Code Audit
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
Triage a reported security finding into a disposition: a private CVE (coordinated disclosure + advisory), a public hardening PR (fix in the open, no CVE), or not-a-security-issue (reply to reporter).
$ npx skills add symfony/symfony --skill security-triage -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install symfony/symfony security-triage --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/symfony/symfony.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-triage .claude/skills/security-triage && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-triage" agent skill from https://github.com/symfony/symfony/tree/8.2/.agents/skills/security-triage into .claude/skills/security-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-triage", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/symfony/symfony/tree/8.2/.agents/skills/security-triageType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add symfony/symfony --skill security-triage -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install symfony/symfony security-triage --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/symfony/symfony.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/security-triage .agents/skills/security-triage && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-triage" agent skill from https://github.com/symfony/symfony/tree/8.2/.agents/skills/security-triage into .agents/skills/security-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-triage", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add symfony/symfony --skill security-triage -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install symfony/symfony security-triage --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/symfony/symfony.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/security-triage .cursor/skills/security-triage && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-triage" agent skill from https://github.com/symfony/symfony/tree/8.2/.agents/skills/security-triage into .cursor/skills/security-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-triage", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/symfony/symfony.git --path .agents/skills/security-triage--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add symfony/symfony --skill security-triage -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install symfony/symfony security-triage --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/symfony/symfony.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/security-triage .gemini/skills/security-triage && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-triage" agent skill from https://github.com/symfony/symfony/tree/8.2/.agents/skills/security-triage into .gemini/skills/security-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-triage", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install symfony/symfony security-triageInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add symfony/symfony --skill security-triage -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/symfony/symfony.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/security-triage .github/skills/security-triage && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-triage" agent skill from https://github.com/symfony/symfony/tree/8.2/.agents/skills/security-triage into .github/skills/security-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-triage", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add symfony/symfony --skill security-triage -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install symfony/symfony security-triage --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/symfony/symfony.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/security-triage .opencode/skills/security-triage && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-triage" agent skill from https://github.com/symfony/symfony/tree/8.2/.agents/skills/security-triage into .opencode/skills/security-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-triage", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-triageTriage a reported security finding into a disposition: a private CVE (coordinated disclosure + advisory), a public hardening PR (fix in the open, no CVE), or not-a-security-issue (reply to reporter).
Security Triage is an agent skill from symfony/symfony. Triage a reported security finding into a disposition: a private CVE (coordinated disclosure + advisory), a public hardening PR (fix in the open, no CVE), or not-a-security-issue (reply to reporter). Assigns severity and affected maintained branches, and routes to the next step. Use when the user says "does this need a CVE", "CVE or hardening", "triage this report", "is this a security issue", "classify this finding", or "how should we disclose this".
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Vulnerability scanning. It works with Symfony and PHP. The repository describes itself as: The Symfony PHP framework. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 31ed3bf. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
symfony.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Triage loads about 2.6k tokens when it runs. Until then it costs about 118 tokens; SKILL.md has 1,344 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from symfony/symfony at commit 31ed3bf, republished under its MIT licence (© symfony). 1,344 words, ~2,646 tokens.
.claude/skills/security-triage/SKILL.md (or your agent's skills folder).Decides how a finding is handled, not whether the code is wrong. It complements
symfony-security-review (which finds missing hardening) by making the disclosure
call on a report.
The three dispositions and the conventions that record them:
| Disposition | Label | Branch prefix | Process |
|---|---|---|---|
| CVE | Has CVE + severity | cve-* | Private fix, GHSA/CVE, credit, blog post, coordinated release |
| Public hardening | none / Not a security issue | harden-*, hardening-*, pin-*, fix-* | Normal open PR, changelog, no embargo |
| Not a security issue | Not a security issue / Won't fix | n/a or fix-* | Reply to reporter; optionally a doc/robustness PR |
This skill produces a recommendation. The final call belongs to the Symfony security
team; treat its output as a structured argument, and defer to symfony.com/security
for the authoritative "what is not a vulnerability" list.
Whenever this skill says "Wait for confirmation", treat anything other than an explicit affirmative as no: stop and ask the user how they want to proceed.
Before classifying, pin down four things. Guessing any of them produces a wrong call.
template_from_string)?Reproduce if at all possible; an unreproducible report is not yet triable.
Apply in order. The first matching bucket wins.
A genuine improvement where a CVE condition fails. Typical shapes:
__unserialize __toString trampoline guard needs a pre-existing
untrusted unserialize() entry to matter).Severity (match the low/medium/high labels; CVSS is a sanity check, not the goal):
Affected branches: find the oldest version where the vulnerable code exists, intersect
with maintained_versions from https://symfony.com/releases.json. Fix on the lowest
maintained affected branch, then merge up (see the merge-up skill). Record the
oldest exposure even if it predates maintained versions.
