LLM Wiki
lewislulu/llm-wiki-skill
Build and maintain a Karpathy-style LLM knowledge base — a self-compiling Obsidian markdown wiki where an Agent ingests raw sources, compiles cross-linked concept/entity/summary pages, answers…
Weekly review of an investigation tenant-context memory file against the most recent SOC scan reports (e.g.
$ npx skills add SCStelz/security-investigator --skill context-memory-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install SCStelz/security-investigator context-memory-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/context-memory-review .claude/skills/context-memory-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "context-memory-review" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/context-memory-review into .claude/skills/context-memory-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "context-memory-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/SCStelz/security-investigator/tree/main/.github/skills/context-memory-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add SCStelz/security-investigator --skill context-memory-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install SCStelz/security-investigator context-memory-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/context-memory-review .agents/skills/context-memory-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "context-memory-review" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/context-memory-review into .agents/skills/context-memory-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "context-memory-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SCStelz/security-investigator --skill context-memory-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install SCStelz/security-investigator context-memory-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/context-memory-review .cursor/skills/context-memory-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "context-memory-review" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/context-memory-review into .cursor/skills/context-memory-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "context-memory-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/SCStelz/security-investigator.git --path .github/skills/context-memory-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add SCStelz/security-investigator --skill context-memory-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install SCStelz/security-investigator context-memory-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/context-memory-review .gemini/skills/context-memory-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "context-memory-review" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/context-memory-review into .gemini/skills/context-memory-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "context-memory-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install SCStelz/security-investigator context-memory-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add SCStelz/security-investigator --skill context-memory-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/context-memory-review .github/skills/context-memory-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "context-memory-review" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/context-memory-review into .github/skills/context-memory-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "context-memory-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SCStelz/security-investigator --skill context-memory-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install SCStelz/security-investigator context-memory-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SCStelz/security-investigator.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/context-memory-review .opencode/skills/context-memory-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "context-memory-review" agent skill from https://github.com/SCStelz/security-investigator/tree/main/.github/skills/context-memory-review into .opencode/skills/context-memory-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "context-memory-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
context-memory-reviewWeekly review of an investigation tenant-context memory file against the most recent SOC scan reports (e.g.
Context Memory Review is an agent skill from SCStelz/security-investigator. Weekly review of an investigation tenant-context memory file against the most recent SOC scan reports (e.g. Threat Pulse) and the Mission Control findings log. Surfaces candidate ADD / MODIFY / FLAG changes to the context file as a propose-only review document for human approval — it NEVER edits the context file, commits, or opens a PR. Trigger on 'review my context file', 'review tenant context', 'propose context updates', 'compact findings to memory', 'what should I add to my context memory'.
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Knowledge Management, covering Journaling and reflection. The repository describes itself as: Automated security investigation tool using Microsoft MCP Servers, GitHub Copilot, Python Modules and custom copilot-instructions. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 51e1385. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context Memory Review loads about 3.7k tokens when it runs. Until then it costs about 130 tokens; SKILL.md has 1,651 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from SCStelz/security-investigator at commit 51e1385, republished under its MIT licence (© SCStelz). 1,651 words, ~3,705 tokens.
.claude/skills/context-memory-review/SKILL.md (or your agent's skills folder).Investigation workflows in this project lean on a tenant-context memory file — a local, gitignored living document that records environment-specific ground truth (known automation/orchestration fingerprints, known-good IPs, account classifications, honeypot/field-device inventory, validated personnel, and documented false-positive rules). Scan automations (e.g. the daily Threat Pulse) read that file to render accurate verdicts.
Over a week of scans, drill-down investigations validate new ground truth — new IPs, new personas,
new FP classes, new device classes — that is not yet captured in the context file. This skill reads two
evidence sources — the last N days of scan reports and the Mission Control findings log
(state/findings.json, the structured record of analyst-triggered skill drill-downs) — compares them
against the current context file, and produces a propose-only review document: a list of discrete,
human-reviewable candidate changes (ADD / MODIFY / FLAG) with section anchors, proposed text, supporting
evidence, recurrence counts, and confidence.
Memory file location. In this project the context file is a relative filename under
.copilot/memories/repo/(Copilot's own repo-memory folder, gitignored). The invoking prompt may pass just the basename; resolve it under that folder. The file is environment-specific and never committed.
This skill is the first half of a deliberate two-phase, human-in-the-loop workflow:
| Phase | Who | Action |
|---|---|---|
| 1. Propose (this skill) | Automation / interactive | Read reports + context file → emit review doc. No edits. |
| 2. Apply (separate, manual) | Human-directed interactive session | Operator reviews the doc, says "apply items X, Y, Z" → surgical edits to the context file. |
PROPOSE-ONLY. NEVER edit the context file in this skill. Do not write, append to, or modify the
context memory file. Do not git commit, push, or open a PR. The only file this skill writes is the
review document in the output directory.
Read-only against the tenant. If any live queries are needed to corroborate a candidate change, they MUST be read-only (per the Remediation Output Policy). Prefer evidence already present in the reports — only query the tenant to disambiguate a contradiction.
