Agent skill

Bumblebee

by sickn33 in sickn33/agentic-awesome-skills

Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs.

MITAuto-check: notesSecurity

Install Bumblebee

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill bumblebee -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills bumblebee --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/bumblebee .claude/skills/bumblebee && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bumblebee
GitHub stars
47k
Used in
1 other repo
Token cost
~2.5k tokens
SKILL.md length
1,203 words
Files
2 (incl. scripts)
Skills in repo
1,354
Repo updated
First seen
Licence
MIT

At a glance

Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs.

  • Works in 6 steps: Clarify the scan request → Check Go → Check or install Bumblebee → …
  • Tasks that involve Supply chain security
  • SKILL.md covers When to Use This Skill, Step 1 — Clarify the scan…, Step 2 — Check Go and Step 3 — Check or install…, plus 8 more sections
  • Runs Python scripts from its folder; calls go, python3 and brew

What it does

Bumblebee is an agent skill from sickn33/agentic-awesome-skills. Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/render_report.py`).

It sits in Security, covering Supply chain security. It works with Model Context Protocol, Linux and macOS. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve Supply chain security

Example prompts

  • “/bumblebee”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Clarify the scan request
  2. Check Go
  3. Check or install Bumblebee
  4. Run the scan
  5. Generate the Markdown report
  6. Present results

What it can do on your machine

Read from SKILL.md and the folder at commit ec02547. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • go
    • python3
    • brew
    • apt
    • dnf
    • pip
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • go.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bumblebee loads about 2.5k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 1,203 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:59
    ://go.dev/dl/ because distro repos lag; `sudo apt install golang-go` only as fallback.
  • NoteRuns commands with sudoSKILL.md:60
    - Fedora/RHEL: `sudo dnf install golang` or the official tarball.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit ec02547, republished under its MIT licence (© sickn33). 1,203 words, ~2,463 tokens.

Download SKILL.mdSave it as .claude/skills/bumblebee/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
bumblebee
description
Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs.
category
security
risk
safe
source
community
source_repo
mycelos-ai/bumblebee-skill
source_type
community
date_added
2026-05-27
author
stefan-kp
tags
security, supply-chain, incident-response, npm, pypi, tooling
tools
claude
license
MIT

Bumblebee Security Scan

Bumblebee (https://github.com/perplexityai/bumblebee) is a read-only inventory collector that surfaces package, extension, and developer-tool metadata on developer endpoints. It answers a focused supply-chain question: when an advisory names a package or version, do any matches exist on this machine right now?

This skill drives a single Bumblebee scan from start to finish:

  1. Verify Go is on the PATH (provide install guidance if not).
  2. Verify or install the bumblebee binary.
  3. Run the requested scan profile (baseline, project, or deep).
  4. Save raw NDJSON output plus a Markdown report into the user's workspace.
  5. Summarize findings — especially exposure-catalog matches — in the chat reply.

Communicate with the user in the language they used (German for Stefan). Code, commit messages, and on-disk file contents stay in English to match existing project conventions.

When to Use This Skill

Use this skill when an advisory, incident report, or exposure catalog names compromised packages, developer tools, browser/editor extensions, or MCP host configuration that may exist on a local macOS or Linux developer endpoint.

Use it for read-only inventory and exposure checks. Do not use it to patch, uninstall, quarantine, or otherwise mutate the scanned machine.

Step 1 — Clarify the scan request

Before running anything, confirm two things with the user via AskUserQuestion, unless the message already pins them down:

  • Profile: baseline (global package roots), project (specific dev folders like ~/code), or deep (explicit --root paths, including $HOME for incident response).
  • Roots: For project and deep profiles, ask which directories to scan. deep is the only profile that accepts a bare-home root.

If the user has an advisory or exposure-catalog file ready, also ask whether they want to pass it via --exposure-catalog. The skill does not ship its own catalogs — point them at threat_intel/ in the Bumblebee repo if they ask where to find ready-made ones.

Skip the questions for one-liner asks like "lauf mal ne Baseline-Scan" — just run a baseline.

Step 2 — Check Go

Run command -v go && go version in bash. Three outcomes:

  • Go ≥ 1.25 present → continue.
  • Go present but < 1.25 → tell the user the version, explain Bumblebee needs Go 1.25+, and stop until they upgrade.
  • Go missing → do not install Go automatically. Show platform-appropriate instructions and stop:
    • macOS: brew install go (or download from https://go.dev/dl/).
    • Debian/Ubuntu: prefer the official tarball from https://go.dev/dl/ because distro repos lag; sudo apt install golang-go only as fallback.
    • Fedora/RHEL: sudo dnf install golang or the official tarball.

After installation, the user must ensure $GOBIN (or $HOME/go/bin) is on $PATH so bumblebee is found later.

Step 3 — Check or install Bumblebee

Run command -v bumblebee && bumblebee version. If missing:

bash
go install github.com/perplexityai/bumblebee/cmd/bumblebee@latest

Then re-check bumblebee version. If the binary still cannot be located, the user's GOBIN/PATH is likely misconfigured — surface the resolved go env GOPATH and go env GOBIN so they can fix it. Do not fall back to running the binary by absolute path silently; explain what is happening.

