PR Babysitter
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
Triage the repo's open "[Vulnerability]" GitHub issues — for every issue lacking a true-positive/false-positive label, fetch the referenced commit, judge whether it is a genuine security fix or a…
$ npx skills add spaceraccoon/vulnerability-spoiler-alert --skill verify-vuln-issues -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install spaceraccoon/vulnerability-spoiler-alert verify-vuln-issues --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/spaceraccoon/vulnerability-spoiler-alert.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/verify-vuln-issues .claude/skills/verify-vuln-issues && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "verify-vuln-issues" agent skill from https://github.com/spaceraccoon/vulnerability-spoiler-alert/tree/main/.claude/skills/verify-vuln-issues into .claude/skills/verify-vuln-issues/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-vuln-issues", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/spaceraccoon/vulnerability-spoiler-alert/tree/main/.claude/skills/verify-vuln-issuesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add spaceraccoon/vulnerability-spoiler-alert --skill verify-vuln-issues -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install spaceraccoon/vulnerability-spoiler-alert verify-vuln-issues --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/spaceraccoon/vulnerability-spoiler-alert.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/verify-vuln-issues .agents/skills/verify-vuln-issues && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "verify-vuln-issues" agent skill from https://github.com/spaceraccoon/vulnerability-spoiler-alert/tree/main/.claude/skills/verify-vuln-issues into .agents/skills/verify-vuln-issues/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-vuln-issues", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add spaceraccoon/vulnerability-spoiler-alert --skill verify-vuln-issues -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install spaceraccoon/vulnerability-spoiler-alert verify-vuln-issues --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/spaceraccoon/vulnerability-spoiler-alert.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/verify-vuln-issues .cursor/skills/verify-vuln-issues && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "verify-vuln-issues" agent skill from https://github.com/spaceraccoon/vulnerability-spoiler-alert/tree/main/.claude/skills/verify-vuln-issues into .cursor/skills/verify-vuln-issues/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-vuln-issues", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/spaceraccoon/vulnerability-spoiler-alert.git --path .claude/skills/verify-vuln-issues--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add spaceraccoon/vulnerability-spoiler-alert --skill verify-vuln-issues -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install spaceraccoon/vulnerability-spoiler-alert verify-vuln-issues --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/spaceraccoon/vulnerability-spoiler-alert.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/verify-vuln-issues .gemini/skills/verify-vuln-issues && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "verify-vuln-issues" agent skill from https://github.com/spaceraccoon/vulnerability-spoiler-alert/tree/main/.claude/skills/verify-vuln-issues into .gemini/skills/verify-vuln-issues/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-vuln-issues", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install spaceraccoon/vulnerability-spoiler-alert verify-vuln-issuesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add spaceraccoon/vulnerability-spoiler-alert --skill verify-vuln-issues -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/spaceraccoon/vulnerability-spoiler-alert.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/verify-vuln-issues .github/skills/verify-vuln-issues && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "verify-vuln-issues" agent skill from https://github.com/spaceraccoon/vulnerability-spoiler-alert/tree/main/.claude/skills/verify-vuln-issues into .github/skills/verify-vuln-issues/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-vuln-issues", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add spaceraccoon/vulnerability-spoiler-alert --skill verify-vuln-issues -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install spaceraccoon/vulnerability-spoiler-alert verify-vuln-issues --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/spaceraccoon/vulnerability-spoiler-alert.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/verify-vuln-issues .opencode/skills/verify-vuln-issues && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "verify-vuln-issues" agent skill from https://github.com/spaceraccoon/vulnerability-spoiler-alert/tree/main/.claude/skills/verify-vuln-issues into .opencode/skills/verify-vuln-issues/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify-vuln-issues", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
verify-vuln-issuesTriage the repo's open "[Vulnerability]" GitHub issues — for every issue lacking a true-positive/false-positive label, fetch the referenced commit, judge whether it is a genuine security fix or a…
Verify Vuln Issues is an agent skill from spaceraccoon/vulnerability-spoiler-alert. Triage the repo's open "[Vulnerability]" GitHub issues — for every issue lacking a true-positive/false-positive label, fetch the referenced commit, judge whether it is a genuine security fix or a false positive, post an analysis comment, and apply the verdict label. Pure dependency bumps get a dependency label and are closed. Use when asked to "verify", "triage", or "review" the vulnerability issues / findings in the tracker.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.
