Agent skill

Variant Analysis

by waybarrios in waybarrios/opencode-power-pack

Find similar vulnerabilities and bugs across codebases using pattern-based analysis.

MITAuto-check passedSecurity

Install Variant Analysis

skills CLI
$ npx skills add waybarrios/opencode-power-pack --skill variant-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install waybarrios/opencode-power-pack variant-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/waybarrios/opencode-power-pack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/variant-analysis .claude/skills/variant-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
variant-analysis
GitHub stars
533
Used in
5 other repos
Token cost
~1.4k tokens
SKILL.md length
681 words
Files
13
Skills in repo
32
Repo updated
First seen
Licence
MIT

At a glance

Find similar vulnerabilities and bugs across codebases using pattern-based analysis.

  • Works in 9 steps: Understand the Original Issue → Create an Exact Match → Identify Abstraction Points → …
  • Hunting bug variants
  • SKILL.md covers When to Use, When NOT to Use, The Five-Step Process and Tool Selection, plus 3 more sections
  • Calls rg

What it does

Variant Analysis is an agent skill from waybarrios/opencode-power-pack. Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing systematic code audits after finding an initial issue.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files (for example `METHODOLOGY.md`, `resources/semgrep/cpp.yaml` and `resources/semgrep/go.yaml`).

It sits in Security, covering Static analysis and SAST. It works with Semgrep. The repository describes itself as: 54 rigorous skills for Codex, OpenCode, and Pi: code review, security audit, feature development, frontend design, MCP tools, Hugging Face ML/training, and more. The licence is MIT.

When your agent uses it

  • Hunting bug variants
  • Building CodeQL/Semgrep queries
  • Analyzing security vulnerabilities
  • Performing systematic code audits after finding an initial issue

Example prompts

  • “/variant-analysis”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Understand the Original Issue
  2. Create an Exact Match
  3. Identify Abstraction Points
  4. Iteratively Generalize
  5. Analyze and Triage Results
  6. Narrow Search Scope
  7. Pattern Too Specific
  8. Single Vulnerability Class
  9. Missing Edge Cases

What it can do on your machine

Read from SKILL.md and the folder at commit 9dccb6d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Variant Analysis loads about 1.4k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 681 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from waybarrios/opencode-power-pack at commit 9dccb6d, republished under its MIT licence (© waybarrios). 681 words, ~1,421 tokens.

Download SKILL.mdSave it as .claude/skills/variant-analysis/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.
name
variant-analysis
description
Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing systematic code audits after finding an initial issue.
license
MIT (modified; see UPSTREAMS.json)

Variant Analysis

You are a variant analysis expert. Your role is to help find similar vulnerabilities and bugs across a codebase after identifying an initial pattern.

When to Use

Use this skill when:

  • A vulnerability has been found and you need to search for similar instances
  • Building or refining CodeQL/Semgrep queries for security patterns
  • Performing systematic code audits after an initial issue discovery
  • Hunting for bug variants across a codebase
  • Analyzing how a single root cause manifests in different code paths

When NOT to Use

Do NOT use this skill for:

  • Initial vulnerability discovery (use audit-context-building or domain-specific audits instead)
  • General code review without a known pattern to search for
  • Writing fix recommendations (use issue-writer instead)
  • Understanding unfamiliar code (use audit-context-building for deep comprehension first)

The Five-Step Process

Step 1: Understand the Original Issue

Before searching, deeply understand the known bug:

  • What is the root cause? Not the symptom, but WHY it's vulnerable
  • What conditions are required? Control flow, data flow, state
  • What makes it exploitable? User control, missing validation, etc.
Step 2: Create an Exact Match

Start with a pattern that matches ONLY the known instance:

bash
rg -n "exact_vulnerable_code_here"

Verify: Does it match exactly ONE location (the original)?

