Fla Ascend Performance
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
Protocol Type Trigger NAMEDEXTERNALPROTOCOL (detected when recon finds import/interface for an identifiable external protocol — not standard libraries).
$ npx skills add PlamenTSV/plamen --skill integration-hazard-research -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install PlamenTSV/plamen integration-hazard-research --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/injectable/integration-hazard-research .claude/skills/integration-hazard-research && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "integration-hazard-research" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/integration-hazard-research into .claude/skills/integration-hazard-research/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "integration-hazard-research", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/integration-hazard-researchType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add PlamenTSV/plamen --skill integration-hazard-research -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install PlamenTSV/plamen integration-hazard-research --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agents/skills/injectable/integration-hazard-research .agents/skills/integration-hazard-research && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "integration-hazard-research" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/integration-hazard-research into .agents/skills/integration-hazard-research/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "integration-hazard-research", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill integration-hazard-research -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install PlamenTSV/plamen integration-hazard-research --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agents/skills/injectable/integration-hazard-research .cursor/skills/integration-hazard-research && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "integration-hazard-research" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/integration-hazard-research into .cursor/skills/integration-hazard-research/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "integration-hazard-research", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/PlamenTSV/plamen.git --path agents/skills/injectable/integration-hazard-research--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add PlamenTSV/plamen --skill integration-hazard-research -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install PlamenTSV/plamen integration-hazard-research --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agents/skills/injectable/integration-hazard-research .gemini/skills/integration-hazard-research && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "integration-hazard-research" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/integration-hazard-research into .gemini/skills/integration-hazard-research/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "integration-hazard-research", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install PlamenTSV/plamen integration-hazard-researchInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add PlamenTSV/plamen --skill integration-hazard-research -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .github/skills && cp -r skills-src/agents/skills/injectable/integration-hazard-research .github/skills/integration-hazard-research && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "integration-hazard-research" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/integration-hazard-research into .github/skills/integration-hazard-research/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "integration-hazard-research", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add PlamenTSV/plamen --skill integration-hazard-research -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install PlamenTSV/plamen integration-hazard-research --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/PlamenTSV/plamen.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agents/skills/injectable/integration-hazard-research .opencode/skills/integration-hazard-research && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "integration-hazard-research" agent skill from https://github.com/PlamenTSV/plamen/tree/main/agents/skills/injectable/integration-hazard-research into .opencode/skills/integration-hazard-research/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "integration-hazard-research", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
integration-hazard-researchProtocol Type Trigger NAMEDEXTERNALPROTOCOL (detected when recon finds import/interface for an identifiable external protocol — not standard libraries).
Integration Hazard Research is an agent skill from PlamenTSV/plamen. Protocol Type Trigger NAMEDEXTERNALPROTOCOL (detected when recon finds import/interface for an identifiable external protocol — not standard libraries). Researches known integration hazards of the target protocol.
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security. The repository describes itself as: Autonomous Web3 security audit agent for Claude Code. The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 795962b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Integration Hazard Research loads about 3.7k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 1,823 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from PlamenTSV/plamen at commit 795962b, republished under its MIT licence (© PlamenTSV). 1,823 words, ~3,692 tokens.
.claude/skills/integration-hazard-research/SKILL.md (or your agent's skills folder).Protocol Type Trigger:
NAMED_EXTERNAL_PROTOCOL— detected when recon identifies imports or interface calls to a named external protocol (Uniswap, Aave, Balancer, Compound, Curve, Chainlink, Lido, MakerDAO, etc.) that is NOT a standard library (OpenZeppelin, solmate, solady) and NOT the protocol under audit itself. Inject Into: depth-external agent Language: All chains (EVM primary; Solana/Aptos/Sui when integrating with named on-chain protocols) Finding prefix:[IHR-N]Added in: v1.1.5
This skill adds a research phase (Section 0) before depth-external's existing code analysis. All sections map to depth-external's domain. The orchestrator includes this skill in the depth-external agent's prompt when NAMED_EXTERNAL_PROTOCOL is flagged.
