Agent skill

Pp Yeswehack

by mvanhorn in mvanhorn/printing-press-library

Every YesWeHack researcher feature, plus an offline SQLite-backed cockpit for scope cartography, drift detection,...

Apache-2.0Auto-check: notesDatabases

Install Pp Yeswehack

skills CLI
$ npx skills add mvanhorn/printing-press-library --skill pp-yeswehack -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mvanhorn/printing-press-library pp-yeswehack --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cli-skills/pp-yeswehack .claude/skills/pp-yeswehack && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pp-yeswehack
GitHub stars
2.1k
Token cost
~4.7k tokens
SKILL.md length
2,003 words
Files
1
Skills in repo
505
Repo updated
First seen
Licence
Apache-2.0

At a glance

Every YesWeHack researcher feature, plus an offline SQLite-backed cockpit for scope cartography, drift detection,...

  • Works in 3 steps: Install via the Printing Press installer → Verify: yeswehack-pp-cli --version → Ensure $GOPATH/bin (or $HOME/go/bin) is…
  • Phrases: hunt on yeswehack
  • SKILL.md covers Prerequisites: Install the CLI, When to Use This CLI, When Not to Use This CLI and Unique Capabilities, plus 12 more sections
  • Calls claude, npx and go

What it does

Pp Yeswehack is an agent skill from mvanhorn/printing-press-library. Every YesWeHack researcher feature, plus an offline SQLite-backed cockpit for scope cartography, drift detection,... Trigger phrases: hunt on yeswehack, qualify a yeswehack program, triage my yeswehack programs, draft a yeswehack report, is this yeswehack bug a duplicate, what changed in yeswehack scope, yeswehack hacktivity for fintech, use yeswehack, run yeswehack-pp-cli.

Its SKILL.md is about 4.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Databases, covering GitOps and Banking and insurance. It works with SQLite. The repository describes itself as: Official library of CLIs generated by the CLI Printing Press. Endorsed, tested, and community-contributed. The licence is Apache-2.0.

When your agent uses it

  • Phrases: hunt on yeswehack
  • Qualify a yeswehack program
  • Triage my yeswehack programs
  • Draft a yeswehack report

Example prompts

  • “/pp-yeswehack”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Read, Bash

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Install via the Printing Press installer
  2. Verify: yeswehack-pp-cli --version
  3. Ensure $GOPATH/bin (or $HOME/go/bin) is on $PATH.

What it can do on your machine

Read from SKILL.md and the folder at commit 7638ad4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • claude
    • npx
    • go
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pp Yeswehack loads about 4.7k tokens when it runs. Until then it costs about 102 tokens; SKILL.md has 2,003 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mvanhorn/printing-press-library at commit 7638ad4, republished under its Apache-2.0 licence (© mvanhorn). 2,003 words, ~4,724 tokens.

Download SKILL.mdSave it as .claude/skills/pp-yeswehack/SKILL.md (or your agent's skills folder).
name
pp-yeswehack
description
Every YesWeHack researcher feature, plus an offline SQLite-backed cockpit for scope cartography, drift detection,... Trigger phrases: `hunt on yeswehack`, `qualify a yeswehack program`, `triage my yeswehack programs`, `draft a yeswehack report`, `is this yeswehack bug a duplicate`, `what changed in yeswehack scope`, `yeswehack hacktivity for fintech`, `use yeswehack`, `run yeswehack-pp-cli`.
allowed-tools
Read, Bash
author
Matt Van Horn
license
Apache-2.0
argument-hint
<command> [args] | install cli|mcp
<!-- GENERATED FILE — DO NOT EDIT.
     This file is a verbatim mirror of library/developer-tools/yeswehack/SKILL.md,
     regenerated post-merge by tools/generate-skills/. Hand-edits here are
     silently overwritten on the next regen. Edit the library/ source instead.
     See the repository agent guide, section "Generated artifacts: registry.json, cli-skills/". -->

YesWeHack — Printing Press CLI

Prerequisites: Install the CLI

This skill drives the yeswehack-pp-cli binary. You must verify the CLI is installed before invoking any command from this skill. If it is missing, install it first:

  1. Install via the Printing Press installer:
    bash
    npx -y @mvanhorn/printing-press-library install yeswehack --cli-only
  2. Verify: yeswehack-pp-cli --version
  3. Ensure $GOPATH/bin (or $HOME/go/bin) is on $PATH.

