Commit Security Scan
codexstar69/bug-hunter
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.
Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks.
$ npx skills add notque/vexjoy-agent --skill security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install notque/vexjoy-agent security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/notque/vexjoy-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/review/security .claude/skills/security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security" agent skill from https://github.com/notque/vexjoy-agent/tree/main/skills/review/security into .claude/skills/security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/notque/vexjoy-agent/tree/main/skills/review/securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add notque/vexjoy-agent --skill security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install notque/vexjoy-agent security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/notque/vexjoy-agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/review/security .agents/skills/security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security" agent skill from https://github.com/notque/vexjoy-agent/tree/main/skills/review/security into .agents/skills/security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add notque/vexjoy-agent --skill security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install notque/vexjoy-agent security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/notque/vexjoy-agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/review/security .cursor/skills/security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security" agent skill from https://github.com/notque/vexjoy-agent/tree/main/skills/review/security into .cursor/skills/security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/notque/vexjoy-agent.git --path skills/review/security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add notque/vexjoy-agent --skill security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install notque/vexjoy-agent security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/notque/vexjoy-agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/review/security .gemini/skills/security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security" agent skill from https://github.com/notque/vexjoy-agent/tree/main/skills/review/security into .gemini/skills/security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install notque/vexjoy-agent securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add notque/vexjoy-agent --skill security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/notque/vexjoy-agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/review/security .github/skills/security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security" agent skill from https://github.com/notque/vexjoy-agent/tree/main/skills/review/security into .github/skills/security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add notque/vexjoy-agent --skill security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install notque/vexjoy-agent security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/notque/vexjoy-agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/review/security .opencode/skills/security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security" agent skill from https://github.com/notque/vexjoy-agent/tree/main/skills/review/security into .opencode/skills/security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
securitySecurity: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks.
Security is an agent skill from notque/vexjoy-agent. Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/coverage.md` and `references/threat-model.md`).
It sits in Security, covering Threat modeling, Security review and Supply chain security. It works with Git. The repository describes itself as: VexJoy AI Agent with Jev Intelligent Routing - /do routes plain-English requests to the right specialist agent and gates the work with reviews, tests, and a learning loop. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 5218674. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteBashGrepGlobEditTaskAgentFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitpython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
ANTHROPIC_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security loads about 2.6k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 31 tokens; SKILL.md has 1,083 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Write, Bash, Grep, Glob, Edit, Task, AgentAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from notque/vexjoy-agent at commit 5218674, republished under its MIT licence (© notque). 1,083 words, ~2,602 tokens.
.claude/skills/security/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Two modes: diff review (scan current git changes for vulnerabilities) and threat model (audit a system's full attack surface). Load the reference for the mode the request matches.
| Signal | Load | Why |
|---|---|---|
| Review git changes, scan a diff, check for vulnerabilities | references/coverage.md | 40 vulnerability classes for LLM-depth review of changed code |
| Threat model, attack surface, supply-chain audit, deny list, security posture | references/threat-model.md | 5-phase threat model workflow with deterministic scripts and artifact gates |
When the request is about reviewing changes (not a full threat model), run the diff review directly. This is the common case.
Run a two-layer security review over the current git changes: a deterministic regex scan for known vulnerability classes, then an LLM-depth Security review of the diff. Report a single BLOCK / FIX / APPROVE verdict.
The LLM-depth review runs inside the current Claude session — the same
subscription that loaded this skill. There is no separate model call, no
ANTHROPIC_API_KEY, no Agent SDK, and no network request. The "reviewer" is the
session agent executing the steps below, exactly like every other skill here.
Detection reaches parity with Anthropic's security-guidance plugin: the scanner
ports its 25 deterministic patterns, and the LLM pass applies its full review
taxonomy (loaded on demand from references/coverage.md).
| Signal | Load | Why |
|---|---|---|
| Running Phase 3 (LLM-depth review); classifying a finding; needing the vuln taxonomy, severity rubric, FP exclusions, or per-language guidance | references/coverage.md | 40 vulnerability classes + 4-tier severity + false-positive exclusions + per-language guidance + the 12 high-miss reviewer classes + the finding output schema. |
Goal: Determine the changed files to review before scanning.
Step 1: List changed files — scope to the working-tree and staged changes so the review covers exactly what the user is about to commit, not the whole repo.
# Tracked changes (working tree + index) plus staged adds:
git diff --name-only HEAD
git diff --cached --name-only --diff-filter=ACMStep 2: Read repository CLAUDE.md to load project conventions the reviewer must respect (e.g. secrets-handling rules, allowed patterns).