⛔ Feedback-loop guard (the single most important rule). Scan reports are partly downstream of the context file: a scan verdict may simply echo an existing context entry rather than independently confirm it. You MUST distinguish:
Never propose weakening or removing a documented FP/safety guardrail based solely on its absence from the week's reports. Absence of a finding ≠ obsolescence of a guardrail. Staleness candidates are FLAG-only, Low confidence, for human judgment — never auto-REMOVE.
Evidence-based only. Every proposed change cites the specific report file(s), date(s), and finding it derives from. Never invent entities, counts, IPs, UPNs, or dates. If the reports don't support a change, don't propose it.
PII stays local. The review document will contain live tenant entities (IPs, UPNs, device names). Write it ONLY to the gitignored output directory. Never commit it, never include it in a PR, never paste tenant PII into any git artifact.
The invoking workflow or user supplies these. If invoked interactively without them, ask once, then proceed with the defaults shown.
| Input | Meaning | Default |
|---|---|---|
context_file | Relative filename (under .copilot/memories/repo/) or absolute path to the tenant-context memory file to review | (must be provided) |
reports_dir | Directory (or glob) holding the scan reports to review | reports/ |
reports_glob | Filename pattern for the reports of interest | *.md |
findings_file | Mission Control findings log (structured analyst drill-down records) | .mission-control/findings.json |
lookback_days | How far back to include reports (by filename date or mtime) | 7 |
output_dir | Where to write the review document (must be gitignored) | reports/context-reviews |
At least one of
reports_dirorfindings_filemust yield evidence. When launched from Mission Control's Compact to memory button,findings_fileis the primary source and reports are supplementary.
context_file). Build an internal index of its structure: every
section heading (the anchor targets for proposals), and within sections the discrete entries — table
rows (e.g. IP tables), bullet points, labelled sub-notes (e.g. "A.2", "Section C"), device entries.
Note any validated YYYY-MM-DD provenance stamps.reports_dir matching reports_glob, select those
whose date (from filename YYYYMMDD if present, else file mtime) falls within lookback_days. Sort
oldest→newest. If zero reports are in window and the findings log is empty, STOP and report
"no reports or findings in window — nothing to review" (a normal quiet-week outcome, not a failure).findings_file, JSON). Each finding is a structured record
the analyst produced by triggering a skill drill-down from the canvas — treat these as first-party
validation (they are the product of an actual investigation, not a scan echo). For each finding
extract: title, description, severity, the originating skill, any entity/IP/UPN referenced in
the text, and the timestamp. Findings whose evidence duplicates a scan report are the same first-party
signal — correlate, don't double-count. A finding that merely restates an existing context entry with
no new evidence is still an echo (feedback-loop guard applies equally here).Aggregate signal across all in-window reports:
validated date if a first-party drill-down re-confirmed
it — and that is a Low/Medium MODIFY, clearly labelled "provenance refresh only".Assign each candidate a type and confidence:
| Type | When |
|---|---|
| ADD | New, first-party-validated fact absent from the context file. |
| MODIFY | Existing entry that a first-party drill-down refined/expanded, or a provenance-refresh. |
| FLAG | A contradiction needing human judgment, or a staleness candidate. Never an auto-edit. |
| Confidence | Criteria |
|---|---|
| High | First-party validated AND recurred on ≥3 report-days (or a single explicit, thorough validated drill-down with enrichment/queries). Consistent classification, no contradicting evidence. |
| Medium | First-party validated on 2 report-days, OR 1 strong drill-down without recurrence. |
| Low | Single weak signal, provenance-refresh only, or any FLAG/staleness candidate. |
For every proposal, produce:
P1, P2, …).(validated <today's date>) stamp where the file uses that convention.Write the document to output_dir (create the folder if needed) as:
<output_dir>/context-review_<YYYYMMDD>_<HHMMSS>.md
Use this structure:
# Context Memory Review — <today's date>
**Context file reviewed:** <context_file>
**Evidence reviewed:** <N> report(s) over <lookback_days>d (<earliest> → <latest>) + <K> Mission Control finding(s)
**Proposed changes:** <A> ADD · <M> MODIFY · <F> FLAG
**Confidence mix:** <High count> High · <Medium count> Medium · <Low count> Low
> ⚠️ PROPOSE-ONLY. No changes have been made to the context file. To apply, open an interactive
> session and say e.g. "apply items P1, P3, P7" — those edits will be made surgically with a
> validated-date stamp. Review each item's evidence before approving.
## Evidence in this review window
| Source | Date | Ref | First-party? |
|--------|------|-----|--------------|
| report | ... | <file> | yes / echo |
| finding | ... | <title / skill> | yes / echo |
## Proposed changes
### P1 — [ADD · High] <short title>
- **Target section:** <heading/anchor>
- **Proposed text:**
> <literal text to add, in file style, with (validated <date>)>
- **Rationale:** ...
- **Evidence:** <report file(s) + date(s) + finding>; first-party drill-down.
- **Recurrence:** appeared on N of M report-days.
- **Apply instruction:** Insert under "<section>" after "<anchor line>".