When decomposing into investigation questions:
Recon Agent 3 detects named external protocol imports during TASK 6 pattern scanning. Indicators:
IUniswapV2Router, IUniswapV3Pool, IBalancerVault, IPool, IAToken, ICToken, ILendingPool, ICurvePool, IChainlinkAggregator, IStETH@uniswap/, @aave/, @balancer-labs/, @chainlink/, @openzeppelin/ (only when calling protocol-specific functions, not generic utilities)The flag records which protocols were detected: NAMED_EXTERNAL_PROTOCOL: [Uniswap V3, Chainlink]
For each section below, execute in order:
For EACH named external protocol detected by recon:
DO NOT call mcp__unified-vuln-db__search_solodit_live or any tavily/web-search
MCP tool for dependency research. They are unavailable in depth-phase subagent
contexts — the driver launches depth workers with --disallowedTools mcp__*
and an empty MCP server config to prevent cold-start hangs. Any Solodit/Tavily
MCP call in this phase will silently fail or hang; do not attempt it.
Read {SCRATCHPAD}/external_dependency_research.md instead. This is the
recon-baked research ledger: recon runs as a phase-LLM with live
WebSearch/WebFetch/tavily_search access and already researched every
detected external dependency's real interface/semantics (deployed source,
ABI/arity, monotonicity, gas/error behavior) before depth ever runs. For each
target protocol/dependency, find its row: Dependency | Integration Surface (file:line) | Assumed Behavior (as coded) | Real Behavior (researched) | Source (URL + fetch date) | Conformance MATCH/MISMATCH/CHECK | Fetch Status OK/FETCH_FAILED:reason. Use the ledger's Real Behavior / Conformance columns
as your hazard-catalog input for Section 0c below instead of live search
results.
For an integration surface in your target that is NOT covered by any ledger
row (a dependency the ledger missed, or a row with Fetch Status: FETCH_FAILED), do NOT guess the real behavior and do NOT silently fall
through to the 0d floor catalog as if it were live research. Emit, in your
finding output, one escalation line per uncovered surface:
NEEDS_DEPENDENCY_RESEARCH: <dependency>:<file:line>: <what you need to know>Then proceed under the assumed WORST-CASE realistic external condition per
Rule 10 (rules/finding-output-format.md), tagging the finding
[EXTERNAL-ASSUMPTION: <assumed condition>]. Note: native WebSearch/
WebFetch (non-MCP Claude Code tools) remain available if you need a single
targeted check beyond the ledger — but the ledger is the primary source and
should cover the large majority of surfaces; ad-hoc web search is not a
substitute for reading it first.
| Target Protocol | Known Integration Hazard | Severity | Root Cause | Source | Applicable to This Integration? |
|---|---|---|---|---|---|
| {protocol} | {hazard title} | {sev} | {brief root cause} | {ledger row dependency name / URL from external_dependency_research.md} | YES / NO / CHECK |
Applicability criteria (same as FORK_ANCESTRY):
Cross-chain gateways frequently deliver the gas token in a DIFFERENT FORM than the handler assumes — native vs wrapped (e.g. ETH vs WETH). This is an asset-FORM mismatch, distinct from the asset-IDENTITY (declared-output-token vs delivered-token) mismatch. For EACH inbound callback (onCall/onReceive/onRevert/router callback) and EACH outbound deposit/withdraw:
approve/transferFrom/swap requires the asset to already be wrapped; a .call{value:}/native send requires it to be native.UNVERIFIED): the callback names a wrapped-token address as the asset param but the handler moves it via ERC20 approve/transfer with NO deposit{value:}/withdraw() reconciliation (or vice-versa). The missing inbound native→wrapped (or wrapped→native) conversion is a candidate asset-form mismatch — verify reachability and impact.UNVERIFIED.This floor is a coarse last resort, not a substitute for 0a. Use it ONLY when
BOTH hold: (1) external_dependency_research.md has no row for the
dependency (or the row is Fetch Status: FETCH_FAILED), AND (2) you have
already emitted the matching NEEDS_DEPENDENCY_RESEARCH escalation line for
it per 0b. Do NOT reach for this table as a first move, and do NOT treat a
hit here as equivalent to a live-researched ledger row — it only lists
historical bug classes for a fixed list of famous protocols, not the
dependency's current real interface/semantics. Check EACH applicable
protocol against this minimum catalog:
This floor is keyed on the dependency's TYPE (generic mechanism), NOT on any specific protocol name — brand-keyed rows are prohibited (a floor row naming a specific protocol is the confirmed benchmark-contamination vector; see the HARD no-overfit rule). Classify the detected dependency into a type below and check the generic hazard class; use at most one illustrative brand only in prose, never as the row key.