Gate: Changed files listed. When the list is empty, report "no changes to review" and stop — there is nothing to scan.
Goal: Run the regex engine first so judgment time is spent on real signal, not on patterns a script catches deterministically.
Step 1: Run the scanner over the changed files. It is the single source of detection rules (secrets, SQL injection, shell injection, dangerous eval, unsafe deserialization). Exit 1 means at least one HIGH/CRITICAL finding.
# Staged-files convenience (matches the commit-time hook):
python3 scripts/security-review-scan.py --staged --format json
# Or an explicit list from Phase 1:
python3 scripts/security-review-scan.py --files <changed-files> --format jsonStep 2: Record the findings by severity. CRITICAL and HIGH are blocking-class;
MEDIUM is advisory. Keep the file:line and rule for each.
Gate: Scanner ran and JSON parsed. Proceed with the findings in hand.
Goal: Catch what regex cannot — authorization gaps, injection through data
flow, missing input validation, secrets in non-obvious forms. This is the
session agent's review of the diff; compose the existing parallel-code-review
Security reviewer over the changed files.
Step 1: Load references/coverage.md — the full review taxonomy (40
vulnerability classes, the 4-tier severity rubric, the false-positive exclusion
list, per-language guidance, and the 12 high-miss reviewer classes). Review to
this taxonomy so the session-agent pass reaches parity with the plugin's reviewer.
If claude-security-guidance.md exists (precedence: ~/.claude/ →
<cwd>/.claude/ → <cwd>/.claude/*.local.md), read it as ADDITIVE context — it
may add checks or raise a class's severity, and must not suppress findings.
Step 2: Dispatch the Security reviewer (the Reviewer 1 — Security role from
parallel-code-review) over the changed files via the Task tool, applying the
coverage.md taxonomy. Surface medium and above. Output: findings in the
coverage.md schema (filePath, category, vulnerableCode, explanation, fix, severity) with file:line references.
Step 3: Merge the LLM findings with the Phase 2 scanner findings.
Deduplicate — when both flag the same file:line, keep one entry at the higher
severity. Independent confirmation by both layers raises confidence.
Gate: Security reviewer returned results and findings are merged. Issue a verdict only from a completed review — a missing reviewer may hold the only CRITICAL finding.
Goal: Produce a single clear recommendation.
Step 1: Determine the verdict from the merged findings:
| Condition | Verdict |
|---|---|
| Any CRITICAL finding | BLOCK |
| HIGH findings, no CRITICAL | FIX (resolve before commit) |
| Only MEDIUM/LOW findings | APPROVE (with suggestions) |
Step 2: Output the structured report:
## Security Review Complete
### Severity Matrix
| Severity | Count | Source (scanner / reviewer / both) |
|----------|-------|------------------------------------|
| Critical | N | ... |
| High | N | ... |
| Medium | N | ... |
### Findings
#### CRITICAL (Block)
1. [source] description — file:line
#### HIGH (Fix before commit)
1. [source] description — file:line
#### MEDIUM (Should fix)
1. [source] description — file:line
### VERDICT
**BLOCK / FIX / APPROVE** — [1-2 sentence rationale]Gate: Structured report delivered with an explicit verdict. Review complete.
This skill is the on-demand (PULL) path. The same review also runs automatically
(PUSH) via hooks/security-review-hook.py, wired in .claude/settings.json:
| Event | Behavior |
|---|---|
PreToolUse (Bash git commit) | Scans STAGED files with the same scanner. A HIGH/CRITICAL finding blocks the commit (deny). Clean commits pass. |
| Stop | Re-wakes the session with the working-tree diff and an instruction to run this pipeline. Advisory — never blocks. |
Bypass / kill switches (commit-time block only, deliberate overrides):
| Env var | Effect |
|---|---|
VEXJOY_SECURITY_REVIEW_SKIP=1 | Allow a commit through despite findings (one-off override). |
VEXJOY_SECURITY_REVIEW_DISABLE=1 | Disable the hook entirely (both events). |
The hook fails open on any internal error — a hook crash never blocks a commit.
Both extension points are additive and discovered in this precedence order:
~/.claude/<name> → <cwd>/.claude/<name> → <cwd>/.claude/<name>.local.<ext>.
| File | Effect |
|---|---|
security-patterns.{yaml,json} | Custom regex/substring rules merged into the scanner's built-ins. Shape: {"patterns": [{"rule_name", "regex"|"substrings", "severity"?, "paths"?, "exclude_paths"?}]}. Capped at 50. ReDoS-prone or invalid rules are skipped with a stderr warning (non-fatal). PyYAML is used only if importable — JSON always works (stdlib-only). |
claude-security-guidance.md | Markdown surfaced to the Phase 3 review as ADDITIVE context. It may add checks or raise a class's severity; it must not suppress findings — if it says to ignore a class, flag the vulnerability anyway and note the conflict. |
Built-in scanner rules always run and cannot be disabled by a config file.