It sits in Development. It works with GitHub. The repository describes itself as: A monitoring hub that watches popular open-source repositories and uses AI to detect when commits are patching security vulnerabilities - often before a CVE is even assigned… The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 096072c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
ghnodeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GH_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Verify Vuln Issues loads about 2.3k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 1,055 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from spaceraccoon/vulnerability-spoiler-alert at commit 096072c, republished under its MIT licence (© spaceraccoon). 1,055 words, ~2,291 tokens.
.claude/skills/verify-vuln-issues/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.This repo's monitoring action files a GitHub issue for every commit it thinks is a security patch. Many are genuine; some are false positives (routine dependency bumps, feature commits, build-tooling changes, AI-misclassified commits). This skill verifies the unverified ones, comments, and labels each.
Target: open issues authored by github-actions[bot] that carry none
of the verdict labels — true-positive, false-positive, or dependency.
An issue carrying any of those, or one already closed (e.g. a dependency
bump closed in an earlier run, or a duplicate), has already been dispositioned
— skip it. prepare.mjs applies exactly this filter.
For every targeted issue: post one analysis comment, then apply the disposition:
| Finding | Action |
|---|---|
| Genuine security fix | comment + add true-positive label |
| False positive | comment + add false-positive label |
| Pure dependency bump | comment + add dependency label + close (not planned) |
Pure dependency bump = the commit's entire diff is package manifests, lockfiles, or version changelogs — no hand-written fix code. Close it regardless of whether the upstream advisory is real; dependency bumps are out of scope for this tracker.
true-positive), do not close it.Duplicate issues: the monitor sometimes files more than one issue for the
same commit. prepare.mjs detects these (writes /tmp/vsa/duplicates.json).
Keep and verify the canonical one (lowest issue number = first filed); the
rest are duplicates — close them as duplicates, or delete with gh issue delete only after the user confirms, since deletion is permanent.
Labels: add the verdict label. Never remove a label someone else applied
— if an issue carries a conflicting one, stop and surface it. You may correct
a verdict this skill applied earlier (e.g. true-positive → false-positive)
when re-analysis warrants: remove the stale label, add the right one, and post
a correction comment explaining why.
Relay a final summary (counts per repo, false positives, issues closed as dependency bumps, duplicates found).
gh must be authenticated. gh auth status reporting "not logged in" inside the
sandbox is normal for git operations, but gh api/gh issue calls still need a
real token. If gh calls fail with HTTP 401/Bad credentials, ask the user
to run ! gh auth login in the prompt (the dummy-GH_TOKEN trick does not work —
the proxy rejects it).
Ensure the dependency label exists (create once if missing):
gh label create dependency --repo <owner/repo> \
--description "Issue is only a dependency/version bump — out of scope, ignored" \
--color ededednode .claude/skills/verify-vuln-issues/prepare.mjsIt lists issues, filters to unverified ones, parses each body for its repo + full
commit SHA (via scripts/lib/parser.mjs), downloads every commit diff and
metadata, and writes /tmp/vsa/:
todo.json — [{number, state, repository, commitSha, ...}]ctx/<n>.txt — per-issue: the AI claim + commit message + file list + diff
(lockfiles trimmed, huge files truncated)duplicates.json — groups of issues sharing one commit SHA (see "Duplicate
issues" above)results.json — starts {}; record verdicts here as you go.The --- FILES CHANGED --- list in each context file is what you use to spot a
pure dependency bump (only package.json / *.lock / go.mod / go.sum /
CHANGELOG* / doc/changelogs/* / toolchain files).
Read ctx/<n>.txt files (~10–15 per turn; read large ones individually). For each
issue decide the finding using the rubric below, and record into results.json
(verified / false-positive / dependency) so progress survives compaction.
Write each comment to /tmp/vsa/comments/<n>.md, then per issue:
gh issue comment <n> --repo <owner/repo> --body-file /tmp/vsa/comments/<n>.md
# verified:
gh issue edit <n> --repo <owner/repo> --add-label true-positive
# false positive:
gh issue edit <n> --repo <owner/repo> --add-label false-positive
# pure dependency bump:
gh issue edit <n> --repo <owner/repo> --add-label dependency
gh issue close <n> --repo <owner/repo> --reason "not planned"Loop over a batch; report any failures.
