Official agent skill

Review Security Issue

by NVIDIA in NVIDIA/OpenShell

Review an authorized security issue for validity, severity, and a remediation plan.

OfficialApache-2.0Auto-check passed

Install Review Security Issue

skills CLI
$ npx skills add NVIDIA/OpenShell --skill review-security-issue -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NVIDIA/OpenShell review-security-issue --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NVIDIA/OpenShell.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/review-security-issue .claude/skills/review-security-issue && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-security-issue
GitHub stars
15k
Token cost
~425 tokens
SKILL.md length
214 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
Apache-2.0

At a glance

Review an authorized security issue for validity, severity, and a remediation plan.

  • Works in 4 steps: Fetch the issue and comments with gh… → Inspect affected code and verify the… → If actionable, propose a remediation… → …
  • Calls gh

What it does

Review Security Issue is an agent skill from NVIDIA/OpenShell, published by the product's own GitHub organization. Review an authorized security issue for validity, severity, and a remediation plan.

Its SKILL.md is about 430 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: OpenShell is the safe, private runtime for autonomous AI agents. The licence is Apache-2.0.

Example prompts

  • “/review-security-issue”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Fetch the issue and comments with gh issue view --json title,body,state,labels,comments. Follow Label Discovery in CONTRIBUTING.md rather…
  2. Inspect affected code and verify the claim. Assess impact, exploitability, prerequisites, affected surface, and a concrete attack…
  3. If actionable, propose a remediation plan with code areas, safe rollout, and focused tests. If not actionable, explain the evidence and…
  4. Post the review only when the request authorizes posting. Begin the comment with > 🔒 security-review-agent so later reviews can detect…

What it can do on your machine

Read from SKILL.md and the folder at commit 277f922. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Security Issue loads about 425 tokens when it runs. Until then it costs about 26 tokens; SKILL.md has 214 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~26
When it runs · the whole SKILL.md, loaded when a task matches
~425

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from NVIDIA/OpenShell at commit 277f922, republished under its Apache-2.0 licence (© NVIDIA). 214 words, ~425 tokens.

Download SKILL.mdSave it as .claude/skills/review-security-issue/SKILL.md (or your agent's skills folder).
name
review-security-issue
description
Review an authorized security issue for validity, severity, and a remediation plan.
metadata.internal
true

Review Security Issue

Review a security concern through its authorized private workflow. Do not file or expand a vulnerability in a public issue; follow SECURITY.md. A direct request to review authorizes review only, not remediation. For unattended review, inspect current state:* label descriptions, maintainer assignments, and comments to verify that review is authorized.

Assess

  1. Fetch the issue and comments with gh issue view <id> --json title,body,state,labels,comments. Follow Label Discovery in CONTRIBUTING.md rather than assuming exact label names; resolve unclear meanings before interpreting authorization. Verify that this is an authorized security issue and that a prior review does not already answer the request.
  2. Inspect affected code and verify the claim. Assess impact, exploitability, prerequisites, affected surface, and a concrete attack scenario. Separate evidence from assumptions and give a severity with rationale.
  3. If actionable, propose a remediation plan with code areas, safe rollout, and focused tests. If not actionable, explain the evidence and recommended disposition. Do not decide product acceptance or silently close the issue.
  4. Post the review only when the request authorizes posting. Begin the comment with > **🔒 security-review-agent** so later reviews can detect it. Keep sensitive details in the authorized private venue.

A human decides whether to authorize remediation. Route an authorized fix to fix-security-issue. Do not introduce agent:* workflow labels.

© NVIDIA, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/review-security-issue of NVIDIA/OpenShell.

Open the folder on GitHubat commit 277f922

Compare with similar skills

Review Security Issue next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Security Issue compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Security Issue this skillNVIDIA/OpenShell15k—~425Automated safety check: PassApache-2.0
Form Validationthedaviddias/Front-End-Checklist74k—~633Automated safety check: PassMIT
Hermes Agent Skill AuthoringNousResearch/hermes-agent252k—~3.6kAutomated safety check: PassMIT
Configuring Oauth2 Authorization Flowmukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.0
Authoring Skillsvercel/next.js143k—~1kAutomated safety check: PassMIT
Validateagenticnotetaking/arscontexta3.5k—~3kAutomated safety check: PassMIT

Similar skills

  • Form Validation

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing templates, rendered HTML, or shared components related to Validate forms accessibly.

