Agent skill

Skeptic

by RaoFoundation in RaoFoundation/subtensor

Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

Apache-2.0Auto-check passedSecurity

Install Skeptic

skills CLI
$ npx skills add RaoFoundation/subtensor --skill skeptic -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install RaoFoundation/subtensor skeptic --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/RaoFoundation/subtensor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/skeptic .claude/skills/skeptic && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skeptic
GitHub stars
391
Token cost
~660 tokens
SKILL.md length
297 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

  • Works in 3 steps: Determine the diff → Run the persona → Output
  • The user wants to security-review a branch before pushing
  • SKILL.md covers Step 1 — Determine the diff, Step 2 — Run the persona and Step 3 — Output
  • Calls git and gh

What it does

Skeptic is an agent skill from RaoFoundation/subtensor. Run the security-focused Skeptic persona on the local working tree's diff against a base branch. Static analysis only — does not build, test, or execute anything from the diff. Outputs a verdict comment and a suggested-changes patch file. Use when the user wants to security-review a branch before pushing.

Its SKILL.md is about 660 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review and Static analysis and SAST. It works with Rust, Git and GitHub. The licence is Apache-2.0.

When your agent uses it

  • The user wants to security-review a branch before pushing
  • Tasks that involve Security review
  • Tasks that involve Static analysis and SAST

Example prompts

  • “/skeptic”

Requirements

  • Docker

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Determine the diff
  2. Run the persona
  3. Output

What it can do on your machine

Read from SKILL.md and the folder at commit 5c6e83e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skeptic loads about 660 tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 297 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~660

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from RaoFoundation/subtensor at commit 5c6e83e, republished under its Apache-2.0 licence (© RaoFoundation). 297 words, ~660 tokens.

Download SKILL.mdSave it as .claude/skills/skeptic/SKILL.md (or your agent's skills folder).
name
skeptic
description
Run the security-focused Skeptic persona on the local working tree's diff against a base branch. Static analysis only — does not build, test, or execute anything from the diff. Outputs a verdict comment and a suggested-changes patch file. Use when the user wants to security-review a branch before pushing.

Skeptic — local mode

You are running the Skeptic persona locally against the user's working tree. There is no PR yet (or the PR exists but the user wants a fast iteration before pushing). Your output goes to the terminal, not GitHub.

Step 1 — Determine the diff

Detect the base branch in this order:

  1. If gh pr view --json baseRefName succeeds in the current branch's PR, use that.
  2. Else, default to devnet (the policy base for new PRs).
  3. Allow override: if the user invoked the skill with an argument like /skeptic main, use that.

Compute the diff:

bash
git fetch origin "$BASE" --quiet
git diff --merge-base "origin/$BASE"...HEAD

If the diff is empty, report "No changes vs $BASE" and exit.

Step 2 — Run the persona

Load and follow the instructions in:

  • .github/ai-review/common.md
  • .github/ai-review/skeptic.md

Constraints inherited from the persona file:

  • Do NOT run cargo, npm, make, docker, or any build/test command. Read-only analysis only.
  • You may use gh, git log, git show, git diff, grep, rg, and read files.

For the contributor signal step, if gh pr view reveals an existing PR, query the author's history. Otherwise (no PR yet), use the local commit author identity from git log --format='%an <%ae>' and skip the GitHub-API queries — note in the output that the contributor-signal check was limited because no PR exists yet.

Step 3 — Output

Print to stdout in the same format the persona file specifies, but adapted for terminal:

============================================================
  SKEPTIC VERDICT: [SAFE | VULNERABLE | MALICIOUS]
============================================================

Contributor scrutiny: <tier>
Branch: <head> -> <base>

Findings:
  [SEVERITY] Title
    file:line — description

Conclusion: <one sentence>

If you have suggested changes (suggestion-block content from the persona output), additionally write them to .skeptic-suggestions.patch in unified diff format that the user can apply with git apply .skeptic-suggestions.patch. Print the patch path at the end of your output. If no suggestions, do not create the file.

Do NOT post anything to GitHub. Do NOT modify any files in the working tree (other than writing the suggestions patch).

© RaoFoundation, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/skeptic of RaoFoundation/subtensor.

Open the folder on GitHubat commit 5c6e83e

Compare with similar skills

Skeptic next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skeptic compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skeptic this skillRaoFoundation/subtensor391—~660Automated safety check: PassApache-2.0
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence
Trailmark Graph Evolutiontrailofbits/skills7.5k—~3.4kAutomated safety check: PassCC-BY-SA-4.0
Kedro Plugins Security Reviewkedro-org/kedro-plugins119—~3.1kAutomated safety check: PassApache-2.0
Agentic GitHub Actions Auditortrailofbits/skills7.5k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated 3 days ago
    SecurityAuto-check: notes
  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.5k GitHub stars~3.4k tokensUpdated today
    SecurityAuto-check passed
  • Kedro Plugins Security Review

    kedro-org/kedro-plugins

    Run a security scan on the kedro-plugins codebase or a pull request.

    119 GitHub stars~3.1k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.5k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • Security Setup

    luongnv89/skills

    Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.

    131 GitHub stars~4.5k tokensUpdated yesterday
    SecurityAuto-check passed

More from RaoFoundation/subtensor

  • Auditor

    RaoFoundation/subtensor

    Run the domain-focused Auditor persona on the local working tree's diff against a base branch.

    391 GitHub stars~813 tokensUpdated today
    Auto-check passed
  • Evm Maintainer

    RaoFoundation/subtensor

    Maintain backwards-compatible, versioned EVM precompiles that expose runtime extrinsics, state, constants, and APIs to Solidity.

    391 GitHub stars~2.5k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Skeptic

What does Skeptic do?

Run the security-focused Skeptic persona on the local working tree's diff against a base branch. Skeptic is an agent skill from RaoFoundation/subtensor. Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

When should I use Skeptic?

Skeptic fits situations like: the user wants to security-review a branch before pushing; tasks that involve Security review; tasks that involve Static analysis and SAST.

How do I install Skeptic in Claude Code?

Run `npx skills add RaoFoundation/subtensor --skill skeptic -a claude-code`. Or copy the skill folder (.agents/skills/skeptic in RaoFoundation/subtensor) into .claude/skills/skeptic in your project. Claude Code loads it when a task matches its description.

How do I install Skeptic in Codex?

Run `npx skills add RaoFoundation/subtensor --skill skeptic -a codex`. Or copy the skill folder (.agents/skills/skeptic in RaoFoundation/subtensor) into .agents/skills/skeptic in your project. Codex loads it when a task matches its description.

Can I use Skeptic in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add RaoFoundation/subtensor --skill skeptic -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skeptic, .gemini/skills/skeptic, .github/skills/skeptic and .opencode/skills/skeptic in your project.

What does Skeptic need to run?

Going by SKILL.md and its folder, Skeptic needs the command-line tools its instructions call (git and gh). Our summary lists: Docker.

Does Skeptic access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Skeptic safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Skeptic use?

Skeptic is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skeptic use?

About 660 tokens (SKILL.md is roughly 2.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Skeptic?

Skills that share tags, products or a category with Skeptic: Pyspector Security Audit (ParzivalHack/PySpector, 151 stars), Kedro Security Review (kedro-org/kedro, 11k stars), Trailmark Graph Evolution (trailofbits/skills, 7.5k stars) and Kedro Plugins Security Review (kedro-org/kedro-plugins, 119 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skeptic?

RaoFoundation (a GitHub organization) maintains it in RaoFoundation/subtensor, which has 391 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 10, 2026.

Source: RaoFoundation/subtensor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.