If the npx install fails (no Node, offline, etc.), fall back to a direct Go install (requires Go 1.26.6 or newer):

bash
go install github.com/mvanhorn/printing-press-library/library/developer-tools/yeswehack/cmd/yeswehack-pp-cli@latest

If --version reports "command not found" after install, the install step did not put the binary on $PATH. Do not proceed with skill commands until verification succeeds.

yeswehack-pp-cli is the researcher-side cockpit for the YesWeHack bug bounty platform. It syncs every program you can see, every scope, every hacktivity disclosure into a local SQLite store so an agent can answer 'what should I work on', 'has this been reported', and 'what is in scope here' in milliseconds, offline. Submit and draft commands are guard-railed by design - the goal is better reports, not more reports.

When to Use This CLI

Reach for this CLI when a security researcher (or their agent) is qualifying YesWeHack programs, drafting a report, or trying to calibrate severity from prior disclosures. Particularly strong for agent-driven triage workflows where the agent needs structured local state to answer 'has this been reported', 'what is in scope', and 'which program pays the most for this asset'. Skip it for program-manager workflows (use ywh2bugtracker) and for one-off curl calls to the public API.

When Not to Use This CLI

Do not activate this CLI for requests that require creating, updating, deleting, publishing, commenting, upvoting, inviting, ordering, sending messages, booking, purchasing, or changing remote state. This printed CLI exposes read-only commands for inspection, export, sync, and analysis.

Unique Capabilities

These capabilities aren't available in any other tool for this API.

Local state that compounds
  • programs list --all --results-per-page 100 — Fetch every public and private program visible to the authenticated researcher, using YesWeHack's browser-facing page-size parameter.

    Use this before local triage or backfill. It establishes the visible program set that later scope, hacktivity, and membership commands enrich.

    bash
    yeswehack-pp-cli programs list --all --results-per-page 100 --json
  • programs scope-drift — See what changed in any program's scope this week — assets added, removed, or modified, with first-seen dates.

    When an agent triages where to spend the hunter's week, drift is the highest-signal source of fresh attack surface. Pick this over a generic program list when the user has already chosen programs and wants to know what changed.

    bash
    yeswehack-pp-cli programs scope-drift --since-days 7 --json
  • programs list-scopes <slug> — Read one program's in-scope and out-of-scope assets and cache them locally as program-scopes.

    Use this when the user asks for a project plan from the policy/scope data. The cache records program_slug so later local lookup and overlap analysis can stay program-aware.

    bash
    yeswehack-pp-cli programs list-scopes swiss-post-evoting --json
  • scopes overlap — Surface assets (host or wildcard) that appear in two or more of your invited programs, ranked by best payout.

    When the agent finds a candidate finding on an asset, this answers 'which program pays the most for this asset' before drafting the report.

    bash
    yeswehack-pp-cli scopes overlap --min-programs 2 --json
  • triage weekend — Ranked plan for a short hunting session - newly added scope, reports needing your response, and trending CWEs in your specialty.

    Picks the right starting move when the hunter (or their agent) has limited time and needs a confidence-weighted plan, not a feed.

    bash
    yeswehack-pp-cli triage weekend --hours 6 --json
  • programs fit — Rank invited and public programs by how well your historical CWE specialties match each program's hacktivity payout pattern.

    Answers 'which program am I most likely to land on this week' before time is spent on scope reading or report drafting.

    bash
    yeswehack-pp-cli programs fit --specialty xss,ssrf,idor --json
  • events calendar — Chronological view of platform events, payout deadlines, and CTFs gating private invites - filtered to programs you are invited to.

    Surfaces time-bound opportunities (renewal bumps, CTF gates) the hunter would otherwise miss until after the fact.

    bash
    yeswehack-pp-cli events calendar --mine --json
Anti-spam guard-rails
  • report dedupe — FTS5 search over the public hacktivity feed plus your own reports for title, asset, or CWE overlap — exits 2 if a high-confidence collision exists.

    Aligns with the YesWeHack Platform Code of Conduct's anti-spam rule. Before an agent drafts a report, this answers 'has someone already filed this' deterministically.

    bash
    yeswehack-pp-cli report dedupe --title 'SQLi in /api/users/{id}' --asset api.example.com --cwe CWE-89 --json
  • report cvss-check — Parse a CVSS 3.1 vector, recompute its base score, and flag impossible combinations against report steps text - rule-based, no LLM.

