Sast Xxe
utkusen/sast-skills
Detect XML External Entity (XXE) vulnerabilities in a codebase using a three-phase approach: recon (find XML parsing sites without external-entity hardening), batched verify (trace user input to…
Guide for resolving NullAway static analysis errors. An agent skill from nwjs/chromium.src.
$ npx skills add nwjs/chromium.src --skill nullaway -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nwjs/chromium.src nullaway --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/nullaway .claude/skills/nullaway && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nullaway" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/skills/nullaway into .claude/skills/nullaway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nullaway", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nwjs/chromium.src/tree/main/agents/skills/nullawayType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nwjs/chromium.src --skill nullaway -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nwjs/chromium.src nullaway --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agents/skills/nullaway .agents/skills/nullaway && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nullaway" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/skills/nullaway into .agents/skills/nullaway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nullaway", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nwjs/chromium.src --skill nullaway -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nwjs/chromium.src nullaway --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agents/skills/nullaway .cursor/skills/nullaway && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nullaway" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/skills/nullaway into .cursor/skills/nullaway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nullaway", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nwjs/chromium.src.git --path agents/skills/nullaway--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nwjs/chromium.src --skill nullaway -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nwjs/chromium.src nullaway --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agents/skills/nullaway .gemini/skills/nullaway && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nullaway" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/skills/nullaway into .gemini/skills/nullaway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nullaway", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nwjs/chromium.src nullawayInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nwjs/chromium.src --skill nullaway -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .github/skills && cp -r skills-src/agents/skills/nullaway .github/skills/nullaway && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nullaway" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/skills/nullaway into .github/skills/nullaway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nullaway", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nwjs/chromium.src --skill nullaway -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nwjs/chromium.src nullaway --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agents/skills/nullaway .opencode/skills/nullaway && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nullaway" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/skills/nullaway into .opencode/skills/nullaway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nullaway", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nullawayGuide for resolving NullAway static analysis errors. An agent skill from nwjs/chromium.src.
Nullaway is an agent skill from nwjs/chromium.src. Guide for resolving NullAway static analysis errors. Best practices for: - Passing ObservableSupplier/Supplier<@Nullable T - Dereferencing potentially @Nullable values - Adding @NullMarked to Java code
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.
It sits in Security, covering Static analysis and SAST. It works with Java. The repository describes itself as: Chromium codebase with NW.js modifications. Based on https://chromium.googlesource.com/chromium/src.git. The licence is BSD-3-Clause.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit a9e8946. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are java).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nullaway loads about 3k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 1,414 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from nwjs/chromium.src at commit a9e8946, republished under its BSD-3-Clause licence (© nwjs). 1,414 words, ~2,999 tokens.
.claude/skills/nullaway/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.@NullMarked vs New CodeThe approach differs significantly depending on whether you are migrating
existing code to @NullMarked or writing new code in an already @NullMarked
context:
@NullMarked:NullUtil.assumeNonNull() when dereferencing immediately
to satisfy the analyzer without runtime overhead. Use assert when storing
or returning values. Use if guards occasionally if it helps avoid
assertions, but avoid changing the logic.@NullMarked code):asserts to enforce contracts. Rely on
correct annotations (or their absence for implicit @NonNull) and only use
null guards for @Nullable values. assumeNonNull() should generally not
be used for new code.assumeNonNull vs assert != nullThe choice between assumeNonNull and Java assert depends on how the value is
used:
@Nullable values immediately: Use
NullUtil.assumeNonNull(x).var value = mSupplier.get();
assumeNonNull(value);
value.doSomething();assumeNonNull
is a no-op that satisfies the analyzer without adding redundant runtime
checks.assumeNonNull() should be on a separate line, almost
always, rather than used inline.assumeNonNull().@Nullable values to non-null parameters: First, look into the
call tree of the receiver class and see if that parameter should be
annotated as @Nullable or not. If it can natively handle null, update the
method signature instead of adding an assertion. If it strictly requires a
non-null value, THEN you MUST use a Java assert x != null; on a preceding
line before passing or storing it.[!CAUTION] NEVER use
assumeNonNull(x)to pass a@Nullablevalue to a non-null parameter or to return it from a non-nullable method. This is STRICTLY FORBIDDEN. You MUST use a Javaasserton a preceding line to add a runtime check.