| Dependency Type | Generic Integration Hazard (class) | Check For |
|---|---|---|
| AMM / swap pool | Slippage bypass when min-out may be 0; stale TWAP/observation read from an inactive pool; read-only reentrancy via pool-balance views during a callback | any swap call with zero/unbounded slippage; a price/observation read with no freshness assertion; a balance query during or after the external interaction |
| Lending / money market | First-depositor / empty-market exchange-rate rounding; flash-borrow-driven oracle shift within one tx; governance-mutable collateral factor assumed constant | receipt-token interaction at low total supply; an oracle read after interacting with the dependency; a hardcoded LTV / collateral factor |
| Oracle / price feed | Stale price (publisher or L2-sequencer downtime) consumed without a max-staleness check; confidence / exponent field ignored; feed or aggregator address assumed permanent | a price read with no freshness/staleness bound; use of the price without checking its confidence/exponent; a hardcoded feed address |
| Bridge / cross-chain messenger | Delivered value in a different FORM than the handler assumes (native vs wrapped auto-(un)wrap); message/return arity or ABI differing from the vendored interface; zero- or underfunded-gas send that "succeeds" without delivery | the inbound native↔wrapped conversion is present and the first value-moving op's form matches the delivered form; the real deployed message signature vs the vendored trait; the messenger's zero-gas success semantics |
| Staking / rebasing token | Balance changing between blocks with no transfer (rebase) used as an accounting input; share↔underlying conversion rate assumed constant | a balanceOf used as accounting that can rebase; a hardcoded or cached conversion rate |
| Delayed-claim / epoch ticket | State claimable only after an epoch/time boundary read as if immediately available | ticket/order state reads across an epoch or time boundary |
| Concentrated-liquidity / order-book DEX | Tick-density gas-exhaustion DoS on swap; permissionless cancellation of an order a third party can race | swap calls into narrow-tick pools; reading order/position state a third party can cancel or mutate |
Note: This floor lists generic hazard CLASSES by dependency type only — it is minimum coverage, not exhaustive, and NOT a substitute for the live-researched ledger (0a). Real research typically surfaces several more hazards specific to the actual dependency.
Write the hazard catalog to {SCRATCHPAD}/integration_hazard_catalog.md. This file is consumed by:
For each YES/CHECK hazard in the catalog, ask:
Permissionless function race: Does the target protocol expose permissionless functions that modify state the audited code depends on? Can a third party call that function between the audited code's transactions?
| Target Function | Permissionless? | State Modified | Our Code Reads This State? | Race Window |
|---|---|---|---|---|
| {function} | YES/NO | {state var} | {where our code reads it} | {blocks/time} |
For each race with Permissionless=YES AND Our Code Reads=YES:
Tag: [TRACE:third_party_call({target_function}) → our_read({our_function}) → state_is={stale/zeroed/modified} → impact={loss/revert/incorrect_accounting}]
For each external state the audited code reads:
| State Read | Read Location | Used At | Time Between Read and Use | Can State Change In Window? |
|---|---|---|---|---|
| {value} | {our function:line} | {downstream use:line} | {same tx / cross-tx / cross-block} | YES/NO |
For each Can Change=YES:
Tag: [VARIATION:external_state({value}) fresh_at_read=X → stale_at_use=Y → delta={amount} → impact={consequence}]
Coverage assertion: Before returning, verify every entity enumerated under each section has been processed. Report enumerated vs analyzed counts in your return message.
