Hunt Race Condition
sickn33/agentic-awesome-skills
Hunting skill for race condition vulnerabilities. An agent skill from sickn33/agentic-awesome-skills.
Look up running race results across NYRR, Mika Timing, Athlinks, and RaceResult by fuzzy race name, bib, runner name, or athlete history.
$ npx skills add mvanhorn/printing-press-library --skill pp-running-race-results -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mvanhorn/printing-press-library pp-running-race-results --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cli-skills/pp-running-race-results .claude/skills/pp-running-race-results && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pp-running-race-results" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-running-race-results into .claude/skills/pp-running-race-results/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-running-race-results", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-running-race-resultsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mvanhorn/printing-press-library --skill pp-running-race-results -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mvanhorn/printing-press-library pp-running-race-results --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .agents/skills && cp -r skills-src/cli-skills/pp-running-race-results .agents/skills/pp-running-race-results && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pp-running-race-results" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-running-race-results into .agents/skills/pp-running-race-results/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-running-race-results", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mvanhorn/printing-press-library --skill pp-running-race-results -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mvanhorn/printing-press-library pp-running-race-results --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/cli-skills/pp-running-race-results .cursor/skills/pp-running-race-results && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pp-running-race-results" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-running-race-results into .cursor/skills/pp-running-race-results/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-running-race-results", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mvanhorn/printing-press-library.git --path cli-skills/pp-running-race-results--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mvanhorn/printing-press-library --skill pp-running-race-results -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mvanhorn/printing-press-library pp-running-race-results --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/cli-skills/pp-running-race-results .gemini/skills/pp-running-race-results && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pp-running-race-results" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-running-race-results into .gemini/skills/pp-running-race-results/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-running-race-results", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mvanhorn/printing-press-library pp-running-race-resultsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mvanhorn/printing-press-library --skill pp-running-race-results -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .github/skills && cp -r skills-src/cli-skills/pp-running-race-results .github/skills/pp-running-race-results && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pp-running-race-results" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-running-race-results into .github/skills/pp-running-race-results/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-running-race-results", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mvanhorn/printing-press-library --skill pp-running-race-results -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mvanhorn/printing-press-library pp-running-race-results --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/cli-skills/pp-running-race-results .opencode/skills/pp-running-race-results && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pp-running-race-results" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-running-race-results into .opencode/skills/pp-running-race-results/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-running-race-results", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pp-running-race-resultsLook up running race results across NYRR, Mika Timing, Athlinks, and RaceResult by fuzzy race name, bib, runner name, or athlete history.
Pp Running Race Results is an agent skill from mvanhorn/printing-press-library. Look up running race results across NYRR, Mika Timing, Athlinks, and RaceResult by fuzzy race name, bib, runner name, or athlete history.
Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Official library of CLIs generated by the CLI Printing Press. Endorsed, tested, and community-contributed. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit d9a1696. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadBashFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxgoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
ATHLINKS_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pp Running Race Results loads about 1k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 353 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, BashAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from mvanhorn/printing-press-library at commit d9a1696, republished under its Apache-2.0 licence (© mvanhorn). 353 words, ~1,012 tokens.
.claude/skills/pp-running-race-results/SKILL.md (or your agent's skills folder).<!-- GENERATED FILE — DO NOT EDIT.
This file is a verbatim mirror of library/other/running-race-results/SKILL.md,
regenerated post-merge by tools/generate-skills/. Hand-edits here are
silently overwritten on the next regen. Edit the library/ source instead.
See the repository agent guide, section "Generated artifacts: registry.json, cli-skills/". -->
This skill drives the running-race-results-pp-cli binary. You must verify the CLI is installed before invoking any command from this skill. If it is missing, install it first:
$HOME/.local/bin on macOS/Linux and %LOCALAPPDATA%\Programs\PrintingPress\bin on Windows:npx -y @mvanhorn/printing-press-library install running-race-results --cli-onlyrunning-race-results-pp-cli --version$PATH for the agent/runtime that will invoke this skill.If the npx install fails (no Node, offline, etc.), fall back to a direct Go install (requires Go 1.26.6 or newer). This installs into $GOPATH/bin (default $HOME/go/bin), so add that directory to $PATH instead:
go install github.com/mvanhorn/printing-press-library/library/other/running-race-results/cmd/running-race-results-pp-cli@latestIf --version reports "command not found" after install, the runtime cannot see the binary directory on $PATH. Do not proceed with skill commands until verification succeeds.
Use this CLI when a user wants to look up a runner's published race result, search for a runner inside a known race, or inspect a runner's cross-event history from supported race-results providers.
Do not use this CLI for live race tracking, private training analytics, registration, purchases, or changing remote state. It is read-only and reports publicly published race results.
lookup — Resolve a fuzzy race name to the right provider and edition, then return a unified result by bib or runner name.athlete — Show cross-event race history from Athlinks or NYRR by name, racer id, or the optional Athlinks current-user token.running-race-results-pp-cli lookup "<race name>" <bib> — Look up one runner in a known race by bib.running-race-results-pp-cli lookup "<race name>" --name "<runner name>" — Search for runners by name inside the resolved race.running-race-results-pp-cli athlete "<runner name>" — Search Athlinks for a runner and show cross-event race history.running-race-results-pp-cli athlete --provider nyrr "<runner name>" — Search NYRR for a runner and show NYRR race history.running-race-results-pp-cli lookup "mini 10k" 19 --year 2026running-race-results-pp-cli lookup "berlin marathon" 73664 --year 2025 --jsonrunning-race-results-pp-cli lookup "berlin marathon" --name "Runner" --year 2025running-race-results-pp-cli athlete "Sample Athlete"Most commands do not require credentials. ATHLINKS_TOKEN is optional and is only needed for athlete --me or if an Athlinks endpoint starts returning 401/403 for anonymous requests.
