Kedro Security Review
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
Turns a verbose, reporter-submitted obot security advisory into a short, deployer-facing writeup covering impact, affected versions and mitigation.
$ npx skills add obot-platform/obot --skill rewrite-security-advisory -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install obot-platform/obot rewrite-security-advisory --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/obot-platform/obot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/rewrite-security-advisory .claude/skills/rewrite-security-advisory && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "rewrite-security-advisory" agent skill from https://github.com/obot-platform/obot/tree/main/.claude/skills/rewrite-security-advisory into .claude/skills/rewrite-security-advisory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rewrite-security-advisory", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/obot-platform/obot/tree/main/.claude/skills/rewrite-security-advisoryType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add obot-platform/obot --skill rewrite-security-advisory -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install obot-platform/obot rewrite-security-advisory --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/obot-platform/obot.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/rewrite-security-advisory .agents/skills/rewrite-security-advisory && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "rewrite-security-advisory" agent skill from https://github.com/obot-platform/obot/tree/main/.claude/skills/rewrite-security-advisory into .agents/skills/rewrite-security-advisory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rewrite-security-advisory", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add obot-platform/obot --skill rewrite-security-advisory -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install obot-platform/obot rewrite-security-advisory --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/obot-platform/obot.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/rewrite-security-advisory .cursor/skills/rewrite-security-advisory && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "rewrite-security-advisory" agent skill from https://github.com/obot-platform/obot/tree/main/.claude/skills/rewrite-security-advisory into .cursor/skills/rewrite-security-advisory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rewrite-security-advisory", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/obot-platform/obot.git --path .claude/skills/rewrite-security-advisory--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add obot-platform/obot --skill rewrite-security-advisory -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install obot-platform/obot rewrite-security-advisory --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/obot-platform/obot.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/rewrite-security-advisory .gemini/skills/rewrite-security-advisory && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "rewrite-security-advisory" agent skill from https://github.com/obot-platform/obot/tree/main/.claude/skills/rewrite-security-advisory into .gemini/skills/rewrite-security-advisory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rewrite-security-advisory", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install obot-platform/obot rewrite-security-advisoryInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add obot-platform/obot --skill rewrite-security-advisory -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/obot-platform/obot.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/rewrite-security-advisory .github/skills/rewrite-security-advisory && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "rewrite-security-advisory" agent skill from https://github.com/obot-platform/obot/tree/main/.claude/skills/rewrite-security-advisory into .github/skills/rewrite-security-advisory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rewrite-security-advisory", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add obot-platform/obot --skill rewrite-security-advisory -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install obot-platform/obot rewrite-security-advisory --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/obot-platform/obot.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/rewrite-security-advisory .opencode/skills/rewrite-security-advisory && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "rewrite-security-advisory" agent skill from https://github.com/obot-platform/obot/tree/main/.claude/skills/rewrite-security-advisory into .opencode/skills/rewrite-security-advisory/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rewrite-security-advisory", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
rewrite-security-advisoryTurns a verbose, reporter-submitted obot security advisory into a short, deployer-facing writeup covering impact, affected versions and mitigation.
Pulls the advisory through the authenticated GitHub API rather than the web URL, since a private draft advisory 404s for an unauthenticated fetch, retrieving the summary, full description, CVSS vector and score, affected range and credited reporters in one call. The advisory's comment thread is not exposed by either the REST or GraphQL API and the draft page also 404s for a plain fetch, so the user is asked to paste the comments directly, especially the team's own response, since that thread often reframes the issue, for example clarifying that a reported mechanism was actually a fail-safe.
Affected versions are always expressed as release tags rather than commit hashes, because deployers reason about releases, not commits; when the patched field is empty or recorded as a commit, the user is asked which release contains the fix so the affected range can be written as everything up to and including the last release before that fix.
The rewrite itself follows Obot's fixed section order: a plain-language title that reflects the real, team-confirmed impact rather than just copying a reporter's headline mechanism, followed by a short Summary, Am I affected, Details, Impact, Mitigation, Severity and Credits. The result is written to a markdown file at the repo root for the user to review and paste into the advisory editor themselves, never pushed to GitHub automatically.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 43a9522. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Advisory Rewriter loads about 1.3k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 596 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from obot-platform/obot at commit 43a9522, republished under its MIT licence (© obot-platform). 596 words, ~1,267 tokens.
.claude/skills/rewrite-security-advisory/SKILL.md (or your agent's skills folder).Take a verbose, reporter-submitted obot security advisory and rewrite it into Obot's concise, user-facing format. The goal is a short writeup a deployer can read and immediately know whether they're affected and what to do — not a reproduction of the researcher's full report.
Output is a markdown file at the repo root named <GHSA-id>.md. The user reviews
it and pastes it into the GitHub advisory editor themselves. Do not push it to
GitHub or modify the live advisory unless explicitly asked.
The advisory is usually a private draft, so the web URL 404s for WebFetch. Pull it via the authenticated API instead:
gh api repos/obot-platform/obot/security-advisories/<GHSA-id> --jq '{summary, description, severity, cvss: .cvss.vector_string, score: .cvss.score, vuln_range: .vulnerabilities[0].vulnerable_version_range, patched: .vulnerabilities[0].patched_versions, credits: [.credits_detailed[].user.login], cwes: [.cwes[].cwe_id]}'This gives you the title, the reporter's full description (Summary/Details/PoC/Impact), CVSS vector + score, affected range, and the credited reporters.