mReceiver.setSomething(assumeNonNull(nullableValue));assert nullableValue != null;
mReceiver.setSomething(nullableValue);@Nullable values from non-nullable methods: First, consider if
the method's return type can be safely updated to @Nullable. If it cannot
(e.g., because it implements an interface or strictly enforces a non-null
contract), you MUST use a Java assert x != null; on a preceding line before
returning the value. Using assumeNonNull(x) inline within a return statement
is strictly forbidden.return assumeNonNull(nullableValue);assert nullableValue != null;
return nullableValue;@Nullable, prefer updating the method
signature over adding an assertion.assert value != null on Supplier.get()
during initialization. If the supplier value is set LATER (as is common with
UI wiring), the assert might fail immediately during construction. In such
cases, the getter should return @Nullable and callers should handle it,
rather than asserting non-null immediately.Supplier<@Nullable T> to a constructor that expects
Supplier<T> (non-nullable), or vice versa.Supplier<@Nullable T> rather
than wildcards like Supplier<? extends @Nullable T> in method signatures and
fields.SupplierUtils.upcast() is strictly for upcasting the type
parameter to a base class (e.g., Supplier<DerivedT> to Supplier<BaseT>).
Do NOT use it solely for handling nullability differences (e.g., Supplier<T>
to Supplier<@Nullable T>).Supplier<T> to Supplier<@Nullable T>) if you are passing around subclasses
of ObservableSupplier.Supplier<@Nullable T> and handle the nullity. Never use
hacks or assertions to force a Supplier<@Nullable T> to act as a
non-nullable Supplier<T>.Supplier<@Nullable T>.assumeNonNull or assert).() -> assumeNonNull(supplier.get()) or this:
() -> { var x = getter(); assert x != null; return x; }. These are
anti-patterns.ObservableSupplier: Pass supplier.asNonNull() directly.
This returns a NonNullObservableSupplier which satisfies
Supplier<@NonNull T>.Supplier<@Nullable T> and handle the nullity inside the receiver class. Do
not force non-nullability at the call site with hacks.Supplier<@Nullable T> or MonotonicObservableSupplier<T> in method
signatures to avoid forcing non-nullability on callers.org.chromium.build.annotations.Nullable and
org.chromium.build.annotations.NullMarked. Do NOT use androidx.annotation
or javax.annotation variations.@NullMarked: Apply to the class level when you are ready to make the
whole class null-safe.@Nullable: Apply to fields, parameters, and return types that can be
null.@NonNull Default: Values are @NonNull by default in a @NullMarked
class. Do NOT use @NonNull explicitly on fields, parameters, or return
types. Use @NonNull only in the context of nullable generic parameters if
absolutely necessary.@SuppressWarnings("NullAway"):destroy() or onDestroy(): If fields are
nulled out during teardown to prevent memory leaks, do NOT mark the fields
as @Nullable just to satisfy this one assignment. Instead, mark the fields
as @MonotonicNonNull (if late-initialized) or @NonNull (if initialized
in constructor), and add @SuppressWarnings("NullAway") to the destroy()
or onDestroy() method. This prevents having to null-check the fields
everywhere else in the class.@Nullable
field, the parameter itself should usually be marked @Nullable as well, even
if it is not immediately used as nullable in the constructor. This avoids
artificial non-null requirements at construction time.@Nullable, look at
how callers handle the return value:@Nullable.Before (in Caller):
mReceiver = new Receiver(() -> assumeNonNull(nullableSupplier.get()));After:
// Change constructor to take exact Supplier<@Nullable Item>
public Receiver(Supplier<@Nullable Item> supplier) {
mSupplier = supplier;
}
// In usage (Dereferenced right away)
void doSomething() {
var item = mSupplier.get();
assumeNonNull(item);
item.use();
}
// In usage (Stored or Passed)
void storeItem() {
var item = mSupplier.get();
assert item != null;
mStoredItem = item;
}Supplier<DerivedItem> and the receiver
expects Supplier<@Nullable BaseItem>, use SupplierUtils.upcast() to pass
it:mReceiver = new Receiver(SupplierUtils.upcast(derivedSupplier, BaseItem.class));Supplier<@Nullable Item>, pass it directly:mReceiver = new Receiver(nullableSupplier);Before applying the recipe above to force non-nullability or add assertions,
investigate the receiver. If the receiver (or classes it passes the supplier
to) already checks for null or can easily be updated to handle null, prefer
updating the signature to accept Supplier<@Nullable T> instead of forcing
non-nullability.
