skills/security-audit/scripts/render-security-audit-md.py \
output/ai/security-audit-{date}.jsonThis produces:
The HTML renders:
Present the output path to the user:
✅ security-audit-2026-04-10.html (45 KB)
m132 • 2026-04-10 • 12 CVEs • Highest: HIGH
🔴 3 attention · 🆕 2 undiscovered · ⚪ 4 FP · ✅ 5 cleanThe Markdown report was already generated in Step 11. Present a brief summary in the conversation pointing to the generated files:
✅ Reports generated:
• output/ai/security-audit-{date}.json (structured data)
• output/ai/security-audit-{date}.html (interactive dashboard)
• output/ai/security-audit-{date}.md (full markdown for AI review)
m147 • 2026-05-29 • 102 CVEs • Highest: CRITICAL
🔴 0 attention · 🆕 0 undiscovered · ⚪ 1 FP · ✅ 6 clean
📰 Chrome Releases: 146 Skia-relevant CVEs (16 above current milestone)Then highlight the top actionable items from the report:
needs_attention or undiscovered findingsmain behind the Beta milestone, or a milestone branching/going stable soonversions.json support block out of date with the live Chrome channelsThese rules apply to the JSON assembly (Step 9) and are enforced by the renderers:
After audit, use the native-dependency-update skill to act on findings:
For Skia core CVEs, the fix typically requires merging a newer upstream milestone into the fork (or cherry-picking specific fix commits, per the resolution pipeline). This is a significant undertaking — flag it in the report with the milestone gap and the list of required commits.
For CG container alerts, the fix is updating Dockerfiles under
scripts/infra/native/linux/docker/. This does not require a Skia submodule update — only
Docker image rebuilds.
© mono, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 16 other files (scripts, references) in .agents/skills/security-audit of mono/SkiaSharp.
Open the folder on GitHubat commit a74f7f9
Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Audit this skillmono/SkiaSharp | 5.6k | — | ~5.7k | Automated safety check: Pass | MIT | |
| Cyberowlaikarimhabush/cyberowl | 263 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Upgrade Notesgetknit/knit | 130 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | |
| JS Security Auditc0x12c/ai-toolkit | 106 | — | ~1.6k | Automated safety check: Warn | None | |
| Security AuditorFerroxLabs/wayland | 608 | — | ~5.1k | Automated safety check: Pass | Apache-2.0 | |
| Security Checkgocronx-team/gocron | 808 | — | ~690 | Automated safety check: Pass | MIT |
karimhabush/cyberowl
Check if recent cybersecurity alerts from 10 international CERTs affect your current project.
getknit/knit
Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool.
c0x12c/ai-toolkit
Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response.
FerroxLabs/wayland
Becomes a principal security engineer who conducts comprehensive security audits of applications, APIs, and infrastructure using threat modeling and vulnerability analysis methodologies.
gocronx-team/gocron
Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.
ghostsecurity/skills
Ghost Security - Software Composition Analysis (SCA) scanner.
mono/SkiaSharp
Fix bugs in SkiaSharp C bindings. An agent skill from mono/SkiaSharp.
mono/SkiaSharp
Reproduce a SkiaSharp issue systematically and capture structured reproduction results.
mono/SkiaSharp
Triage a SkiaSharp GitHub issue or PR into structured JSON with classification (type, area, platform, severity), suggested response, automatable actions, and companion Markdown/HTML reports.
mono/SkiaSharp
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.
mono/SkiaSharp
Review a Skia upstream merge PR in mono/skia. An agent skill from mono/SkiaSharp.
mono/SkiaSharp
Scout Skia GM (golden master) samples in the externals/skia submodule to find demos worth porting to the SkiaSharp Gallery.
Works with
Categories
Audit SkiaSharp's native dependencies for security vulnerabilities and CVEs, including Component Governance (CG) alerts from the combined skiasharp-package Azure DevOps pipeline. Security Audit is an agent skill from mono/SkiaSharp. Audit SkiaSharp's native dependencies for security vulnerabilities and CVEs, including Component Governance (CG) alerts from the combined skiasharp-package Azure DevOps pipeline.
Security Audit fits situations like: user asks to: - Audit security issues; what security issues are open; check vulnerability status; security overview.
Run `npx skills add mono/SkiaSharp --skill security-audit -a claude-code`. Or copy the skill folder (.agents/skills/security-audit in mono/SkiaSharp) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mono/SkiaSharp --skill security-audit -a codex`. Or copy the skill folder (.agents/skills/security-audit in mono/SkiaSharp) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mono/SkiaSharp --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.
Going by SKILL.md and its folder, Security Audit needs Python for the scripts in its folder and the command-line tools its instructions call (git, python3 and az). Our summary lists: Python 3; Docker.
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.7k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 20k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Security Audit: Cyberowlai (karimhabush/cyberowl, 263 stars), Upgrade Notes (getknit/knit, 130 stars), JS Security Audit (c0x12c/ai-toolkit, 106 stars) and Security Auditor (FerroxLabs/wayland, 608 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mono (a GitHub organization) maintains it in mono/SkiaSharp, which has 5,585 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 7, 2026.
Source: mono/SkiaSharp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.