Security Setup
luongnv89/skills
Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.
Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.
$ npx skills add Narwhal-Lab/MagicSkills --skill c-to-ast -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Narwhal-Lab/MagicSkills c-to-ast --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Narwhal-Lab/MagicSkills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skill_template/c_2_ast .claude/skills/c-to-ast && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "c-to-ast" agent skill from https://github.com/Narwhal-Lab/MagicSkills/tree/main/skill_template/c_2_ast into .claude/skills/c-to-ast/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "c-to-ast", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Narwhal-Lab/MagicSkills/tree/main/skill_template/c_2_astType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Narwhal-Lab/MagicSkills --skill c-to-ast -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Narwhal-Lab/MagicSkills c-to-ast --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Narwhal-Lab/MagicSkills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skill_template/c_2_ast .agents/skills/c-to-ast && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "c-to-ast" agent skill from https://github.com/Narwhal-Lab/MagicSkills/tree/main/skill_template/c_2_ast into .agents/skills/c-to-ast/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "c-to-ast", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Narwhal-Lab/MagicSkills --skill c-to-ast -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Narwhal-Lab/MagicSkills c-to-ast --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Narwhal-Lab/MagicSkills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skill_template/c_2_ast .cursor/skills/c-to-ast && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "c-to-ast" agent skill from https://github.com/Narwhal-Lab/MagicSkills/tree/main/skill_template/c_2_ast into .cursor/skills/c-to-ast/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "c-to-ast", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Narwhal-Lab/MagicSkills.git --path skill_template/c_2_ast--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Narwhal-Lab/MagicSkills --skill c-to-ast -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Narwhal-Lab/MagicSkills c-to-ast --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Narwhal-Lab/MagicSkills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skill_template/c_2_ast .gemini/skills/c-to-ast && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "c-to-ast" agent skill from https://github.com/Narwhal-Lab/MagicSkills/tree/main/skill_template/c_2_ast into .gemini/skills/c-to-ast/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "c-to-ast", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Narwhal-Lab/MagicSkills c-to-astInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Narwhal-Lab/MagicSkills --skill c-to-ast -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Narwhal-Lab/MagicSkills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skill_template/c_2_ast .github/skills/c-to-ast && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "c-to-ast" agent skill from https://github.com/Narwhal-Lab/MagicSkills/tree/main/skill_template/c_2_ast into .github/skills/c-to-ast/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "c-to-ast", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Narwhal-Lab/MagicSkills --skill c-to-ast -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Narwhal-Lab/MagicSkills c-to-ast --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Narwhal-Lab/MagicSkills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skill_template/c_2_ast .opencode/skills/c-to-ast && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "c-to-ast" agent skill from https://github.com/Narwhal-Lab/MagicSkills/tree/main/skill_template/c_2_ast into .opencode/skills/c-to-ast/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "c-to-ast", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
c-to-astParse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.
C To Ast is an agent skill from Narwhal-Lab/MagicSkills. Parse C source code into an Abstract Syntax Tree (AST). Use when analyzing C programs, understanding code structure, performing static analysis, or preparing code for further program analysis (e.g., CFG, DFG, vulnerability detection).
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts (for example `reference.md`, `scripts/c_2_ast.py` and `scripts/save_c.py`).
It sits in Security, covering Static analysis and SAST and Skill authoring. It works with Python. The repository describes itself as: MagicSkills:Stop copying skills between agents. MagicSkills turns scattered SKILL.md folders into reusable, composable, tool-ready capabilities. The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 00f3e86. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 6 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
C To Ast loads about 1.1k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 552 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from Narwhal-Lab/MagicSkills at commit 00f3e86, republished under its MIT licence (© Narwhal-Lab). 552 words, ~1,116 tokens.
.claude/skills/c-to-ast/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.This Skill converts C source code into its Abstract Syntax Tree (AST) representation.
Use this Skill when you need to:
The AST is generated using a Python-based C parser and printed directly to standard output.