Once installed, also run bumblebee selftest as a sanity check. A non-zero exit means the local install is broken and the scan should not proceed.

Step 4 — Run the scan

All scans write NDJSON to a file. Use the workspace folder for output so the user can open the results afterwards.

Output filenames (use the user's workspace path; the example below assumes $OUT is set):

  • bumblebee-<profile>-<UTC-timestamp>.ndjson — raw records.
  • bumblebee-<profile>-<UTC-timestamp>.report.md — Markdown report (generated in Step 5).

Pick a sensible --max-duration so a runaway scan does not hang the session. Reasonable defaults:

  • baseline: 5m
  • project: 10m
  • deep: 15m (warn the user that scanning $HOME can still take longer; offer to raise the limit)

Always stream stderr to a sibling .log file — Bumblebee emits diagnostic NDJSON there that helps explain partial scans.

Baseline
bash
bumblebee scan --profile baseline \
  --max-duration 5m \
  > "$OUT/bumblebee-baseline-$TS.ndjson" \
  2> "$OUT/bumblebee-baseline-$TS.log"

Optional: scope to specific ecosystems if the user only cares about, say, npm and PyPI:

bash
bumblebee scan --profile baseline --ecosystem npm,pypi ...
Project

Each --root must be an existing absolute path. Reject bare $HOME for this profile (Bumblebee will reject it too — surface the message clearly).

bash
bumblebee scan --profile project \
  --root "$HOME/code" \
  --root "$HOME/Developer" \
  --max-duration 10m \
  > "$OUT/bumblebee-project-$TS.ndjson" \
  2> "$OUT/bumblebee-project-$TS.log"
Deep

Used for incident response — broad roots are allowed but should be paired with an exposure catalog and --findings-only whenever possible, so the output stays focused.

bash
bumblebee scan --profile deep \
  --root "$HOME" \
  --exposure-catalog "$CATALOG" \
  --findings-only \
  --max-duration 15m \
  > "$OUT/bumblebee-deep-$TS.ndjson" \
  2> "$OUT/bumblebee-deep-$TS.log"

If the user has no catalog, run deep without --findings-only but warn them that the NDJSON file can grow large (hundreds of MB on dense developer machines).

Show full SKILL.md (500 more words)Show less

Step 5 — Generate the Markdown report

Run the bundled helper to turn the NDJSON into a human-readable report. Resolve the helper from the installed Bumblebee skill directory; never run a workspace-relative scripts/render_report.py from the scanned project.

bash
BUMBLEBEE_SKILL_DIR="/absolute/path/to/the/bumblebee-skill-directory"
test -f "$BUMBLEBEE_SKILL_DIR/scripts/render_report.py"
python3 "$BUMBLEBEE_SKILL_DIR/scripts/render_report.py" \
  "$OUT/bumblebee-<profile>-$TS.ndjson" \
  "$OUT/bumblebee-<profile>-$TS.report.md"

The helper groups records by type and ecosystem, lists every finding record with its catalog entry and severity, and embeds the scan_summary for traceability. It is dependency-free Python 3 — no pip install needed.

If render_report.py exits non-zero (malformed NDJSON, missing summary), surface stderr to the user instead of silently producing an empty report.

Step 6 — Present results

End the turn with:

  • A short summary in chat: profile, root(s), record counts, and — most importantly — any findings with their severity. If there are zero findings, say so explicitly; silence on findings is the kind of thing that gets misread.
  • computer:// links to both the NDJSON and the Markdown report so the user can open them directly.
  • If diagnostics in the .log file indicate skipped roots or read errors, mention it and link the log too.

Do not paste large chunks of NDJSON into the chat — it is noisy and not where the user will read it.

Safety and privacy notes

  • Bumblebee is read-only by design. Do not propose patches, deletions, or npm uninstall actions from inside this skill; the user runs remediation themselves once they know what is affected.
  • MCP host configs can carry secrets in their env blocks. Bumblebee does not emit those values, but the .log file may still contain paths to sensitive config files. Treat the output files as containing inventory data and do not upload them to third-party services without the user's explicit consent (DSGVO-relevant).
  • Never run bumblebee with elevated privileges (sudo). It is meant to inspect the current user's developer environment, not the whole system.

Failure modes to watch for

  • bumblebee: command not found after go install → almost always a PATH/GOBIN problem. Show go env GOPATH GOBIN PATH to debug.
  • refusing to scan bare home with profile baseline → use deep for $HOME, or pick a subdirectory for project.
  • Scan times out → either narrow the --root set, scope with --ecosystem, or raise --max-duration. Do not loop and retry blindly.
  • Exposure catalog rejected → check that the JSON has both schema_version and entries keys (bare top-level arrays are rejected) and that schema_version is one Bumblebee understands.

Limitations

  • This skill only reports local inventory and exposure matches; it does not remediate affected packages, extensions, or configs.
  • Scan coverage depends on Bumblebee's supported ecosystems, the selected roots, and the current user's filesystem permissions.
  • Results are point-in-time evidence and should be re-run after package installs, dependency updates, or incident-response changes.