supplier.asNonNull().get() over var x = supplier.get(); assert x != null;.assumeNonNull(object) from
org.chromium.build.NullUtil instead of assert object != null when you want
to chain calls on the non-null object (e.g.,
assumeNonNull(mLayoutManager).getSomething()). It returns the non-null
object.if (x != null) to assert x != null).get*ForTesting() methods should just return @Nullable
(and be annotated as such) rather than asserting non-null, if the underlying
field is nullable. Let the test handle the nullity.PublicTransitLeakTest as a smoke test locally before
running all tests on CQ to validate functional changes introduced by
assertions.@Nullable or @MonotonicNonNull if
it's initialized later (e.g., in init or initWithProfile).@Nullable to
the method signature.assumeNonNull(null) to satisfy
a callback that expects a non-null value if the value can actually be null.
Update the callback definition to accept @Nullable T.© nwjs, BSD-3-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in agents/skills/nullaway of nwjs/chromium.src.
Open the folder on GitHubat commit a9e8946
Nullaway next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nullaway this skillnwjs/chromium.src | 160 | — | ~3k | Automated safety check: Pass | BSD-3-Clause | |
| Sast Xxeutkusen/sast-skills | 1.3k | — | ~7.2k | Automated safety check: Pass | MIT | |
| Java API Consistency ValidatorArabelaTso/Skills-4-SE | 253 | — | ~660 | Automated safety check: Pass | Apache-2.0 | |
| CodeQL Security Scantrailofbits/skills | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Skylosduriantaco/skylos | 843 | — | ~581 | Automated safety check: Pass | Apache-2.0 | |
| Skylos Securityduriantaco/skylos | 843 | — | ~545 | Automated safety check: Pass | Apache-2.0 |
utkusen/sast-skills
Detect XML External Entity (XXE) vulnerabilities in a codebase using a three-phase approach: recon (find XML parsing sites without external-entity hardening), batched verify (trace user input to…
ArabelaTso/Skills-4-SE
Validate API consistency between two versions of Java libraries.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
duriantaco/skylos
Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.
duriantaco/skylos
Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.
trailofbits/skills
Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.
nwjs/chromium.src
Extracts raw trace data from Perfetto traces, runs arbitrary SQL queries for custom follow-up analysis, and applies expert cognitive principles (Tiered Flow Analysis, Semantic Mismatch, Redundancy)…
nwjs/chromium.src
Autonomous multi-agent performance optimization loop for Chromium and V8.
nwjs/chromium.src
Automated Tracing & Performance Telemetry in Chromium using Perfetto and Telemetry benchmarks.
nwjs/chromium.src
Queries Chrome commit, version, release, and milestone metadata.
nwjs/chromium.src
Search and reference Chromium documentation from the local docs index, including design docs, APIs, and development guides.
nwjs/chromium.src
Diagnose Chromium GN dependency and include-visibility failures, including BUILD.gn deps/publicdeps, DEPS include rules, private headers, and circular dependencies.
Works with
Categories
Guide for resolving NullAway static analysis errors. An agent skill from nwjs/chromium.src. src. Guide for resolving NullAway static analysis errors.
Nullaway fits situations like: tasks that involve Static analysis and SAST.
Run `npx skills add nwjs/chromium.src --skill nullaway -a claude-code`. Or copy the skill folder (agents/skills/nullaway in nwjs/chromium.src) into .claude/skills/nullaway in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nwjs/chromium.src --skill nullaway -a codex`. Or copy the skill folder (agents/skills/nullaway in nwjs/chromium.src) into .agents/skills/nullaway in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nwjs/chromium.src --skill nullaway -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nullaway, .gemini/skills/nullaway, .github/skills/nullaway and .opencode/skills/nullaway in your project.
SKILL.md names no scripts, command-line tools or credentials: Nullaway is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Nullaway is published under the BSD-3-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Nullaway: Sast Xxe (utkusen/sast-skills, 1.3k stars), Java API Consistency Validator (ArabelaTso/Skills-4-SE, 253 stars), CodeQL Security Scan (trailofbits/skills, 7.4k stars) and Skylos (duriantaco/skylos, 843 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nwjs (a GitHub organization) maintains it in nwjs/chromium.src, which has 160 GitHub stars. The repository holds 64 skills in this directory. The repository was last updated on October 3, 2026.
Source: nwjs/chromium.src on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.