Fix Vulns
linuxfoundation/insights
Automated triage and fixing of Dependabot security vulnerabilities (IN-1189).
A skill your agent uses when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a…
$ npx skills add nubjs/nub --skill audit-thread -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nubjs/nub audit-thread --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-thread .claude/skills/audit-thread && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "audit-thread" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/audit-thread into .claude/skills/audit-thread/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-thread", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nubjs/nub/tree/main/.claude/skills/audit-threadType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nubjs/nub --skill audit-thread -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nubjs/nub audit-thread --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/audit-thread .agents/skills/audit-thread && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "audit-thread" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/audit-thread into .agents/skills/audit-thread/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-thread", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nubjs/nub --skill audit-thread -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nubjs/nub audit-thread --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/audit-thread .cursor/skills/audit-thread && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "audit-thread" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/audit-thread into .cursor/skills/audit-thread/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-thread", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nubjs/nub.git --path .claude/skills/audit-thread--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nubjs/nub --skill audit-thread -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nubjs/nub audit-thread --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/audit-thread .gemini/skills/audit-thread && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "audit-thread" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/audit-thread into .gemini/skills/audit-thread/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-thread", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nubjs/nub audit-threadInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nubjs/nub --skill audit-thread -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/audit-thread .github/skills/audit-thread && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "audit-thread" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/audit-thread into .github/skills/audit-thread/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-thread", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nubjs/nub --skill audit-thread -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nubjs/nub audit-thread --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/audit-thread .opencode/skills/audit-thread && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "audit-thread" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/audit-thread into .opencode/skills/audit-thread/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-thread", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
audit-threadA skill your agent uses when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a…
Audit Thread is an agent skill from nubjs/nub. Use when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a flag surface). Encodes the hard gates that stop an audit from surfacing false positives. Auto-triggers on "audit", "compat audit", "parity audit", "find all the gaps", "what are we missing vs <tool".
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Dependency management. It works with pnpm and Git. The repository describes itself as: The fast all-in-one Node.js toolkit. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 568e73a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Audit Thread loads about 1.8k tokens when it runs. Until then it costs about 97 tokens; SKILL.md has 587 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from nubjs/nub at commit 568e73a, republished under its MIT licence (© nubjs). 587 words, ~1,809 tokens.
.claude/skills/audit-thread/SKILL.md (or your agent's skills folder).An audit's deliverable is a CLEAN, COMPLETE, VERIFIED list of real gaps between nub and a reference it claims parity with. A single false positive destroys trust in the whole audit; the bar is zero garbage.
Canonical methodology: AGENTS.md → "Audit threads." Read it first. This skill is the operational surface: the gate checklist, the verbatim dispatch template, and the orchestration shape.
git -C .repos/<tool> describe --tags, its package.json version, the installed tool's --version). Wrong-major reference is the #1 garbage source. When the audit target is a branch/SHA of THIS repo, git fetch origin FIRST and pin origin/<branch>@<sha> — never a local worktree/branch checkout, which routinely lags origin. Verify reachability (git merge-base --is-ancestor <sha> origin/<branch>) before reading a byte.--help reading yield leads only.wiki/ decision docs, and prior thread notes.wiki/research/<topic>.md with all buckets explicit (real gaps / confirmed-OK / intentional-divergence); each finding records reproduction + decision-record cross-check + severity + confidence.Enumerate the full surface (coverage) → harvest candidate gaps → cross-check the decision record → reproduce each against the pinned real tool → adversarially refute in fresh context → surface ONLY survivors, with evidence.
Run it with individually-dispatched agents — not a blind parallel Workflow fan-out that buries the gates.
Only a top-level session dispatches those agents. If you are yourself a dispatched sub-agent, the repo-wide depth cap in AGENTS.local.md applies: run the gates INLINE and return. Gate 4's "fresh context" is then a fresh PASS, not a fresh agent — re-pin, re-run the fixture, and re-check the decision record yourself, defaulting to refuted when uncertain. An audit prong that cannot be refuted inline returns saying so rather than spawning a refuter.
When a finding is ACTIONED. An audit is investigation-scope: it surfaces gaps, it does not land fixes. The moment a finding becomes a code change, verify it the standard way — an ad-hoc fixture sweep against a built binary, re-running the audit's own differential against the pinned reference, then an in-thread read of the diff. A parity fix touching a shared verb/flag dispatch path routinely ripples to sibling commands, which is one of the cases that earns escalating to a fresh-context impact-analysis pass — but that never substitutes for running the sibling commands and diffing them against the reference. Gate 4 asks whether a FINDING is real; impact analysis asks whether a FIX is safe.
You are running a <SCOPE> audit: find where nub diverges from <REFERENCE> <EXACT MAJOR> on <SURFACE>.
This is an AUDIT — the deliverable is a CLEAN, VERIFIED list of REAL gaps. A single false positive is
unacceptable. Follow all 5 gates; do not skip any.
GATE 1 — PIN: The target is <REFERENCE> <EXACT MAJOR>. BEFORE reading anything, verify the version of
every reference you use: `git -C .repos/<tool> describe --tags` and its package.json version, and
`<tool> --version` for any installed binary. If a checkout is the wrong major, check out the right
tag / install the right version FIRST. State the verified versions at the top of your output.