    Catches CVSS misrepresentations before the report is filed - the kind of mistake that loses credibility with triagers.

    bash
    yeswehack-pp-cli report cvss-check 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H' --steps draft.md --json
  • report draft — Create a markdown draft pre-filled with the program's reward grid, accepted severity levels, and an allowed asset picker from local scopes - no network call.

    Gives an agent a deterministic shape for a report instead of letting it fabricate the structure. Quality multiplier per the Platform CoC.

    bash
    yeswehack-pp-cli report draft yes-we-hack --output ./my-draft.md
  • report submit — Submit a drafted report after dry-run preview, in-scope validation, and automatic pre-submit dedupe. Requires --confirm.

    Lets an agent close the loop on submission without violating the platform's anti-AI-slop policy. No batch flag, no template-flood.

    bash
    yeswehack-pp-cli report submit ./my-draft.md --confirm
Agent-native plumbing
  • programs hacktivity <slug> — Read the YesWeHack web app's project-specific hacktivity endpoint for one program.

    Use this instead of assuming hacktivity list --programs <slug> filters the global feed. It is the reliable project activity source when a program exposes hacktivity.

    bash
    yeswehack-pp-cli programs hacktivity digital-flanders-vulnerability-disclosure-program --json
  • hacktivity trends — Histogram of disclosed report categories and average bounty for one program over a time window.

    Calibrates severity expectations and report-style for a target program before the agent starts hunting it.

    bash
    yeswehack-pp-cli hacktivity trends gojek --since-days 90 --json
  • hacktivity learn — Filtered slice of disclosed reports for a program and CWE - top N by bounty, with severity and writeup links, in pipe-friendly JSON.

    Lets the agent calibrate from prior art before the hunter writes a single line - turning hacktivity into a learning surface, not just a feed.

    bash
    yeswehack-pp-cli hacktivity learn --program gojek --cwe CWE-89 --since-days 90 --json | claude 'summarize what worked'

HTTP Transport

This CLI uses Chrome-compatible HTTP transport for browser-facing endpoints. It does not require a resident browser process for normal API calls.

Command Reference

business_units — Customer organizations that run programs

  • yeswehack-pp-cli business_units — List business units visible to the user

events — Platform events (CTFs, dojos, live sessions)

  • yeswehack-pp-cli events — List YesWeHack events

hacktivity — Public disclosed reports feed (the platform's learning surface)

  • yeswehack-pp-cli hacktivity by_hunter — List a hunter's disclosed reports
  • yeswehack-pp-cli hacktivity list — List recently disclosed reports across all public programs

hunters — Researcher profiles (other hunters on the platform)

  • yeswehack-pp-cli hunters get — Get a hunter's public profile (points, rank, impact, achievements)
  • yeswehack-pp-cli hunters list_achievements — List a hunter's earned achievement badges

programs — Bug bounty programs (public and private the user is invited to)

  • yeswehack-pp-cli programs get — Get a program's full detail (rules, reward grid, scope counts, BU, etc.)
  • yeswehack-pp-cli programs list — List bug bounty programs the user can see
  • yeswehack-pp-cli programs list-scopes — List the in-scope and out-of-scope assets for a program
  • yeswehack-pp-cli programs hacktivity — List disclosed activity for one program

ranking — Global researcher leaderboard

  • yeswehack-pp-cli ranking — Top hunters by points

taxonomies — Reference data used by the platform (vulnerability parts, countries, profile URL types)

  • yeswehack-pp-cli taxonomies list_countries — Country reference list (codes, names)
  • yeswehack-pp-cli taxonomies list_profile_url_types — Allowed profile URL types (twitter, github, linkedin, etc.)
  • yeswehack-pp-cli taxonomies list_vulnerable_parts — List vulnerability parts (CWE-like taxonomy used when filing reports)

user — Authenticated user account, reports, invitations, email aliases

  • yeswehack-pp-cli user get_self — Get the authenticated user
  • yeswehack-pp-cli user list_email_aliases — List the authenticated user's email aliases (per-program forwarding addresses)
  • yeswehack-pp-cli user list-invitations — List pending program invitations
  • yeswehack-pp-cli user list-members — List the authenticated hunter's program membership records
  • yeswehack-pp-cli user list-access-programs — List programs the authenticated hunter can currently access
  • yeswehack-pp-cli user list-revoked-members — List revoked program membership records
  • yeswehack-pp-cli user list-reports — List reports the authenticated user has submitted
Show full SKILL.md (804 more words)Show less
Finding the right command

When you know what you want to do but not which command does it, ask the CLI directly:

bash
yeswehack-pp-cli which "<capability in your own words>"

which resolves a natural-language capability query to the best matching command from this CLI's curated feature index. Exit code 0 means at least one match; exit code 2 means no confident match — fall back to --help or use a narrower query.