### P2 — [MODIFY · Medium] ...
...
### P3 — [FLAG · Low] <contradiction or staleness> ...
- **Question for human:** ...
## Items considered but NOT proposed (feedback-loop guard)
Brief list of candidate signals that were only context-echoes (already in the file, no new first-party
evidence) and were therefore intentionally dropped — so the reviewer can confirm nothing was missed.
## Summary
One paragraph: the week's theme, the highest-value proposed addition, any contradiction needing
attention, and the count of staleness flags.End your response with a concise summary: context file + report window reviewed, counts of ADD/MODIFY/FLAG by confidence, the single highest-value proposed change, any contradictions surfaced, the output document path, and a reminder that nothing was applied and how to apply (interactive "apply items …").
Before finishing, verify:
© SCStelz, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/context-memory-review of SCStelz/security-investigator.
Open the folder on GitHubat commit 51e1385
Context Memory Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Context Memory Review this skillSCStelz/security-investigator | 250 | — | ~3.7k | Automated safety check: Pass | MIT | |
| LLM Wikilewislulu/llm-wiki-skill | 655 | — | ~3.7k | Automated safety check: Pass | None | |
| Munger Perspectivealchaincyf/munger-skill | 379 | 1 repos | ~3.7k | Automated safety check: Pass | MIT | |
| Daily Journalhuytieu/COG-second-brain | 1.3k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Letterboxd Diaryjoe-bell/skills | 211 | — | ~4.2k | Automated safety check: Pass | MIT | |
| Em Grid Scorermanager-dot-dev/manager-skills | 114 | — | ~5.8k | Automated safety check: Pass | MIT |
lewislulu/llm-wiki-skill
Build and maintain a Karpathy-style LLM knowledge base — a self-compiling Obsidian markdown wiki where an Agent ingests raw sources, compiles cross-linked concept/entity/summary pages, answers…
alchaincyf/munger-skill
查理·芒格的思维框架与表达方式。基于《穷查理宝典》、伯克希尔/Daily Journal股东会、 USC/哈佛演讲、访谈记录、外部批评等50+来源的深度调研, 提炼5个核心心智模型、8条决策启发式和完整的表达DNA。
huytieu/COG-second-brain
A passive daily work journal that Claude keeps FOR you so you never have to write it yourself.
joe-bell/skills
Fetch recently watched films from a Letterboxd member's diary RSS feed and render them as a compact markdown list, with first-run setup for the username.
manager-dot-dev/manager-skills
Score an Engineering Manager's coverage across all 12 cells of the EM Grid based on their calendar and Slack.
foryourhealth111-pixel/Vibe-Skills
This skill should be used when the user asks to "write a post", "check my voice", "look up contact", "prepare for meeting", "weekly review", "track goals", or mentions personal brand, content…
SCStelz/security-investigator
A skill your agent uses when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy…
SCStelz/security-investigator
A skill your agent uses when asked to create heatmaps, visualize patterns over time, show activity grids, or display aggregated data in a matrix format.
SCStelz/security-investigator
Report/investigate RUNTIME ACTIVITY of AI agents (Agent 365 / Copilot Studio / M365 Copilot / Work IQ) — agents used, tools/connectors, channels, tokens, prompt/reply content, and Prompt Shield…
SCStelz/security-investigator
Audit or report on AI agent security posture across Copilot Studio, Microsoft 365 Copilot, Microsoft Foundry, and third-party agents.
SCStelz/security-investigator
Audit Entra ID app registration and service principal security posture.
SCStelz/security-investigator
A skill your agent uses when asked to trace authentication flows, analyze SessionId chains, investigate token reuse vs interactive MFA, or assess geographic anomalies in sign-ins.
Categories
Weekly review of an investigation tenant-context memory file against the most recent SOC scan reports (e.g. Context Memory Review is an agent skill from SCStelz/security-investigator.g.
Context Memory Review fits situations like: review my context file; review tenant context; propose context updates; compact findings to memory.
Run `npx skills add SCStelz/security-investigator --skill context-memory-review -a claude-code`. Or copy the skill folder (.github/skills/context-memory-review in SCStelz/security-investigator) into .claude/skills/context-memory-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add SCStelz/security-investigator --skill context-memory-review -a codex`. Or copy the skill folder (.github/skills/context-memory-review in SCStelz/security-investigator) into .agents/skills/context-memory-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SCStelz/security-investigator --skill context-memory-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/context-memory-review, .gemini/skills/context-memory-review, .github/skills/context-memory-review and .opencode/skills/context-memory-review in your project.
Going by SKILL.md and its folder, Context Memory Review needs the command-line tools its instructions call (git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Context Memory Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Context Memory Review: LLM Wiki (lewislulu/llm-wiki-skill, 655 stars), Munger Perspective (alchaincyf/munger-skill, 379 stars), Daily Journal (huytieu/COG-second-brain, 1.3k stars) and Letterboxd Diary (joe-bell/skills, 211 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
SCStelz (a GitHub user) maintains it in SCStelz/security-investigator, which has 250 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 8, 2026.
Source: SCStelz/security-investigator on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.