Find Law Firm
jeremylongshore/tons-of-skills-marketplace
A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US B2B law firms — corporate, IP/patent, M&A and securities, employment, commercial litigation…
Apply when writing code that touches auth, data access, file handling, or external APIs.
$ npx skills add stella/stella --skill conventions-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install stella/stella conventions-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/stella/stella.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/conventions-security .claude/skills/conventions-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "conventions-security" agent skill from https://github.com/stella/stella/tree/main/.agents/skills/conventions-security into .claude/skills/conventions-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "conventions-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/stella/stella/tree/main/.agents/skills/conventions-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add stella/stella --skill conventions-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install stella/stella conventions-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/stella/stella.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/conventions-security .agents/skills/conventions-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "conventions-security" agent skill from https://github.com/stella/stella/tree/main/.agents/skills/conventions-security into .agents/skills/conventions-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "conventions-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add stella/stella --skill conventions-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install stella/stella conventions-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/stella/stella.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/conventions-security .cursor/skills/conventions-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "conventions-security" agent skill from https://github.com/stella/stella/tree/main/.agents/skills/conventions-security into .cursor/skills/conventions-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "conventions-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/stella/stella.git --path .agents/skills/conventions-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add stella/stella --skill conventions-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install stella/stella conventions-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/stella/stella.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/conventions-security .gemini/skills/conventions-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "conventions-security" agent skill from https://github.com/stella/stella/tree/main/.agents/skills/conventions-security into .gemini/skills/conventions-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "conventions-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install stella/stella conventions-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add stella/stella --skill conventions-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/stella/stella.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/conventions-security .github/skills/conventions-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "conventions-security" agent skill from https://github.com/stella/stella/tree/main/.agents/skills/conventions-security into .github/skills/conventions-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "conventions-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add stella/stella --skill conventions-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install stella/stella conventions-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/stella/stella.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/conventions-security .opencode/skills/conventions-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "conventions-security" agent skill from https://github.com/stella/stella/tree/main/.agents/skills/conventions-security into .opencode/skills/conventions-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "conventions-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
conventions-securityApply when writing code that touches auth, data access, file handling, or external APIs.
Conventions Security is an agent skill from stella/stella. Apply when writing code that touches auth, data access, file handling, or external APIs. Stella handles privileged legal data (attorney-client privilege, litigation holds, personal data).
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Legal & Compliance, covering Legal research and SOC 2 and security compliance. The repository describes itself as: Open-source legal workspace. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 269655d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Conventions Security loads about 1.7k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 845 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from stella/stella at commit 269655d, republished under its Apache-2.0 licence (© stella). 845 words, ~1,719 tokens.
.claude/skills/conventions-security/SKILL.md (or your agent's skills folder).Apply when writing code that touches auth, data access, file handling, or external APIs. Stella handles privileged legal data (attorney-client privilege, litigation holds, personal data).
member role at the RLS layer (not
just the UI): a member has zero visibility into workspaces they
are not assigned to via workspace_members — no names, no
members, no metadata. Known limitation: org owner/admin
roles carry a deliberate firm-admin override granting access to
every client matter (client_id IS NOT NULL) regardless of
assignment, and there is no per-matter screening to wall a
specific admin out of a specific matter. Do not describe admin
access as "absolute confidentiality." Screening a matter from an
admin requires a matter-level exclusion consulted by the RLS
view (stella_authorized_workspaces), which is not yet built.Prefer solutions that make security bugs structurally impossible (compile-time, lint-time) over ones that rely on developer discipline.
Workspace-scoped handlers use createSafeHandler, declare permissions beside
the route, derive workspaceId: SafeId<"workspace"> from the authorized
context, and access tenant data through scopedDb. Never accept ownership IDs
from body/query input or fall back to root db because a relation is awkward
to express. Root/system handlers require a documented non-tenant purpose and
tables whose RLS posture denies ordinary application access. Enforced by
require-safe-route-handlers/require-safe-route-handlers and
no-body-ownership-ids/no-body-ownership-ids.
When an identifier comes from a related row, authorize it in the same query or transaction that uses it. A prior UI filter, cache lookup, or separate read-then-write check is not an access-control boundary.
Actors, workspace/organization ownership, request metadata, and before/after
identifiers come from authenticated server context. Clients may supply a user
action or reason where the domain requires it, but never the authoritative
actor or tenant. Required audit writes participate in the same transaction as
the mutation, or use a durable outbox when the sink is external. Enforced by
require-audit-on-mutation/require-audit-on-mutation.
resolveAccessibleWorkspaces returns all workspaces (including
deleting). The auth macro exposes two fields:
activeWorkspaceIds — excludes deleting workspaces (includes
active and archived). Use this for search, chat, MCP, and any
query that builds a workspace allowlist. This is the default;
reach for it first.accessibleWorkspaces — includes all statuses. Only use in
workspaceAccessMacro (which needs the status to return
appropriate HTTP codes). Never pass these IDs as a search/query
allowlist.If you need workspace IDs for a new feature, use activeWorkspaceIds
unless you have an explicit reason to include deleting workspaces
and document that reason in a comment.
Use escapeCSV from @/api/lib/csv for all CSV cell values. Never
hand-roll CSV escaping; the shared utility handles both delimiter
quoting and spreadsheet formula neutralization (=, +, -, @, tab, CR
prefixes). This prevents CSV injection attacks where user-controlled
values starting with formula characters execute in Excel/LibreOffice.