Recipes

Triage a hunting session
bash
yeswehack-pp-cli triage weekend --hours 6 --json --select programs,reports,cwes

Single ranked plan for a time-boxed session. --select narrows the JSON to the three high-gravity fields so agents don't burn context on full payloads.

Detect new scope before competitors do
bash
yeswehack-pp-cli programs scope-drift --since-days 7 --json

Compares this week's scope snapshot to last week's. Catches the asset that quietly got added between Sunday syncs.

Pre-submit dedupe before drafting
bash
yeswehack-pp-cli report dedupe --title 'SQLi /api/users/{id}' --asset api.example.com --cwe CWE-89 --json

Run before you spend an hour drafting. Exit 2 = high-confidence collision; the agent should stop and look at the matching disclosure.

Calibrate severity from disclosed reports
bash
yeswehack-pp-cli hacktivity learn --program gojek --cwe CWE-89 --since-days 90 --json | claude 'summarize the highest-bounty tactics'

Pipes a deterministic data slice into an LLM for synthesis - the CLI stays auditable; the model only sees the curated slice.

Pick the right program for an asset finding
bash
yeswehack-pp-cli scopes find 'api-v3.*example\\.com' --json --select asset,program_slug,bounty_reward_max

Regex lookup across every synced scope. Picks the program with the highest payout when the asset is in multiple scopes.

Build a local YesWeHack workbench
bash
yeswehack-pp-cli sync --resources programs,user,user-members,hunter-access-programs,events,ranking,hacktivity --full --json
yeswehack-pp-cli programs list --all --results-per-page 100 --json --select slug | jq -r '.results[].slug' |
  while read -r slug; do
    yeswehack-pp-cli programs get "$slug" --json >/dev/null
    yeswehack-pp-cli programs list-scopes "$slug" --json >/dev/null
  done

This fills the local SQLite store with visible programs, detailed policies, per-program scope rows, membership/access records, and public hacktivity. Use local reads for fast planning after the backfill.

Auth Setup

Authentication is JWT-based and tied to your logged-in browser session. Run yeswehack-pp-cli auth login --chrome and the CLI reads the access_token from your Chrome profile's localStorage - no copy-paste from DevTools. The JWT refreshes automatically against the OAuth2 token endpoint when it expires. YesWeHack's Personal Access Tokens are gated to manager-tier accounts; the CLI does not support them for the researcher surface.

Run yeswehack-pp-cli doctor to verify setup.

Agent Mode

Add --agent to any command. Expands to: --json --compact --no-input --no-color --yes.

  • Pipeable — JSON on stdout, errors on stderr

  • Filterable — --select keeps a subset of fields. Dotted paths descend into nested structures; arrays traverse element-wise. Critical for keeping context small on verbose APIs:

    bash
    yeswehack-pp-cli business_units --agent --select id,name,status
  • Previewable — --dry-run shows the request without sending

  • Offline-friendly — sync/search commands can use the local SQLite store when available

  • Non-interactive — never prompts, every input is a flag

  • Read-only — do not use this CLI for create, update, delete, publish, comment, upvote, invite, order, send, or other mutating requests

Response envelope

Commands that read from the local store or the API wrap output in a provenance envelope:

json
{
  "meta": {"source": "live" | "local", "synced_at": "...", "reason": "..."},
  "results": <data>
}

Parse .results for data and .meta.source to know whether it's live or local. A human-readable N results (live) summary is printed to stderr only when stdout is a terminal — piped/agent consumers get pure JSON on stdout.

Agent Feedback

When you (or the agent) notice something off about this CLI, record it:

yeswehack-pp-cli feedback "the --since flag is inclusive but docs say exclusive"
yeswehack-pp-cli feedback --stdin < notes.txt
yeswehack-pp-cli feedback list --json --limit 10

Entries are stored locally at ~/.yeswehack-pp-cli/feedback.jsonl. They are never POSTed unless YESWEHACK_FEEDBACK_ENDPOINT is set AND either --send is passed or YESWEHACK_FEEDBACK_AUTO_SEND=true. Default behavior is local-only.

Write what surprised you, not a bug report. Short, specific, one line: that is the part that compounds.