State the recommendation as: disposition + severity + affected maintained branches + the one-line rationale (which decision-tree conditions decided it), then route:
cve-<slug>-<branch>; apply Has CVE + severity; the fix is
prepared privately and goes through the coordinated-disclosure process (request a
GHSA/CVE, credit the reporter, prepare the security release and blog post). Do not
open a public PR or push to a public remote before release. Wait for confirmation
before any outward step.harden-/hardening-/pin-/fix-<slug>; open a
normal PR with a CHANGELOG entry; use symfony-security-review to confirm the fix and
hardening-rule to add a durable gate where the class recurs.Not a security issue / Won't fix.In every case, the fix follows TDD, component-scoped tests, no em-dashes, no Claude/Anthropic credit, comments sparingly, no issue references in code.
| Finding shape | Disposition | Deciding factor |
|---|---|---|
| SSRF filter (private-network client) bypassed in a default configuration | CVE | default control bypassed, unauthenticated reach |
HTML sanitizer lets a javascript: URL through on a default profile | CVE | sanitizer's core contract bypassed, stored XSS |
| URL generator emits a path that crosses a routing boundary by default | CVE | boundary crossed in default use |
| A signed transport decodes the payload before verifying its MAC | CVE candidate, high | pre-auth RCE if signing is meant to defend a malicious broker; confirm the trust model |
Webhook signature compared with !==, or the secret is ignored | Hardening | opt-in endpoint, user-configured secret, bounded impact |
__unserialize assigns a string property without a \Stringable guard | Hardening | needs a pre-existing untrusted unserialize() entry (game-over precondition) |
| Input-length cap / broader sanitizer coverage added | Hardening | robustness, not a default-exploitable bypass |
| Unbounded recursion / regex backtracking / cache growth on input | Hardening, low | pure DoS, excluded from the CVE pipeline |
| Deserializing bytes through an API documented as trusted-only | Not a security issue | documented contract, caller's responsibility |
| A trusted-channel feature (e.g. ESI/SSI) used to reach internal hosts | Not a security issue | trusted by design |
| Case-insensitive host allowlist with no working bypass | Not a security issue | not a realistic bypass |
cve-* branch, or open a
public PR for a CVE-class finding before the coordinated release. Wait for confirmation.symfony.com/security is the source of truth for what is not a
vulnerability; this skill encodes observed practice, not policy.© symfony, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/security-triage of symfony/symfony.
Open the folder on GitHubat commit 31ed3bf
Security Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Triage this skillsymfony/symfony | 31k | — | ~2.6k | Automated safety check: Pass | MIT | |
| Code Audit3stoneBrother/code-audit | 892 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Security Reviewgithub/awesome-copilot | 40k | 1 repos | ~2.3k | Automated safety check: Notes | MIT | |
| Php Symfony Audit0xShe/PHP-Code-Audit-Skill | 402 | 1 repos | ~599 | Automated safety check: Pass | None | |
| Phy Regex AuditLeoYeAI/openclaw-master-skills | 2.2k | — | ~5.1k | Automated safety check: Pass | Apache-2.0 | |
| Security Triagesymfony/ux | 1.1k | — | ~3.2k | Automated safety check: Pass | MIT |
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
github/awesome-copilot
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…
0xShe/PHP-Code-Audit-Skill
Symfony 框架特效安全审计工具。针对 Symfony 常见 security.yaml、CSRF、Twig/Twig raw、表达式与访问控制等框架机制做白盒静态审计,并将风险映射到通用漏洞类型体系(AUTH/CSRF/CFG/XSS/TPL/LOGIC 等)。
LeoYeAI/openclaw-master-skills
Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases.
symfony/ux
Triage a security finding in a Symfony UX package into a disposition: a private CVE (coordinated disclosure through the Symfony security process), a public hardening PR (fix in the open, no CVE), or…
wgpsec/AboutSecurity
PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。
symfony/symfony
Synchronize translation catalogs across maintained Symfony branches: find messages that newer branches added to the English catalogs but that are still missing from the oldest maintained branch…
symfony/symfony
Decide whether open Bug PRs target the correct branch. An agent skill from symfony/symfony.
symfony/symfony
Cascade-merge maintained Symfony branches from oldest to newest (e.g.
symfony/symfony
Merge a reviewed pull request the way the Symfony core team does: one --no-ff merge commit per PR, whose message archives the whole discussion, with the review gates checked first.
symfony/symfony
Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening.
symfony/symfony
Decide whether a recurring hardening invariant is worth a CI gate, and add it without hitting the traps.
Categories
Triage a reported security finding into a disposition: a private CVE (coordinated disclosure + advisory), a public hardening PR (fix in the open, no CVE), or not-a-security-issue (reply to reporter). Security Triage is an agent skill from symfony/symfony. Triage a reported security finding into a disposition: a private CVE (coordinated disclosure + advisory), a public hardening PR (fix in the open, no CVE), or not-a-security-issue (reply to reporter).
Security Triage fits situations like: the user says does this need a CVE; triage this report; is this a security issue; classify this finding.
Run `npx skills add symfony/symfony --skill security-triage -a claude-code`. Or copy the skill folder (.agents/skills/security-triage in symfony/symfony) into .claude/skills/security-triage in your project. Claude Code loads it when a task matches its description.
Run `npx skills add symfony/symfony --skill security-triage -a codex`. Or copy the skill folder (.agents/skills/security-triage in symfony/symfony) into .agents/skills/security-triage in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add symfony/symfony --skill security-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-triage, .gemini/skills/security-triage, .github/skills/security-triage and .opencode/skills/security-triage in your project.
SKILL.md names no scripts, command-line tools or credentials: Security Triage is instructions for the agent only.
SKILL.md names 1 domain. In commands or code: symfony.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Triage: Code Audit (3stoneBrother/code-audit, 892 stars), Security Review (github/awesome-copilot, 40k stars), Php Symfony Audit (0xShe/PHP-Code-Audit-Skill, 402 stars) and Phy Regex Audit (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
symfony (a GitHub organization) maintains it in symfony/symfony, which has 31,182 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 9, 2026.
Source: symfony/symfony on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.