Validate untrusted input at each entry boundary with the owning shared schema.
Generated MCP capabilities validate the live endpoint's body, params, and query
schemas in apps/api/src/mcp/capability-tools.ts; do not repeat that parsing
inside the handler. Native MCP tools and chat registry tools normalize input
through normalizeObjectInputAtBoundary before dispatch; any other caller that
bypasses the HTTP route (cron jobs, workers) must apply the same normalizer and
schema before calling the operation. Keep business invariants and
related-resource authorization in the owning operation: an ID's valid shape
does not establish its ownership.
All user-supplied filenames must pass through sanitizeFilename
(@/api/lib/sanitize-filename) before storage or use in file
operations (ZIP entries, Content-Disposition headers, S3 keys).
The sanitizer strips path separators, traversal sequences, and
dangerous characters. Enforced by
security-guards/no-raw-filename-write.
When a handler accepts a userId from user input (body, query, or
params) and uses it in a query that returns user data (names, emails,
images), validate org membership first using validateOrgUserId from
@/api/lib/validated-org-user-id. The returned ValidatedOrgUserId
proves the check happened at the type level, making cross-org user ID
injection structurally impossible. For read paths that resolve
userIds stored in the database (not from user input), scope the user
query with an innerJoin on the member table filtered by
session.activeOrganizationId; enforced by
security-guards/no-unscoped-user-query.
GitHub Actions workflows must declare the minimum permissions
needed. Never use permissions: write-all. For PR-triggered
workflows, scope to contents: read + pull-requests: write.
Pin third-party actions to commit SHAs, not mutable tags. For
SBOM/provenance, use the shared stella/.github reusable
workflows which handle pinning, checksums, and PR-based updates.
© stella, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/conventions-security of stella/stella.
Open the folder on GitHubat commit 269655d
Conventions Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Conventions Security this skillstella/stella | 258 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Find Law Firmjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~3.6k | Automated safety check: Notes | MIT | |
| Tw Legal RAGaa0101181514/tw-legal-rag | 327 | — | ~580 | Automated safety check: Pass | Custom licence | |
| Design Award SearchSeanJ1ang/design-judge-skills | 712 | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| China Lawyer AnalystCSlawyer1985/china-lawyer-analyst | 194 | — | ~3.3k | Automated safety check: Pass | None | |
| Billing And Litigation BudgetTHUYRan/Legal-Skills-Chinese | 868 | — | ~5k | Automated safety check: Pass | None |
jeremylongshore/tons-of-skills-marketplace
A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US B2B law firms — corporate, IP/patent, M&A and securities, employment, commercial litigation…
aa0101181514/tw-legal-rag
Retrieve real Taiwan court judgments with verifiable citations before answering any question about Taiwan law or case law.
SeanJ1ang/design-judge-skills
Find and verify award-winning designs in the same or adjacent functional category through eight explicit relevance dimensions: problem and user, core function, sensing technology, intervention…
CSlawyer1985/china-lawyer-analyst
通过中国法律视角分析事件,运用成文法解释、指导案例参照、请求权基础分析等方法, 理解权利义务、评估责任风险、识别法律依据并推荐合规策略。
THUYRan/Legal-Skills-Chinese
A skill your agent uses when the user needs to track or manage attorney hours, expert fees, and investigation costs; control litigation spend; or prepare timesheets or expense statements for clients.
davepoon/buildwithclaude
Activate this agent for any future-oriented question that requires deep quantitative analysis, historical precedents, and structured scenario planning.
stella/stella
Create a concise, evidence-backed implementation plan in the repository planning area when the user explicitly asks for a plan.
stella/stella
Answers data-protection (GDPR) questions grounded in the regulation and supervisory guidance, with a citation for every claim.
stella/stella
Reviews a non-disclosure agreement against the firm's NDA checklist and reports findings with citations.
stella/stella
Collects the facts of an unpaid invoice, then drafts a payment demand letter.
stella/stella
Apply when a performance-guard check (network baseline, bundle baseline, DB query count, loader-prefetch lint, RC bailouts) fails or when touching a hot route/endpoint.
stella/stella
Apply when writing or reviewing React effects in apps/web. An agent skill from stella/stella.
Categories
Apply when writing code that touches auth, data access, file handling, or external APIs. Conventions Security is an agent skill from stella/stella. Apply when writing code that touches auth, data access, file handling, or external APIs.
Conventions Security fits situations like: tasks that involve Legal research; tasks that involve SOC 2 and security compliance.
Run `npx skills add stella/stella --skill conventions-security -a claude-code`. Or copy the skill folder (.agents/skills/conventions-security in stella/stella) into .claude/skills/conventions-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add stella/stella --skill conventions-security -a codex`. Or copy the skill folder (.agents/skills/conventions-security in stella/stella) into .agents/skills/conventions-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add stella/stella --skill conventions-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/conventions-security, .gemini/skills/conventions-security, .github/skills/conventions-security and .opencode/skills/conventions-security in your project.
SKILL.md names no scripts, command-line tools or credentials: Conventions Security is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Conventions Security is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Conventions Security: Find Law Firm (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Tw Legal RAG (aa0101181514/tw-legal-rag, 327 stars), Design Award Search (SeanJ1ang/design-judge-skills, 712 stars) and China Lawyer Analyst (CSlawyer1985/china-lawyer-analyst, 194 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
stella (a GitHub organization) maintains it in stella/stella, which has 258 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 8, 2026.
Source: stella/stella on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.