If the AUDIT TARGET is a branch/SHA of THIS repo (not a reference tool): `git fetch origin` FIRST,
pin `origin/<branch>@<sha>` (NEVER a local worktree/branch — it routinely lags origin), and verify
`git merge-base --is-ancestor <sha> origin/<branch>` before reading. State the pinned SHA at the top.
GATE 2 — EMPIRICAL: A gap is NOT a finding until you reproduce it by RUNNING <REFERENCE> <MAJOR> AND nub
on identical input and diffing the actual output. Source-reading and --help parsing are LEADS only.
Build a minimal differential fixture per candidate; capture both commands + both outputs.
GATE 3 — DECISION RECORD: Drop any candidate that is a deprecated/removed flag in <REFERENCE> <MAJOR>,
an npm-ism nub deliberately rejects, one of nub's intentional pnpm-compat divergences, or already
decided/built. Cross-check AGENTS.md "Core design positions", wiki/ decision docs, and prior thread notes.
Deeply evaluate what has ALREADY been discussed — surfacing a settled call is as bad as a false positive.
GATE 4 — REFUTE: After harvesting, re-verify every surviving candidate adversarially (try to REFUTE it:
re-pin, re-reproduce, re-check the record). Treat "irreducible" or "cannot close" as claims that also
require evidence: exhaust the documented mechanism surface and test plausible closures. Keep only
what survives, with its reproduction evidence.
GATE 5 — COVERAGE + PRECISION: Enumerate the FULL surface from <REFERENCE> <MAJOR>'s own authoritative
source (its --help / source), so nothing is missed; AND verify every surfaced item. Output ALL buckets:
real gaps / confirmed-OK / intentional-divergence. Each real finding: reproduction command + both
outputs + decision-record cross-check + severity + confidence.
Deliverable: a catalog at wiki/research/<topic>.md (all buckets) + a tight triaged list of REAL gaps for
the maintainer. Investigation-scope — do NOT land fixes; surface findings recommend-only.When an audit reveals a NEW pitfall not covered above, fold it into the gate it strengthens.
© nubjs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/audit-thread of nubjs/nub.
Open the folder on GitHubat commit 568e73a
Audit Thread next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Audit Thread this skillnubjs/nub | 4.4k | — | ~1.8k | Automated safety check: Pass | MIT | |
| Fix Vulnslinuxfoundation/insights | 280 | — | ~3.8k | Automated safety check: Notes | MIT | |
| React Router Release Notes Prepremix-run/react-router | 57k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Verdaccio Pull Request Workflowverdaccio/verdaccio | 18k | — | ~1.9k | Automated safety check: Pass | MIT | |
| Pnpm Engineteambit/bit | 18k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Ghostty Submodule and GhosttyKit Workflowmanaflow-ai/cmux | 28k | 1 repos | ~580 | Automated safety check: Pass | Custom licence |
linuxfoundation/insights
Automated triage and fixing of Dependabot security vulnerabilities (IN-1189).
remix-run/react-router
Polishes pending React Router change files before the versioning scripts run, and decides whether a long-form What's Changed section is warranted.
verdaccio/verdaccio
Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.
teambit/bit
Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.
manaflow-ai/cmux
Workflow rules for the Ghostty submodule in cmux: rebuilding GhosttyKit.xcframework, pushing fork changes and updating the parent submodule pointer safely.
GitTools/GitVersion
Gives repository-specific .NET guidance for GitVersion: build and test commands, central package management, project layout and coding conventions.
nubjs/nub
Diagnose and clear CPU, memory, and disk contention on the maintainer's dev host.
nubjs/nub
Reclaim disk on the maintainer's Mac when the volume is full or filling — ENOSPC, "no space left on device", a failed build or agent harness, or a routine sweep of Rust build residue.
nubjs/nub
Build a performance chart for nubjs.com — the SVG bar figures in blog posts, docs pages and social posts (a runtime augmentation against plain node, an install or dispatch comparison, a cross-tool…
nubjs/nub
Run ad-hoc Nub tests and debugging probes on real local Linux guests.
nubjs/nub
Performance-trace Nub package-manager installs using the existing phase timings, structured diagnostics, and sampling-profiler workflow.
nubjs/nub
A skill your agent uses when building or testing the nub Rust workspace inside a git worktree — cargo build/test/clippy for nub-cli/nub-core/aube in a worktree off origin/main.
Categories
A skill your agent uses when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a…. Audit Thread is an agent skill from nubjs/nub. Use when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a flag surface).
Audit Thread fits situations like: running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar; A lockfile format; A Node behavior; A flag surface).
Run `npx skills add nubjs/nub --skill audit-thread -a claude-code`. Or copy the skill folder (.claude/skills/audit-thread in nubjs/nub) into .claude/skills/audit-thread in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nubjs/nub --skill audit-thread -a codex`. Or copy the skill folder (.claude/skills/audit-thread in nubjs/nub) into .agents/skills/audit-thread in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nubjs/nub --skill audit-thread -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-thread, .gemini/skills/audit-thread, .github/skills/audit-thread and .opencode/skills/audit-thread in your project.
Going by SKILL.md and its folder, Audit Thread needs the command-line tools its instructions call (git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Audit Thread is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Audit Thread: Fix Vulns (linuxfoundation/insights, 280 stars), React Router Release Notes Prep (remix-run/react-router, 57k stars), Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars) and Pnpm Engine (teambit/bit, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nubjs (a GitHub organization) maintains it in nubjs/nub, which has 4,370 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 7, 2026.
Source: nubjs/nub on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.