Commit Security Scan
codexstar69/bug-hunter
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.
Agent skill
Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.
$ npx skills add nordstjernen-web/northstar-browser --skill audit-browser-security-boundaries -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nordstjernen-web/northstar-browser audit-browser-security-boundaries --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nordstjernen-web/northstar-browser.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/audit-browser-security-boundaries .claude/skills/audit-browser-security-boundaries && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "audit-browser-security-boundaries" agent skill from https://github.com/nordstjernen-web/northstar-browser/tree/main/.agents/skills/audit-browser-security-boundaries into .claude/skills/audit-browser-security-boundaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-browser-security-boundaries", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nordstjernen-web/northstar-browser/tree/main/.agents/skills/audit-browser-security-boundariesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nordstjernen-web/northstar-browser --skill audit-browser-security-boundaries -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nordstjernen-web/northstar-browser audit-browser-security-boundaries --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nordstjernen-web/northstar-browser.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/audit-browser-security-boundaries .agents/skills/audit-browser-security-boundaries && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "audit-browser-security-boundaries" agent skill from https://github.com/nordstjernen-web/northstar-browser/tree/main/.agents/skills/audit-browser-security-boundaries into .agents/skills/audit-browser-security-boundaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-browser-security-boundaries", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nordstjernen-web/northstar-browser --skill audit-browser-security-boundaries -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nordstjernen-web/northstar-browser audit-browser-security-boundaries --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nordstjernen-web/northstar-browser.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/audit-browser-security-boundaries .cursor/skills/audit-browser-security-boundaries && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "audit-browser-security-boundaries" agent skill from https://github.com/nordstjernen-web/northstar-browser/tree/main/.agents/skills/audit-browser-security-boundaries into .cursor/skills/audit-browser-security-boundaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-browser-security-boundaries", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nordstjernen-web/northstar-browser.git --path .agents/skills/audit-browser-security-boundaries--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nordstjernen-web/northstar-browser --skill audit-browser-security-boundaries -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nordstjernen-web/northstar-browser audit-browser-security-boundaries --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nordstjernen-web/northstar-browser.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/audit-browser-security-boundaries .gemini/skills/audit-browser-security-boundaries && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "audit-browser-security-boundaries" agent skill from https://github.com/nordstjernen-web/northstar-browser/tree/main/.agents/skills/audit-browser-security-boundaries into .gemini/skills/audit-browser-security-boundaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-browser-security-boundaries", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nordstjernen-web/northstar-browser audit-browser-security-boundariesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nordstjernen-web/northstar-browser --skill audit-browser-security-boundaries -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nordstjernen-web/northstar-browser.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/audit-browser-security-boundaries .github/skills/audit-browser-security-boundaries && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "audit-browser-security-boundaries" agent skill from https://github.com/nordstjernen-web/northstar-browser/tree/main/.agents/skills/audit-browser-security-boundaries into .github/skills/audit-browser-security-boundaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-browser-security-boundaries", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nordstjernen-web/northstar-browser --skill audit-browser-security-boundaries -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nordstjernen-web/northstar-browser audit-browser-security-boundaries --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nordstjernen-web/northstar-browser.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/audit-browser-security-boundaries .opencode/skills/audit-browser-security-boundaries && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "audit-browser-security-boundaries" agent skill from https://github.com/nordstjernen-web/northstar-browser/tree/main/.agents/skills/audit-browser-security-boundaries into .opencode/skills/audit-browser-security-boundaries/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-browser-security-boundaries", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
audit-browser-security-boundariesAudit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.
Audit Browser Security Boundaries is an agent skill from nordstjernen-web/northstar-browser. Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries. Use for security reviews, threat analysis, and security fixes where parsing, lifetime, isolation, or containment guarantees could regress.
Its SKILL.md is about 920 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Security, covering Threat modeling and Security review. The repository describes itself as: Northstar web browser, Open Source License: GPL v3. Northstar web browser is a real web browser, not based on Firefox or Chrome. The licence is GPL-3.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 5a86d8b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Audit Browser Security Boundaries loads about 920 tokens when it runs. Until then it costs about 86 tokens; SKILL.md has 449 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from nordstjernen-web/northstar-browser at commit 5a86d8b, republished under its GPL-3.0 licence (© nordstjernen-web). 449 words, ~920 tokens.
.claude/skills/audit-browser-security-boundaries/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Read the repository instructions, threat model, changed code, and its callers. Preserve unrelated changes. Treat all fetched content and metadata as attacker-controlled unless the threat model says otherwise.
Do not weaken verification, limits, isolation, or sandbox rules to improve compatibility. Prefer fail-closed behavior at security boundaries.
For a review, report only findings with a concrete attacker path and consequence. Include severity, exact evidence, violated invariant, impact, and the smallest safe correction. Do not edit code during a review-only request.