Output Delivery

Every command accepts --deliver <sink>. The output goes to the named sink in addition to (or instead of) stdout, so agents can route command results without hand-piping. Three sinks are supported:

SinkEffect
stdoutDefault; write to stdout only
file:<path>Atomically write output to <path> (tmp + rename)
webhook:<url>POST the output body to the URL (application/json or application/x-ndjson when --compact)

Unknown schemes are refused with a structured error naming the supported set. Webhook failures return non-zero and log the URL + HTTP status on stderr.

Named Profiles

A profile is a saved set of flag values, reused across invocations. Use it when a scheduled agent calls the same command every run with the same configuration - HeyGen's "Beacon" pattern.

yeswehack-pp-cli profile save briefing --json
yeswehack-pp-cli --profile briefing business_units
yeswehack-pp-cli profile list --json
yeswehack-pp-cli profile show briefing
yeswehack-pp-cli profile delete briefing --yes

Explicit flags always win over profile values; profile values win over defaults. agent-context lists all available profiles under available_profiles so introspecting agents discover them at runtime.

Exit Codes

CodeMeaning
0Success
2Usage error (wrong arguments)
3Resource not found
4Authentication required
5API error (upstream issue)
7Rate limited (wait and retry)
10Config error

Argument Parsing

Parse $ARGUMENTS:

  1. Empty, help, or --help → show yeswehack-pp-cli --help output
  2. Starts with install → ends with mcp → MCP installation; otherwise → see Prerequisites above
  3. Anything else → Direct Use (execute as CLI command with --agent)

MCP Server Installation

Install the MCP binary from this CLI's published public-library entry or pre-built release, then register it:

bash
claude mcp add yeswehack-pp-mcp -- yeswehack-pp-mcp

Verify: claude mcp list

Direct Use

  1. Check if installed: which yeswehack-pp-cli If not found, offer to install (see Prerequisites at the top of this skill).
  2. Match the user query to the best command from the Unique Capabilities and Command Reference above.
  3. Execute with the --agent flag:
    bash
    yeswehack-pp-cli <command> [subcommand] [args] --agent
  4. If ambiguous, drill into subcommand help: yeswehack-pp-cli <command> --help.

© mvanhorn, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in cli-skills/pp-yeswehack of mvanhorn/printing-press-library.

Open the folder on GitHubat commit 7638ad4

Compare with similar skills

Pp Yeswehack next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pp Yeswehack compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pp Yeswehack this skillmvanhorn/printing-press-library2.1k—~4.7kAutomated safety check: NotesApache-2.0
DB Ops SopOpenDCAI/DataMind406—~388Automated safety check: PassApache-2.0
Codex Activity ReportSpecterOps/skills702—~805Automated safety check: PassApache-2.0
OmniRoute Database Backupsdiegosouzapw/OmniRoute74k1 repos~395Automated safety check: PassMIT
Iptvnator Sqlite DB Worker4gray/iptvnator7.3k—~824Automated safety check: PassMIT
Analyze Nsys Profilemlc-ai/pith-train355—~1.9kAutomated safety check: PassApache-2.0

Similar skills

  • DB Ops Sop

    OpenDCAI/DataMind

    Database operations runbook — backup, recovery, performance tuning, troubleshooting.

    406 GitHub stars~388 tokensUpdated 17 days ago
    DatabasesAuto-check passed
  • Codex Activity Report

    SpecterOps/skills

    Generate a normalized UTC timeline and evidence-based narrative from Codex activity artifacts.

    702 GitHub stars~805 tokensUpdated 14 days ago
    DatabasesAuto-check passed
  • OmniRoute Database Backups

    diegosouzapw/OmniRoute

    Trigger system backups, restore from backup files, and manage the SQLite database lifecycle. Supports export, import, and incremental snapshot strategies.

    74k GitHub starsUsed in 1 repo~395 tokens
    DevOps & CloudAuto-check passed
  • A skill your agent uses when changing Electron SQLite IPC, database-worker operations, request-scoped progress or cancellation, worker packaging, or runtime verification of non-EPG database work.

    7.3k GitHub stars~824 tokensUpdated yesterday
    DatabasesAuto-check passed
  • Analyze Nsys Profile

    mlc-ai/pith-train

    Query a captured PithTrain Nsight Systems profile to measure compute/communication overlap, locate exposed comm by DualPipeV stage, and inspect per-rank stream behavior.