Reference

See scripts/render_report.py for the report layout. Bumblebee's own documentation lives at https://github.com/perplexityai/bumblebee — consult docs/inventory-sources.md, docs/transport.md, and docs/state-model.md when a question goes beyond what this skill covers.

Credit

Bumblebee is developed by Perplexity (https://github.com/perplexityai/bumblebee, Apache-2.0). All scan logic, output formats, and exposure-catalog semantics belong to that project. This repository is just a thin Claude-skill wrapper around the official bumblebee CLI; the wrapper itself is MIT-licensed (see LICENSE).

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in skills/bumblebee of sickn33/agentic-awesome-skills.

  • SKILL.md
  • scripts/render_report.py

Open the folder on GitHubat commit ec02547

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Bumblebee next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bumblebee compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bumblebee this skillsickn33/agentic-awesome-skills47k1 repos~2.5kAutomated safety check: NotesMIT
Open Computer UseiFurySt/open-codex-computer-use2.4k—~1.5kAutomated safety check: PassMIT
Gearcoleco Debuggingdrhelius/Gearcoleco141—~3.5kAutomated safety check: PassGPL-3.0
Cortex Mem MCPsopaco/cortex-mem312—~2.8kAutomated safety check: PassMIT
Browser MCP Agentantibrow/anti-detect-browser-skills9321 repos~4.2kAutomated safety check: WarnMIT
Mps Project ManagementJetBrains/MPS1.7k—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • Open Computer Use

    iFurySt/open-codex-computer-use

    Platform-neutral guidance for using Open Computer Use, the open-source Computer Use MCP server and CLI for macOS, Linux, and Windows.

    2.4k GitHub stars~1.5k tokensUpdated yesterday
    Productivity & AutomationAuto-check passed
  • Gearcoleco Debugging

    drhelius/Gearcoleco

    Debug and trace ColecoVision and Super Game Module games using the Gearcoleco emulator MCP server.

    141 GitHub stars~3.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Cortex Mem MCP

    sopaco/cortex-mem

    Persistent memory enhancement for AI agents. An agent skill from sopaco/cortex-mem.

    312 GitHub stars~2.8k tokensUpdated 2 mo ago
    Agent WorkflowsAuto-check passed
  • Browser MCP Agent

    antibrow/anti-detect-browser-skills

    Give an AI agent its own real browser over MCP tool calls - launch, navigate, click, fill, screenshot, extract text, run JS - with a kernel-level real-device fingerprint and a persistent profile, so…

    932 GitHub starsUsed in 1 repo~4.2k tokens
    Productivity & AutomationAuto-check: warnings
  • Official

    Open an MPS project in a running or freshly started MPS instance when MCP tools fail because no project is open (welcome screen), close an open project with mpsmcpcloseproject, or create a new empty…

    1.7k GitHub stars~2.2k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Gearcoleco Romhacking

    drhelius/Gearcoleco

    Hack, modify, and translate ColecoVision and Super Game Module ROMs using the Gearcoleco emulator MCP server.

    141 GitHub stars~3.9k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,354 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed
  • Content Creator

    sickn33/agentic-awesome-skills

    Drafts and reviews audience-specific content from supplied brand examples, with local scripts for brand voice and SEO diagnostics, channel templates and a content calendar.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed

Categories

Questions about Bumblebee

What does Bumblebee do?

Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs. Bumblebee is an agent skill from sickn33/agentic-awesome-skills. Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs.

When should I use Bumblebee?

Bumblebee fits situations like: tasks that involve Supply chain security.

How do I install Bumblebee in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill bumblebee -a claude-code`. Or copy the skill folder (skills/bumblebee in sickn33/agentic-awesome-skills) into .claude/skills/bumblebee in your project. Claude Code loads it when a task matches its description.

How do I install Bumblebee in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill bumblebee -a codex`. Or copy the skill folder (skills/bumblebee in sickn33/agentic-awesome-skills) into .agents/skills/bumblebee in your project. Codex loads it when a task matches its description.

Can I use Bumblebee in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill bumblebee -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bumblebee, .gemini/skills/bumblebee, .github/skills/bumblebee and .opencode/skills/bumblebee in your project.

What does Bumblebee need to run?

Going by SKILL.md and its folder, Bumblebee needs Python for the scripts in its folder and the command-line tools its instructions call (go, python3, brew, apt, dnf and pip). Our summary lists: Python 3.

Does Bumblebee access the network?

SKILL.md names 2 domains. As links in the text: github.com and go.dev. This is read from the text; nothing was executed.

Is Bumblebee safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Bumblebee use?

Bumblebee is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bumblebee use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bumblebee?

Skills that share tags, products or a category with Bumblebee: Open Computer Use (iFurySt/open-codex-computer-use, 2.4k stars), Gearcoleco Debugging (drhelius/Gearcoleco, 141 stars), Cortex Mem MCP (sopaco/cortex-mem, 312 stars) and Browser MCP Agent (antibrow/anti-detect-browser-skills, 932 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bumblebee?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,343 GitHub stars. The repository holds 1,354 skills in this directory. The repository was last updated on October 7, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.