For a requested fix, reuse established security helpers and keep equivalent platform paths aligned where capabilities overlap. Compile and exercise the affected path, run deterministic smoke cases, and update the threat-model documentation only when its guarantees change.
Reading a code path is enough to raise a suspicion, not to report it. Reach the behavior through the real browser: a minimal local page for parser and DOM paths, the headless driver with --debug=net,error for fetch, cache, and policy paths. Report what the browser did, and say plainly when a finding is reasoned rather than observed.
The same evidence protects a fix. A security correction that cannot be shown to change the observed behavior has not been verified, and one that changes behavior on paths the report never mentioned needs its blast radius established before it lands.
Read SECURITY.md. Northstar processes untrusted pages in a single native process, so JavaScript realm separation does not contain native memory corruption. Pay particular attention to src/security.c, src/net.c, src/csp.c, src/cache.c, src/idb.c, src/ext.c, src/js.c, image/audio decoders, and platform startup code.
The repository's helper scripts export NS_ALLOW_ROOT so headless runs bypass the privileged-startup refusal. That is a convenience for local fixtures, not a statement about the product: never carry it into a claim that the refusal is optional, and never widen it in the engine to make a scenario reproduce.
© nordstjernen-web, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/audit-browser-security-boundaries of nordstjernen-web/northstar-browser.
Open the folder on GitHubat commit 5a86d8b
Audit Browser Security Boundaries next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Audit Browser Security Boundaries this skillnordstjernen-web/northstar-browser | 128 | — | ~920 | Automated safety check: Pass | GPL-3.0 | |
| Commit Security Scancodexstar69/bug-hunter | 520 | — | ~629 | Automated safety check: Pass | MIT | |
| Auditing Code For Vulnerabilitiestrilwu/secskills | 157 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Threat Mitigation Mappingwshobson/agents | 40k | 8 repos | ~742 | Automated safety check: Pass | MIT | |
| Security Auditblueberrycongee/termcanvas | 405 | — | ~966 | Automated safety check: Notes | MIT | |
| Security Reviewcodexstar69/bug-hunter | 520 | — | ~567 | Automated safety check: Pass | MIT |
codexstar69/bug-hunter
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
wshobson/agents
Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.
blueberrycongee/termcanvas
Security audit skill. An agent skill from blueberrycongee/termcanvas.
codexstar69/bug-hunter
Run a focused STRIDE-based security review using Bug Hunter-native artifacts.
Factory-AI/factory-plugins
Analyze code changes for security vulnerabilities using LLM reasoning and threat model patterns.
nordstjernen-web/northstar-browser
Port a browser-engine change between sibling editions or long-lived branches of the same codebase, in either direction.
nordstjernen-web/northstar-browser
Configure, compile, and smoke-test a Meson-based C or C++ desktop browser on Linux, macOS, or Windows, and diagnose dependency, compiler, linker, runtime-library, build-directory, or…
nordstjernen-web/northstar-browser
Diagnose and fix visual, geometry, hit-testing, and viewport regressions in a browser rendering engine.
nordstjernen-web/northstar-browser
Diagnose and fix standards-compatibility gaps in a browser engine across HTML, DOM, JavaScript bindings, events, CSSOM, forms, fetch, storage, and Web APIs.
Categories
Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries. Audit Browser Security Boundaries is an agent skill from nordstjernen-web/northstar-browser. Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.
Audit Browser Security Boundaries fits situations like: security reviews; threat analysis; security fixes where parsing; containment guarantees could regress.
Run `npx skills add nordstjernen-web/northstar-browser --skill audit-browser-security-boundaries -a claude-code`. Or copy the skill folder (.agents/skills/audit-browser-security-boundaries in nordstjernen-web/northstar-browser) into .claude/skills/audit-browser-security-boundaries in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nordstjernen-web/northstar-browser --skill audit-browser-security-boundaries -a codex`. Or copy the skill folder (.agents/skills/audit-browser-security-boundaries in nordstjernen-web/northstar-browser) into .agents/skills/audit-browser-security-boundaries in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nordstjernen-web/northstar-browser --skill audit-browser-security-boundaries -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-browser-security-boundaries, .gemini/skills/audit-browser-security-boundaries, .github/skills/audit-browser-security-boundaries and .opencode/skills/audit-browser-security-boundaries in your project.
SKILL.md names no scripts, command-line tools or credentials: Audit Browser Security Boundaries is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Audit Browser Security Boundaries is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 920 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Audit Browser Security Boundaries: Commit Security Scan (codexstar69/bug-hunter, 520 stars), Auditing Code For Vulnerabilities (trilwu/secskills, 157 stars), Threat Mitigation Mapping (wshobson/agents, 40k stars) and Security Audit (blueberrycongee/termcanvas, 405 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nordstjernen-web (a GitHub organization) maintains it in nordstjernen-web/northstar-browser, which has 128 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 10, 2026.
Source: nordstjernen-web/northstar-browser on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.