© mvanhorn, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in cli-skills/pp-running-race-results of mvanhorn/printing-press-library.
Open the folder on GitHubat commit d9a1696
Pp Running Race Results next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pp Running Race Results this skillmvanhorn/printing-press-library | 2.1k | — | ~1k | Automated safety check: Notes | Apache-2.0 | |
| Hunt Race Conditionsickn33/agentic-awesome-skills | 47k | 1 repos | ~5.7k | Automated safety check: Pass | MIT | |
| Exploiting Race Condition Vulnerabilitiesmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| Godot Genre Racingthedivergentai/GD-Agentic-Skills | 821 | — | ~4.1k | Automated safety check: Pass | LGPL-3.0 | |
| Tinyworld Tinyverse Race Trackjasonkneen/tiny-world-builder | 1.6k | — | ~634 | Automated safety check: Pass | AGPL-3.0 | |
| Infant Looking Time DesignerNeuroAIHub/BrainPilot | 1.1k | — | ~4.5k | Automated safety check: Pass | AGPL-3.0 |
sickn33/agentic-awesome-skills
Hunting skill for race condition vulnerabilities. An agent skill from sickn33/agentic-awesome-skills.
mukul975/Anthropic-Cybersecurity-Skills
Detects and exploits race condition (TOCTOU) vulnerabilities in web applications using Burp Suite's Turbo Intruder extension and its single-packet attack technique to fire parallel requests that…
thedivergentai/GD-Agentic-Skills
Expert blueprint for racing games including vehicle physics (VehicleBody3D, suspension, friction), checkpoint systems (prevent shortcuts), rubber-banding AI (keep races competitive), drifting…
jasonkneen/tiny-world-builder
A skill your agent uses when changing the Tinyverse ground-surface race track, perimeter bridge loop, rally karts, or poser-surface show/hide hook.
NeuroAIHub/BrainPilot
Designs habituation and preferential-looking paradigms with age-appropriate timing parameters and exclusion criteria
GoogleCloudPlatform/race-condition
A skill your agent uses when the simulator receives a validated plan from the planner and must initialize the race: parsing the plan, spawning runner agents, starting the telemetry collector, and…
mvanhorn/printing-press-library
Desktop automation through the real Rust agent-desktop CLI, published in Printing Press through a small bridge.
mvanhorn/printing-press-library
Search, browse, and download Google Fonts from the terminal via the gfonts CLI.
mvanhorn/printing-press-library
The free, offline Trigger phrases: search 1688 for, find a factory on 1688 for, wholesale price on 1688 for, who is the cheapest supplier on 1688 for, compare 1688 suppliers for, use 1688, run 1688.
mvanhorn/printing-press-library
Inspect known Activity Japan plan IDs or URLs, compare dated prices and sessions, check language-sitemap coverage, and hand off to canonical booking pages.
mvanhorn/printing-press-library
Every Admin By Request portal action, plus a local SQLite mirror of audit, events, inventory and requests for ad-hoc...
mvanhorn/printing-press-library
macOS screen capture, window recording, GIF conversion, and agent evidence bundles from the terminal.
Look up running race results across NYRR, Mika Timing, Athlinks, and RaceResult by fuzzy race name, bib, runner name, or athlete history. Pp Running Race Results is an agent skill from mvanhorn/printing-press-library. Look up running race results across NYRR, Mika Timing, Athlinks, and RaceResult by fuzzy race name, bib, runner name, or athlete history.
Run `npx skills add mvanhorn/printing-press-library --skill pp-running-race-results -a claude-code`. Or copy the skill folder (cli-skills/pp-running-race-results in mvanhorn/printing-press-library) into .claude/skills/pp-running-race-results in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mvanhorn/printing-press-library --skill pp-running-race-results -a codex`. Or copy the skill folder (cli-skills/pp-running-race-results in mvanhorn/printing-press-library) into .agents/skills/pp-running-race-results in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mvanhorn/printing-press-library --skill pp-running-race-results -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pp-running-race-results, .gemini/skills/pp-running-race-results, .github/skills/pp-running-race-results and .opencode/skills/pp-running-race-results in your project.
Going by SKILL.md and its folder, Pp Running Race Results needs the command-line tools its instructions call (npx and go) and credentials named ATHLINKS_TOKEN. Our summary lists: Node.js; A credential in ATHLINKS_TOKEN. Its frontmatter pre-approves these tools: Read, Bash.
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Pp Running Race Results is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Pp Running Race Results: Hunt Race Condition (sickn33/agentic-awesome-skills, 47k stars), Exploiting Race Condition Vulnerabilities (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Godot Genre Racing (thedivergentai/GD-Agentic-Skills, 821 stars) and Tinyworld Tinyverse Race Track (jasonkneen/tiny-world-builder, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mvanhorn (a GitHub user) maintains it in mvanhorn/printing-press-library, which has 2,056 GitHub stars. The repository holds 506 skills in this directory. The repository was last updated on October 9, 2026.
Source: mvanhorn/printing-press-library on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.