Step 3: Identify Abstraction Points
ElementKeep SpecificCan Abstract
Function nameIf unique to bugIf pattern applies to family
Variable namesNeverAlways use metavariables
Literal valuesIf value mattersIf any value triggers bug
ArgumentsIf position mattersUse ... wildcards
Step 4: Iteratively Generalize

Change ONE element at a time:

  1. Run the pattern
  2. Review ALL new matches
  3. Classify: true positive or false positive?
  4. If FP rate acceptable, generalize next element
  5. If FP rate too high, revert and try different abstraction

Stop when false positive rate exceeds ~50%

Step 5: Analyze and Triage Results

For each match, document:

  • Location: File, line, function
  • Confidence: High/Medium/Low
  • Exploitability: Reachable? Controllable inputs?
  • Priority: Based on impact and exploitability

For deeper strategic guidance, see METHODOLOGY.md.

Tool Selection

ScenarioToolWhy
Quick surface searchripgrepFast, zero setup
Simple pattern matchingSemgrepEasy syntax, no build needed
Data flow trackingSemgrep taint / CodeQLFollows values across functions
Cross-function analysisCodeQLBest interprocedural analysis
Non-building codeSemgrepWorks on incomplete code

Key Principles

  1. Root cause first: Understand WHY before searching for WHERE
  2. Start specific: First pattern should match exactly the known bug
  3. One change at a time: Generalize incrementally, verify after each change
  4. Know when to stop: 50%+ FP rate means you've gone too generic
  5. Search everywhere: Always search the ENTIRE codebase, not just the module where the bug was found
  6. Expand vulnerability classes: One root cause often has multiple manifestations
Show full SKILL.md (238 more words)Show less

Critical Pitfalls to Avoid

These common mistakes cause analysts to miss real vulnerabilities:

1. Narrow Search Scope

Searching only the module where the original bug was found misses variants in other locations.

Example: Bug found in api/handlers/ → only searching that directory → missing variant in utils/auth.py

Mitigation: Always run searches against the entire codebase root directory.

2. Pattern Too Specific

Using only the exact attribute/function from the original bug misses variants using related constructs.

Example: Bug uses isAuthenticated check → only searching for that exact term → missing bugs using related properties like isActive, isAdmin, isVerified

Mitigation: Enumerate ALL semantically related attributes/functions for the bug class.

3. Single Vulnerability Class

Focusing on only one manifestation of the root cause misses other ways the same logic error appears.

Example: Original bug is "return allow when condition is false" → only searching that pattern → missing:

  • Null equality bypasses (null == null evaluates to true)
  • Documentation/code mismatches (function does opposite of what docs claim)
  • Inverted conditional logic (wrong branch taken)

Mitigation: List all possible manifestations of the root cause before searching.

4. Missing Edge Cases

Testing patterns only with "normal" scenarios misses vulnerabilities triggered by edge cases.

Example: Testing auth checks only with valid users → missing bypass when userId = null matches resourceOwnerId = null

Mitigation: Test with: unauthenticated users, null/undefined values, empty collections, and boundary conditions.

Resources

Ready-to-use templates in resources/:

CodeQL (resources/codeql/):

  • python.ql, javascript.ql, java.ql, go.ql, cpp.ql

Semgrep (resources/semgrep/):

  • python.yaml, javascript.yaml, java.yaml, go.yaml, cpp.yaml

Report: resources/variant-report-template.md

© waybarrios, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 12 other files in skills/variant-analysis of waybarrios/opencode-power-pack.

  • SKILL.md
  • METHODOLOGY.md
  • resources/codeql/cpp.ql
  • resources/codeql/go.ql
  • resources/codeql/java.ql
  • resources/codeql/javascript.ql
  • resources/codeql/python.ql
  • resources/semgrep/cpp.yaml
  • resources/semgrep/go.yaml
  • resources/semgrep/java.yaml
  • resources/semgrep/javascript.yaml
  • resources/semgrep/python.yaml
  • resources/variant-report-template.md

Open the folder on GitHubat commit 9dccb6d

Used in 5 other repositories

We found 14 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 5 other GitHub owners. This page covers the copy in waybarrios/opencode-power-pack, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Variant Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Variant Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Variant Analysis this skillwaybarrios/opencode-power-pack5335 repos~1.4kAutomated safety check: PassMIT
Semgrepvigolium/piolium1381 repos~2.4kAutomated safety check: NotesMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Sast SemgrepAgentSecOps/SecOpsAgentKit2192 repos~2.4kAutomated safety check: PassCustom licence
Semgrep Rule Creatortrailofbits/skills7.4k6 repos~1.8kAutomated safety check: NotesCC-BY-SA-4.0
Semgrep Rule Variant Creatortrailofbits/skills7.4k5 repos~3.4kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Semgrep

    vigolium/piolium

    Run Semgrep static analysis scan on a codebase using parallel subagents.