    74k GitHub stars~633 tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Hermes Agent Skill Authoring

    NousResearch/hermes-agent

    Author in-repo SKILL.md files: frontmatter and structure. An agent skill from NousResearch/hermes-agent.

    252k GitHub stars~3.6k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Configuring Oauth2 Authorization Flow

    mukul975/Anthropic-Cybersecurity-Skills

    Configures secure OAuth 2.0 authorization flows, including Authorization Code with PKCE, Client Credentials, and Device Authorization Grant, covering flow selection, PKCE implementation, token…

    34k GitHub stars~1.7k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Authoring Skills

    vercel/next.js

    Official

    How to create and maintain agent skills in .agents/skills/. An agent skill from vercel/next.js.

    143k GitHub stars~1k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Validate

    agenticnotetaking/arscontexta

    Schema validation for notes. An agent skill from agenticnotetaking/arscontexta.

    3.5k GitHub stars~3k tokensUpdated 7 mo ago
    Frontend & DesignAuto-check passed
  • Abp Authorization

    abpframework/abp

    ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.

    14k GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed

More from NVIDIA/OpenShell

All 23 skills in this repo
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    15k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Create GitHub Issue

    NVIDIA/OpenShell

    Official

    Create GitHub issues using the gh CLI. An agent skill from NVIDIA/OpenShell.

    15k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Create GitHub PR

    NVIDIA/OpenShell

    Official

    Create GitHub pull requests using the gh CLI. An agent skill from NVIDIA/OpenShell.

    15k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Debug Inference

    NVIDIA/OpenShell

    Official

    Debug inference clients that use an attached provider and its native endpoint, including hosted APIs and host-local Ollama, vLLM, SGLang, TRT-LLM, LM Studio, or NIM.

    15k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Debug Openshell Cluster

    NVIDIA/OpenShell

    Official

    Debug why an OpenShell gateway deployment is unhealthy, unreachable, or unable to create sandboxes.

    15k GitHub stars~19k tokensUpdated today
    Auto-check: notes
  • Gator Gate

    NVIDIA/OpenShell

    Official

    Validate and monitor OpenShell GitHub issues and PRs using the gator: state machine.

    15k GitHub stars~19k tokensUpdated today
    Auto-check passed

Questions about Review Security Issue

What does Review Security Issue do?

Review an authorized security issue for validity, severity, and a remediation plan. Review Security Issue is an agent skill from NVIDIA/OpenShell, published by the product's own GitHub organization. Review an authorized security issue for validity, severity, and a remediation plan.

How do I install Review Security Issue in Claude Code?

Run `npx skills add NVIDIA/OpenShell --skill review-security-issue -a claude-code`. Or copy the skill folder (.agents/skills/review-security-issue in NVIDIA/OpenShell) into .claude/skills/review-security-issue in your project. Claude Code loads it when a task matches its description.

How do I install Review Security Issue in Codex?

Run `npx skills add NVIDIA/OpenShell --skill review-security-issue -a codex`. Or copy the skill folder (.agents/skills/review-security-issue in NVIDIA/OpenShell) into .agents/skills/review-security-issue in your project. Codex loads it when a task matches its description.

Can I use Review Security Issue in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NVIDIA/OpenShell --skill review-security-issue -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-security-issue, .gemini/skills/review-security-issue, .github/skills/review-security-issue and .opencode/skills/review-security-issue in your project.

What does Review Security Issue need to run?

Going by SKILL.md and its folder, Review Security Issue needs the command-line tools its instructions call (gh).

Does Review Security Issue access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review Security Issue safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Security Issue use?

Review Security Issue is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Security Issue use?

About 425 tokens (SKILL.md is roughly 1.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Security Issue?

Skills that share tags, products or a category with Review Security Issue: Form Validation (thedaviddias/Front-End-Checklist, 74k stars), Hermes Agent Skill Authoring (NousResearch/hermes-agent, 252k stars), Configuring Oauth2 Authorization Flow (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Authoring Skills (vercel/next.js, 143k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Security Issue?

NVIDIA (a GitHub organization, an official publisher) maintains it in NVIDIA/OpenShell, which has 15,338 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 8, 2026.

Source: NVIDIA/OpenShell on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.