Apply this Skill when the user asks to:
This Skill is especially useful in compiler frontends, program analysis, and security research workflows.
Follow these steps strictly and in order:
Navigate to the Skill scripts directory
scripts/ directory under this skill:scripts/Handle the input C source
.c file, use it directly.python3 save_c.py --input "<C code string>" --output <output_dir> --filename <filename>.c.c extension and is successfully written to disk.Run the AST extraction script
python3 c_2_ast.py --input <path_to_c_file>Do not modify the source code
Return the AST output verbatim
If parsing fails
The output is a tree-structured textual AST, for example:
FileAST:
FuncDef:
Decl: main
FuncDecl:
TypeDecl:
IdentifierType: ['int']
Compound:
FuncCall:
ID: puts
ExprList:
Constant: string, "Hello"
Return:
Constant: int, 0
This output represents the syntactic structure of the C program and can be consumed by downstream tools.
For deeper understanding of:
pycparser internal representationsee the accompanying reference document:
➡️ reference.md
Only read this file when more detailed or theoretical information is required.
For standard AST extraction tasks, this Skill file alone is sufficient.
User request:
Convert this C file to an AST.
Action:
python3 c_2_AST.py --input example.cResult:
User request:
I want to analyze this C program for vulnerabilities.
Action:
End of Skill.
© Narwhal-Lab, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (scripts) in skill_template/c_2_ast of Narwhal-Lab/MagicSkills.
Open the folder on GitHubat commit 00f3e86
C To Ast next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| C To Ast this skillNarwhal-Lab/MagicSkills | 316 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Security Setupluongnv89/skills | 131 | — | ~4.5k | Automated safety check: Pass | MIT | |
| Python API Consistency ValidatorArabelaTso/Skills-4-SE | 253 | — | ~609 | Automated safety check: Pass | Apache-2.0 | |
| CodeQL Security Scantrailofbits/skills | 7.5k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Kedro Security Reviewkedro-org/kedro | 11k | — | ~3.3k | Automated safety check: Pass | Custom licence | |
| Skylosduriantaco/skylos | 846 | — | ~620 | Automated safety check: Pass | Apache-2.0 |
luongnv89/skills
Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.
ArabelaTso/Skills-4-SE
Validate API consistency between two versions of Python libraries.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
duriantaco/skylos
Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.
fengshao1227/ccg-workflow
Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.
Works with
Categories
Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills. C To Ast is an agent skill from Narwhal-Lab/MagicSkills. Parse C source code into an Abstract Syntax Tree (AST).
C To Ast fits situations like: analyzing C programs; understanding code structure; performing static analysis; preparing code for further program analysis (e.g.
Run `npx skills add Narwhal-Lab/MagicSkills --skill c-to-ast -a claude-code`. Or copy the skill folder (skill_template/c_2_ast in Narwhal-Lab/MagicSkills) into .claude/skills/c-to-ast in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Narwhal-Lab/MagicSkills --skill c-to-ast -a codex`. Or copy the skill folder (skill_template/c_2_ast in Narwhal-Lab/MagicSkills) into .agents/skills/c-to-ast in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Narwhal-Lab/MagicSkills --skill c-to-ast -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/c-to-ast, .gemini/skills/c-to-ast, .github/skills/c-to-ast and .opencode/skills/c-to-ast in your project.
Going by SKILL.md and its folder, C To Ast needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
C To Ast is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with C To Ast: Security Setup (luongnv89/skills, 131 stars), Python API Consistency Validator (ArabelaTso/Skills-4-SE, 253 stars), CodeQL Security Scan (trailofbits/skills, 7.5k stars) and Kedro Security Review (kedro-org/kedro, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Narwhal-Lab (a GitHub organization) maintains it in Narwhal-Lab/MagicSkills, which has 316 GitHub stars. The repository was last updated on April 8, 2026.
Source: Narwhal-Lab/MagicSkills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.