    138 GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Sast Semgrep

    AgentSecOps/SecOpsAgentKit

    Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

    219 GitHub starsUsed in 2 repos~2.4k tokens
    SecurityAuto-check passed
  • Semgrep Rule Creator

    trailofbits/skills

    Official

    Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns.

    7.4k GitHub starsUsed in 6 repos~1.8k tokens
    SecurityAuto-check: notes
  • Official

    Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills.

    7.4k GitHub starsUsed in 5 repos~3.4k tokens
    SecurityAuto-check: notes
  • Semgrep

    semgrep/skills

    Official

    Run Semgrep static analysis scans and create custom detection rules.

    322 GitHub stars~2.3k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from waybarrios/opencode-power-pack

All 32 skills in this repo
  • Hf Cloud Sagemaker Iam Preflight

    waybarrios/opencode-power-pack

    Verify or select a SageMaker execution role before creating models, endpoints, or training jobs.

    533 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Huggingface LLM Trainer

    waybarrios/opencode-power-pack

    Train or fine-tune language models with TRL or Unsloth on Hugging Face Jobs, including SFT, DPO, GRPO, reward models, and GGUF conversion.

    533 GitHub stars~3k tokensUpdated yesterday
    Auto-check passed
  • Huggingface Vision Trainer

    waybarrios/opencode-power-pack

    Train object-detection, image-classification, or SAM segmentation models on Hugging Face Jobs.

    533 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Codeql

    waybarrios/opencode-power-pack

    Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF.

    533 GitHub starsUsed in 2 repos~3.7k tokens
    Auto-check passed
  • Semgrep

    waybarrios/opencode-power-pack

    Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.

    533 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Insecure Defaults

    waybarrios/opencode-power-pack

    Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production.

    533 GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed

Works with

Categories

Questions about Variant Analysis

What does Variant Analysis do?

Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Variant Analysis is an agent skill from waybarrios/opencode-power-pack. Find similar vulnerabilities and bugs across codebases using pattern-based analysis.

When should I use Variant Analysis?

Variant Analysis fits situations like: hunting bug variants; building CodeQL/Semgrep queries; analyzing security vulnerabilities; performing systematic code audits after finding an initial issue.

How do I install Variant Analysis in Claude Code?

Run `npx skills add waybarrios/opencode-power-pack --skill variant-analysis -a claude-code`. Or copy the skill folder (skills/variant-analysis in waybarrios/opencode-power-pack) into .claude/skills/variant-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Variant Analysis in Codex?

Run `npx skills add waybarrios/opencode-power-pack --skill variant-analysis -a codex`. Or copy the skill folder (skills/variant-analysis in waybarrios/opencode-power-pack) into .agents/skills/variant-analysis in your project. Codex loads it when a task matches its description.

Can I use Variant Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add waybarrios/opencode-power-pack --skill variant-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/variant-analysis, .gemini/skills/variant-analysis, .github/skills/variant-analysis and .opencode/skills/variant-analysis in your project.

What does Variant Analysis need to run?

Going by SKILL.md and its folder, Variant Analysis needs the command-line tools its instructions call (rg).

Does Variant Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Variant Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Variant Analysis use?

Variant Analysis is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Variant Analysis use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Variant Analysis?

Skills that share tags, products or a category with Variant Analysis: Semgrep (vigolium/piolium, 138 stars), Semgrep Security Scan (trailofbits/skills, 7.4k stars), Sast Semgrep (AgentSecOps/SecOpsAgentKit, 219 stars) and Semgrep Rule Creator (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Variant Analysis?

waybarrios (a GitHub user) maintains it in waybarrios/opencode-power-pack, which has 533 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on October 6, 2026.

Source: waybarrios/opencode-power-pack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.