Cause: A regex rule flagged a test fixture, an example, or a deliberately
hardcoded local value.
Solution: Confirm context in Phase 3. Downgrade in the report with a one-line
justification. For a commit the user knows is safe, document the
VEXJOY_SECURITY_REVIEW_SKIP=1 override rather than editing the scanner rules.
Cause: Task agent exceeded its budget, or the diff was too large. Solution: Report the Phase 2 scanner findings immediately (a partial review beats no review), note the LLM-depth gap in the verdict, and offer to re-run the Security reviewer on a reduced file set.
Cause: scripts/security-review-scan.py missing from the working tree.
Solution: Run the Phase 3 LLM-depth review alone and state in the verdict that
the deterministic layer did not run.
scripts/security-review-scan.py (single source of truth)references/coverage.mdskills/review/parallel-code-review/SKILL.md (Reviewer 1)hooks/security-review-hook.pyadr/local-security-review.md© notque, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in skills/review/security of notque/vexjoy-agent.
Open the folder on GitHubat commit 5218674
Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security this skillnotque/vexjoy-agent | 435 | — | ~2.6k | Automated safety check: Notes | MIT | |
| Commit Security Scancodexstar69/bug-hunter | 519 | — | ~629 | Automated safety check: Pass | MIT | |
| Security Auditblueberrycongee/termcanvas | 406 | — | ~966 | Automated safety check: Notes | MIT | |
| Repo SentinelMathews-Tom/armory | 327 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Csono-session/pstack | 131 | — | ~12k | Automated safety check: Notes | MIT | |
| Security Reviewdanielvm-git/bigpowers | 256 | — | ~1.5k | Automated safety check: Pass | MIT |
codexstar69/bug-hunter
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.
blueberrycongee/termcanvas
Security audit skill. An agent skill from blueberrycongee/termcanvas.
Mathews-Tom/armory
Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses.
no-session/pstack
Chief Security Officer mode. An agent skill from no-session/pstack.
danielvm-git/bigpowers
AI-powered security analysis of code changes — traces data flow, detects injection, auth bypass, secrets exposure, and unsafe deserialization across files.
cdppcorp/KESE-KIT
Run a pre-deployment security compliance checklist based on KISA guidelines.
notque/vexjoy-agent
Deterministic palette/matrix pixel art (not AI). An agent skill from notque/vexjoy-agent.
notque/vexjoy-agent
Pull request lifecycle: commit, codex review, sync, review, fix, status, cleanup, and PR mining.
notque/vexjoy-agent
Improve architecture across modules by deepening interfaces.
notque/vexjoy-agent
Code quality: cleanup, linting, formatting, quality gates. An agent skill from notque/vexjoy-agent.
notque/vexjoy-agent
Statistical rule discovery from Go codebase patterns. An agent skill from notque/vexjoy-agent.
notque/vexjoy-agent
Review and fix temporal references in code comments. An agent skill from notque/vexjoy-agent.
Works with
Categories
Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks. Security is an agent skill from notque/vexjoy-agent. Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks.
Security fits situations like: tasks that involve Threat modeling; tasks that involve Security review; tasks that involve Supply chain security.
Run `npx skills add notque/vexjoy-agent --skill security -a claude-code`. Or copy the skill folder (skills/review/security in notque/vexjoy-agent) into .claude/skills/security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add notque/vexjoy-agent --skill security -a codex`. Or copy the skill folder (skills/review/security in notque/vexjoy-agent) into .agents/skills/security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add notque/vexjoy-agent --skill security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security, .gemini/skills/security, .github/skills/security and .opencode/skills/security in your project.
Going by SKILL.md and its folder, Security needs the command-line tools its instructions call (git and python3) and credentials named ANTHROPIC_API_KEY. Our summary lists: Python 3; A credential in ANTHROPIC_API_KEY. Its frontmatter pre-approves these tools: Read, Write, Bash, Grep, Glob, Edit, Task, Agent.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Security: Commit Security Scan (codexstar69/bug-hunter, 519 stars), Security Audit (blueberrycongee/termcanvas, 406 stars), Repo Sentinel (Mathews-Tom/armory, 327 stars) and Cso (no-session/pstack, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
notque (a GitHub user) maintains it in notque/vexjoy-agent, which has 435 GitHub stars. The repository holds 61 skills in this directory. The repository was last updated on October 3, 2026.
Source: notque/vexjoy-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.