The commit diff is ground truth — the issue body is an LLM guess and is often wrong about the mechanism, severity, or even the vuln class.
true-positive)GL-Vuln:), or a [security] tag.deps/, it carries the actual patch, so keep it open.dependency, then close)dependency + close.false-positive)tools/, hack/,
devDependencies, or a maintainer-only script — no runtime/attacker surface.__proto__ was already handled).When unsure, state the caveat explicitly (dependency bump → flaw is upstream; dev-only reach; severity overstated) rather than forcing a binary call.
Start with a bold verdict line, reference the short commit SHA, reason from the
diff, then a one-line Verdict:. Keep it substantive but tight:
## Verification analysis — **Verified** (genuine <class> fix)
Reviewed commit `<sha>`. <what the diff actually does and why it is/ isn't a
real fix; cite advisory refs, tests, caveats>.
Verdict: verified — <one line>.If an issue already has a CVE in its commit message but no cve: label, mention
it (it would graduate the finding from "verified" to "confirmed").
© spaceraccoon, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .claude/skills/verify-vuln-issues of spaceraccoon/vulnerability-spoiler-alert.
Open the folder on GitHubat commit 096072c
Verify Vuln Issues next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Verify Vuln Issues this skillspaceraccoon/vulnerability-spoiler-alert | 161 | — | ~2.3k | Automated safety check: Pass | MIT | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Greplooponyx-dot-app/onyx | 32k | 4 repos | ~3.3k | Automated safety check: Pass | MIT | |
| Check PRonyx-dot-app/onyx | 32k | 2 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Setup Matt Pocock Skillsbestofjs/bestofjs | 3.1k | 20 repos | ~1.7k | Automated safety check: Pass | MIT | |
| Contributor-First PR MergeHKUDS/OpenHarness | 16k | 1 repos | ~847 | Automated safety check: Pass | MIT |
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
onyx-dot-app/onyx
Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.
onyx-dot-app/onyx
Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.
bestofjs/bestofjs
Configure this repo for the engineering skills — set up its issue tracker, triage label vocabulary, and domain doc layout.
HKUDS/OpenHarness
Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.
cline/cline
Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.
Works with
Categories
Triage the repo's open "[Vulnerability]" GitHub issues — for every issue lacking a true-positive/false-positive label, fetch the referenced commit, judge whether it is a genuine security fix or a…. Verify Vuln Issues is an agent skill from spaceraccoon/vulnerability-spoiler-alert. Triage the repo's open "[Vulnerability]" GitHub issues — for every issue lacking a true-positive/false-positive label, fetch the referenced commit, judge whether it is a genuine security fix or a false positive, post an analysis comment, and apply the verdict label.
Verify Vuln Issues fits situations like: asked to verify; review the vulnerability issues / findings in the tracker.
Run `npx skills add spaceraccoon/vulnerability-spoiler-alert --skill verify-vuln-issues -a claude-code`. Or copy the skill folder (.claude/skills/verify-vuln-issues in spaceraccoon/vulnerability-spoiler-alert) into .claude/skills/verify-vuln-issues in your project. Claude Code loads it when a task matches its description.
Run `npx skills add spaceraccoon/vulnerability-spoiler-alert --skill verify-vuln-issues -a codex`. Or copy the skill folder (.claude/skills/verify-vuln-issues in spaceraccoon/vulnerability-spoiler-alert) into .agents/skills/verify-vuln-issues in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add spaceraccoon/vulnerability-spoiler-alert --skill verify-vuln-issues -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-vuln-issues, .gemini/skills/verify-vuln-issues, .github/skills/verify-vuln-issues and .opencode/skills/verify-vuln-issues in your project.
Going by SKILL.md and its folder, Verify Vuln Issues needs JavaScript for the scripts in its folder, the command-line tools its instructions call (gh and node) and credentials named GH_TOKEN. Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Verify Vuln Issues is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Verify Vuln Issues: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Greploop (onyx-dot-app/onyx, 32k stars), Check PR (onyx-dot-app/onyx, 32k stars) and Setup Matt Pocock Skills (bestofjs/bestofjs, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
spaceraccoon (a GitHub user) maintains it in spaceraccoon/vulnerability-spoiler-alert, which has 161 GitHub stars. The repository was last updated on September 1, 2026.
Source: spaceraccoon/vulnerability-spoiler-alert on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.