Agent skill

Joern Slice

by opensage-agent in opensage-agent/opensage-adk

Tool to get the program slice for a given function using Joern.

Apache-2.0Auto-check passedSecurity

Install Joern Slice

skills CLI
$ npx skills add opensage-agent/opensage-adk --skill joern-slice -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install opensage-agent/opensage-adk joern-slice --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/opensage-agent/opensage-adk.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/opensage/bash_tools/static_analysis/joern-slice .claude/skills/joern-slice && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
joern-slice
GitHub stars
127
Token cost
~189 tokens
SKILL.md length
63 words
Files
2 (incl. scripts)
Skills in repo
21
Repo updated
First seen
Licence
Apache-2.0

At a glance

Tool to get the program slice for a given function using Joern.

  • Tasks that involve Static analysis and SAST
  • SKILL.md covers Usage, Parameters, Return Value and Requires Sandbox
  • Runs Shell scripts from its folder

What it does

Joern Slice is an agent skill from opensage-agent/opensage-adk. Tool to get the program slice for a given function using Joern.

Its SKILL.md is about 190 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/joern_slice.sh`).

It sits in Security, covering Static analysis and SAST. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Static analysis and SAST

Example prompts

  • “/joern-slice”

Requirements

  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit 54d6470. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Joern Slice loads about 189 tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 63 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~189

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from opensage-agent/opensage-adk at commit 54d6470, republished under its Apache-2.0 licence (© opensage-agent). 63 words, ~189 tokens.

Download SKILL.mdSave it as .claude/skills/joern-slice/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
joern-slice
description
Tool to get the program slice for a given function using Joern.
should_run_in_sandbox
joern
returns_json
false

Joern Slice Tool

Tool to get the program slice for a given function using Joern.

Usage

bash
/bash_tools/static_analysis/joern-slice/scripts/joern_slice.sh "function_name" --file-path "relative/path/to/file.py"

Parameters

function_name (required, positional position 0)

Type: str

Function name to slice.

--file-path (optional, named parameter)

Type: str

Optional file path where the function is defined.

Return Value

Returns plain text output listing slice information for each file, including file paths and line numbers.

Requires Sandbox

joern

© opensage-agent, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in src/opensage/bash_tools/static_analysis/joern-slice of opensage-agent/opensage-adk.

  • SKILL.md
  • scripts/joern_slice.sh

Open the folder on GitHubat commit 54d6470

Compare with similar skills

Joern Slice next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Joern Slice compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Joern Slice this skillopensage-agent/opensage-adk127—~189Automated safety check: PassApache-2.0
Semgrepvigolium/piolium1401 repos~2.4kAutomated safety check: NotesMIT
C To AstNarwhal-Lab/MagicSkills316—~1.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
LLM Sast ScannerSunWeb3Sec/llm-sast-scanner286—~6.2kAutomated safety check: PassNone
Sast SemgrepAgentSecOps/SecOpsAgentKit2202 repos~2.4kAutomated safety check: PassCustom licence

Similar skills

  • Semgrep

    vigolium/piolium

    Run Semgrep static analysis scan on a codebase using parallel subagents.

    140 GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • C To Ast

    Narwhal-Lab/MagicSkills

    Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

    316 GitHub stars~1.1k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • LLM Sast Scanner

    SunWeb3Sec/llm-sast-scanner

    General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.

    286 GitHub stars~6.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Sast Semgrep

    AgentSecOps/SecOpsAgentKit

    Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

    220 GitHub starsUsed in 2 repos~2.4k tokens
    SecurityAuto-check passed
  • Triage Codeql

    netdata/netdata

    Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

    81k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes

More from opensage-agent/opensage-adk

All 21 skills in this repo
  • Run Fuzzing Campaign

    opensage-agent/opensage-adk

    Run a fuzzing campaign using AFL++ with optional seeds; supports --custommutatorpath (you can write your own custom mutator and use this to execute).

    127 GitHub stars~542 tokensUpdated 2 mo ago
    Auto-check passed
  • Pool

    opensage-agent/opensage-adk

    Run N tasks under a concurrency cap K via a sliding-window worker pool.

    127 GitHub stars~462 tokensUpdated 2 mo ago
    Auto-check passed
  • Create New Tool

    opensage-agent/opensage-adk

    Scaffold a new bashtools Skill under bashtools/newtools/. An agent skill from opensage-agent/opensage-adk.

    127 GitHub stars~302 tokensUpdated 2 mo ago
    Auto-check passed
  • Extract Crashes

    opensage-agent/opensage-adk

    Extract crash inputs from fuzzing output into a target directory.

    127 GitHub stars~215 tokensUpdated 2 mo ago
    Auto-check passed
  • Get Call Paths

    opensage-agent/opensage-adk

    Get a path in the call graph from a source function to a specified destination function in the codebase.

    127 GitHub stars~272 tokensUpdated 2 mo ago
    Auto-check passed
  • Get Callee

    opensage-agent/opensage-adk

    Tool to get the callee of a function in the codebase by function name and file path.

    127 GitHub stars~223 tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Joern Slice

What does Joern Slice do?

Tool to get the program slice for a given function using Joern. Joern Slice is an agent skill from opensage-agent/opensage-adk. Tool to get the program slice for a given function using Joern.

When should I use Joern Slice?

Joern Slice fits situations like: tasks that involve Static analysis and SAST.

How do I install Joern Slice in Claude Code?

Run `npx skills add opensage-agent/opensage-adk --skill joern-slice -a claude-code`. Or copy the skill folder (src/opensage/bash_tools/static_analysis/joern-slice in opensage-agent/opensage-adk) into .claude/skills/joern-slice in your project. Claude Code loads it when a task matches its description.

How do I install Joern Slice in Codex?

Run `npx skills add opensage-agent/opensage-adk --skill joern-slice -a codex`. Or copy the skill folder (src/opensage/bash_tools/static_analysis/joern-slice in opensage-agent/opensage-adk) into .agents/skills/joern-slice in your project. Codex loads it when a task matches its description.

Can I use Joern Slice in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add opensage-agent/opensage-adk --skill joern-slice -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/joern-slice, .gemini/skills/joern-slice, .github/skills/joern-slice and .opencode/skills/joern-slice in your project.

What does Joern Slice need to run?

Going by SKILL.md and its folder, Joern Slice needs a shell for the scripts in its folder. Our summary lists: A Bash shell.

Does Joern Slice access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Joern Slice safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Joern Slice use?

Joern Slice is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Joern Slice use?

About 189 tokens (SKILL.md is roughly 756 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Joern Slice?

Skills that share tags, products or a category with Joern Slice: Semgrep (vigolium/piolium, 140 stars), C To Ast (Narwhal-Lab/MagicSkills, 316 stars), Semgrep Security Scan (trailofbits/skills, 7.4k stars) and LLM Sast Scanner (SunWeb3Sec/llm-sast-scanner, 286 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Joern Slice?

opensage-agent (a GitHub organization) maintains it in opensage-agent/opensage-adk, which has 127 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on August 4, 2026.

Source: opensage-agent/opensage-adk on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.