The advisory's comment thread is NOT exposed by the GitHub API (REST or GraphQL), and the web page 404s for WebFetch on drafts. Ask the user to paste the comments, especially the obot team's response (often from the lead eng). The comments frequently change the framing — e.g. clarifying that the reporter's headline mechanism was actually a fail-safe and the real fix was something else, or noting which parts were disputed. Do not finalize the rewrite without them.
The advisory's patched field is often empty and vuln_range may be recorded as
a commit hash. Always express versions as release tags, never commit hashes
(users reason about releases, not commits). Ask the user which release contains
the fix if it isn't obvious; the affected range is then <= <last release before the fix> (e.g. fixed in v0.23.0 → affected <= v0.22.1).
Use exactly these sections, in this order. Keep it tight — a few sentences per section. This is a summary for deployers, not the researcher's report.
# ...): a plain-language description of the actual issue and its
real impact. Don't just copy the reporter's title if it leads with a mechanism
that the team's comments downgraded (e.g. don't headline "audience confusion"
if that turned out to be a fail-safe). Keep the (incomplete fix of GHSA-...)
style suffix when the advisory metadata has one.<= vX.Y.Z) plus the
preconditions (config flags, required role, required user interaction). Note
when a configuration makes it a non-issue.checkUICVSS v3.1 Score: **<score>/10 (<Severity>)** — \<vector>``The Obot team would like to thank [@<reporter>](https://github.com/<reporter>) for responsibly disclosing this issue in accordance with our [security policy](https://github.com/obot-platform/obot/?tab=security-ov-file).If there are multiple reporters, thank each ([@a](...) and [@b](...)).
Write to <repo-root>/<GHSA-id>.md, then paste the full rendered text back in the
chat so the user can review inline. Flag anything you assumed (patched version,
title change) so they can correct it.
See the advisory writeups already in the repo root (e.g. GHSA-jgh3-fggc-mcpm.md,
GHSA-pr6h-vr44-xq8j.md, GHSA-xwmw-prc4-v3cr.md) for the exact tone and length
to match.
© obot-platform, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/rewrite-security-advisory of obot-platform/obot.
Open the folder on GitHubat commit 43a9522
Security Advisory Rewriter next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Advisory Rewriter this skillobot-platform/obot | 1.1k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Kedro Security Reviewkedro-org/kedro | 11k | — | ~3.3k | Automated safety check: Pass | Custom licence | |
| Symfony Security Reviewsymfony/symfony | 31k | — | ~2.9k | Automated safety check: Pass | MIT | |
| Pyspector Security AuditParzivalHack/PySpector | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | |
| Slowmist Agent Securityslowmist/slowmist-agent-security | 508 | — | ~1.4k | Automated safety check: Pass | MIT | |
| SkepticRaoFoundation/subtensor | 389 | — | ~660 | Automated safety check: Pass | Apache-2.0 |
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
symfony/symfony
Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening.
ParzivalHack/PySpector
Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.
slowmist/slowmist-agent-security
Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security.
RaoFoundation/subtensor
Run the security-focused Skeptic persona on the local working tree's diff against a base branch.
kedro-org/kedro-plugins
Run a security scan on the kedro-plugins codebase or a pull request.
obot-platform/obot
Drafts release notes for an upcoming Obot minor release and saves them as an unpublished GitHub draft release, never tagging or publishing.
obot-platform/obot
Drafts a release announcement blog post for an obot release as a Markdown file, with an optional WordPress draft through MCP and no live publishing without confirmation.
Works with
Categories
Turns a verbose, reporter-submitted obot security advisory into a short, deployer-facing writeup covering impact, affected versions and mitigation. Pulls the advisory through the authenticated GitHub API rather than the web URL, since a private draft advisory 404s for an unauthenticated fetch, retrieving the summary, full description, CVSS vector and score, affected range and credited reporters in one call. The advisory's comment thread is not exposed by either the REST or GraphQL API and the draft page also 404s for a plain fetch, so the user is asked to paste the comments directly, especially the team's own response, since that thread often reframes the issue, for example clarifying that a reported mechanism was actually a fail-safe.
Security Advisory Rewriter fits situations like: rewriting a verbose security advisory into Obot's short user-facing format; simplifying a GHSA report so deployers can tell if they're affected; expressing a security advisory's affected range as release tags instead of commit hashes; incorporating the advisory's comment thread into the final writeup.
Run `npx skills add obot-platform/obot --skill rewrite-security-advisory -a claude-code`. Or copy the skill folder (.claude/skills/rewrite-security-advisory in obot-platform/obot) into .claude/skills/rewrite-security-advisory in your project. Claude Code loads it when a task matches its description.
Run `npx skills add obot-platform/obot --skill rewrite-security-advisory -a codex`. Or copy the skill folder (.claude/skills/rewrite-security-advisory in obot-platform/obot) into .agents/skills/rewrite-security-advisory in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add obot-platform/obot --skill rewrite-security-advisory -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rewrite-security-advisory, .gemini/skills/rewrite-security-advisory, .github/skills/rewrite-security-advisory and .opencode/skills/rewrite-security-advisory in your project.
Going by SKILL.md and its folder, Security Advisory Rewriter needs the command-line tools its instructions call (gh). Our summary lists: The gh CLI, authenticated against the obot repository.
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Advisory Rewriter is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Advisory Rewriter: Kedro Security Review (kedro-org/kedro, 11k stars), Symfony Security Review (symfony/symfony, 31k stars), Pyspector Security Audit (ParzivalHack/PySpector, 151 stars) and Slowmist Agent Security (slowmist/slowmist-agent-security, 508 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
obot-platform (a GitHub organization) maintains it in obot-platform/obot, which has 1,095 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 8, 2026.
Source: obot-platform/obot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.