    355 GitHub stars~1.9k tokensUpdated 3 days ago
    DatabasesAuto-check passed
  • Reactive Sqlite UI

    fastrepl/anarlog

    Build SQLite-backed reactive UI in apps/desktop using stable patterns for reads, selection, forms, writes, and loading states.

    9.4k GitHub stars~699 tokensUpdated today
    DatabasesAuto-check passed

More from mvanhorn/printing-press-library

All 505 skills in this repo
  • Agent Desktop

    mvanhorn/printing-press-library

    Desktop automation through the real Rust agent-desktop CLI, published in Printing Press through a small bridge.

    2.1k GitHub stars~2.3k tokensUpdated yesterday
    Auto-check: notes
  • Gfonts

    mvanhorn/printing-press-library

    Search, browse, and download Google Fonts from the terminal via the gfonts CLI.

    2.1k GitHub stars~574 tokensUpdated yesterday
    Auto-check passed
  • Pp 1688

    mvanhorn/printing-press-library

    The free, offline Trigger phrases: search 1688 for, find a factory on 1688 for, wholesale price on 1688 for, who is the cheapest supplier on 1688 for, compare 1688 suppliers for, use 1688, run 1688.

    2.1k GitHub stars~3k tokensUpdated yesterday
    Auto-check: notes
  • Pp Activity Japan

    mvanhorn/printing-press-library

    Inspect known Activity Japan plan IDs or URLs, compare dated prices and sessions, check language-sitemap coverage, and hand off to canonical booking pages.

    2.1k GitHub stars~2k tokensUpdated yesterday
    Auto-check: notes
  • Pp Adminbyrequest

    mvanhorn/printing-press-library

    Every Admin By Request portal action, plus a local SQLite mirror of audit, events, inventory and requests for ad-hoc...

    2.1k GitHub stars~3.3k tokensUpdated yesterday
    Auto-check: notes
  • Pp Agent Capture

    mvanhorn/printing-press-library

    macOS screen capture, window recording, GIF conversion, and agent evidence bundles from the terminal.

    2.1k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check: notes

Works with

Questions about Pp Yeswehack

What does Pp Yeswehack do?

Every YesWeHack researcher feature, plus an offline SQLite-backed cockpit for scope cartography, drift detection,... Pp Yeswehack is an agent skill from mvanhorn/printing-press-library. Every YesWeHack researcher feature, plus an offline SQLite-backed cockpit for scope cartography, drift detection,...

When should I use Pp Yeswehack?

Pp Yeswehack fits situations like: phrases: hunt on yeswehack; qualify a yeswehack program; triage my yeswehack programs; draft a yeswehack report.

How do I install Pp Yeswehack in Claude Code?

Run `npx skills add mvanhorn/printing-press-library --skill pp-yeswehack -a claude-code`. Or copy the skill folder (cli-skills/pp-yeswehack in mvanhorn/printing-press-library) into .claude/skills/pp-yeswehack in your project. Claude Code loads it when a task matches its description.

How do I install Pp Yeswehack in Codex?

Run `npx skills add mvanhorn/printing-press-library --skill pp-yeswehack -a codex`. Or copy the skill folder (cli-skills/pp-yeswehack in mvanhorn/printing-press-library) into .agents/skills/pp-yeswehack in your project. Codex loads it when a task matches its description.

Can I use Pp Yeswehack in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mvanhorn/printing-press-library --skill pp-yeswehack -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pp-yeswehack, .gemini/skills/pp-yeswehack, .github/skills/pp-yeswehack and .opencode/skills/pp-yeswehack in your project.

What does Pp Yeswehack need to run?

Going by SKILL.md and its folder, Pp Yeswehack needs the command-line tools its instructions call (claude, npx, go and jq). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Read, Bash.

Does Pp Yeswehack access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Pp Yeswehack safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Pp Yeswehack use?

Pp Yeswehack is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pp Yeswehack use?

About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pp Yeswehack?

Skills that share tags, products or a category with Pp Yeswehack: DB Ops Sop (OpenDCAI/DataMind, 406 stars), Codex Activity Report (SpecterOps/skills, 702 stars), OmniRoute Database Backups (diegosouzapw/OmniRoute, 74k stars) and Iptvnator Sqlite DB Worker (4gray/iptvnator, 7.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pp Yeswehack?

mvanhorn (a GitHub user) maintains it in mvanhorn/printing-press-library, which has 2,053 GitHub stars. The repository holds 505 skills in this directory. The repository was last updated on October 6, 2026.

Source: mvanhorn/printing-press-library on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.