| Section | Required | Completed? | Notes |
|---|---|---|---|
0a. Ledger read (external_dependency_research.md) per target dependency | YES — no MCP calls | Y/N/? | |
0b. NEEDS_DEPENDENCY_RESEARCH emitted for every ledger-uncovered surface | YES for each uncovered surface | Y/N/? | |
| 0c. Hazard catalog compiled | YES | Y/N/? | |
| 0d. Floor catalog checked (TERTIARY — ledger-miss AND 0b escalation only) | IF 0a had no row AND 0b escalated | Y/N/? | |
| 0e. integration_hazard_catalog.md written | YES | Y/N/? | |
| 1. Third-party race conditions | FOR EACH YES/CHECK hazard | Y/N/? | |
| 2. Integration state TOCTOU | FOR EACH external state read | Y/N/? |
© PlamenTSV, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in agents/skills/injectable/integration-hazard-research of PlamenTSV/plamen.
Open the folder on GitHubat commit 795962b
Integration Hazard Research next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Integration Hazard Research this skillPlamenTSV/plamen | 303 | — | ~3.7k | Automated safety check: Pass | MIT | |
| Fla Ascend Performancefla-org/flash-linear-attention | 5.8k | — | ~6.3k | Automated safety check: Pass | MIT | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit | 481 | 1 repos | ~3.3k | Automated safety check: Pass | None | |
| Security Alert Triageelastic/agent-skills | 592 | 1 repos | ~3.5k | Automated safety check: Notes | Apache-2.0 |
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
yan-labs/serenity-aleabitoreddit
Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
SummerSec/ShiroAttack2
当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…
PlamenTSV/plamen
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
PlamenTSV/plamen
Trigger Pattern Always (used by all verifier agents) - Inject Into security-verifier agents (Phase 5)
PlamenTSV/plamen
Trigger Pattern Always (Aptos Move) - foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always (Sui Move) -- foundational security check - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern ACCOUNTCLOSING flag detected (close/CloseAccount usage) - Inject Into Breadth agents, depth agents
PlamenTSV/plamen
Trigger Pattern Always required for Solana audits - Inject Into Breadth agents, depth agents
Categories
Protocol Type Trigger NAMEDEXTERNALPROTOCOL (detected when recon finds import/interface for an identifiable external protocol — not standard libraries). Integration Hazard Research is an agent skill from PlamenTSV/plamen. Protocol Type Trigger NAMEDEXTERNALPROTOCOL (detected when recon finds import/interface for an identifiable external protocol — not standard libraries).
Integration Hazard Research fits situations like: NAMEDEXTERNALPROTOCOL (detected when recon finds import/interface for an identifiable external protocol — not standard libraries).
Run `npx skills add PlamenTSV/plamen --skill integration-hazard-research -a claude-code`. Or copy the skill folder (agents/skills/injectable/integration-hazard-research in PlamenTSV/plamen) into .claude/skills/integration-hazard-research in your project. Claude Code loads it when a task matches its description.
Run `npx skills add PlamenTSV/plamen --skill integration-hazard-research -a codex`. Or copy the skill folder (agents/skills/injectable/integration-hazard-research in PlamenTSV/plamen) into .agents/skills/integration-hazard-research in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PlamenTSV/plamen --skill integration-hazard-research -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/integration-hazard-research, .gemini/skills/integration-hazard-research, .github/skills/integration-hazard-research and .opencode/skills/integration-hazard-research in your project.
SKILL.md names no scripts, command-line tools or credentials: Integration Hazard Research is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Integration Hazard Research is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Integration Hazard Research: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
PlamenTSV (a GitHub user) maintains it in PlamenTSV/plamen, which has 303 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on September 26, 2026.
Source: PlamenTSV/plamen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.