Agent skill

Bumblebee Hygiene Scan

by Szotasz in Szotasz/marveen

Weekly supply-chain hygiene scan (Perplexity Bumblebee). An agent skill from Szotasz/marveen.

MITAuto-check passedProductivity & Automation

Install Bumblebee Hygiene Scan

skills CLI
$ npx skills add Szotasz/marveen --skill bumblebee-hygiene-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Szotasz/marveen bumblebee-hygiene-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Szotasz/marveen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/seed-scheduled-tasks/bumblebee-hygiene-scan .claude/skills/bumblebee-hygiene-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bumblebee-hygiene-scan
GitHub stars
117
Token cost
~2.1k tokens
SKILL.md length
803 words
Files
8
Skills in repo
18
Repo updated
First seen
Licence
MIT

At a glance

Weekly supply-chain hygiene scan (Perplexity Bumblebee). An agent skill from Szotasz/marveen.

  • Works in 4 steps: Locate threat-intel catalogs → Run scan (read-only, ~3 sec) → Evaluate findings → …
  • Tasks that involve Supply chain security
  • SKILL.md covers When / purpose, Binary, Procedure and Pitfalls, plus 1 more section
  • Calls git, python3 and go; reaches github.com

What it does

Bumblebee Hygiene Scan is an agent skill from Szotasz/marveen. Weekly supply-chain hygiene scan (Perplexity Bumblebee). Monday 09:00. Inventories installed packages, MCP configs, and extensions, then matches against known supply-chain threat catalogs. Telegram alert ONLY if findings 0.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `task-config.json`, `threat-intel/antv-mini-shai-hulud.json` and `threat-intel/gemstuffer.json`).

It sits in Productivity & Automation, covering Supply chain security, Web search and Scheduled and recurring tasks. It works with Model Context Protocol, Telegram and Perplexity. The repository describes itself as: AI csapatod, ami fut amíg te alszol. The licence is MIT.

When your agent uses it

  • Tasks that involve Supply chain security
  • Tasks that involve Web search
  • Tasks that involve Scheduled and recurring tasks

Example prompts

  • “/bumblebee-hygiene-scan”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Locate threat-intel catalogs
  2. Run scan (read-only, ~3 sec)
  3. Evaluate findings
  4. A zero is only evidence after a positive control. The scan's output is

What it can do on your machine

Read from SKILL.md and the folder at commit e1ac6cc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • python3
    • go
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bumblebee Hygiene Scan loads about 2.1k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 803 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Szotasz/marveen at commit e1ac6cc, republished under its MIT licence (© Szotasz). 803 words, ~2,052 tokens.

Download SKILL.mdSave it as .claude/skills/bumblebee-hygiene-scan/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
bumblebee-hygiene-scan
description
Weekly supply-chain hygiene scan (Perplexity Bumblebee). Monday 09:00. Inventories installed packages, MCP configs, and extensions, then matches against known supply-chain threat catalogs. Telegram alert ONLY if findings > 0.

Bumblebee weekly supply-chain scan

When / purpose

Monday 09:00. The fleet uses many third-party MCP servers, auto-installed CLIs, packages, and skills, creating supply-chain risk. This is a read-only inventory + known-threat match.

Binary

  • Path: ~/.local/bin/bumblebee (Go build, PIN v0.1.1)
  • Source: github.com/perplexityai/bumblebee (Apache 2.0)
  • Build: git clone https://github.com/perplexityai/bumblebee && cd bumblebee && go build -o ~/.local/bin/bumblebee ./cmd/bumblebee (Go >= 1.25 required)

Procedure

  1. Check binary exists:
bash
if [ ! -x "$HOME/.local/bin/bumblebee" ]; then
  echo "bumblebee binary not found, skipping scan (install Go>=1.25 and build from github.com/perplexityai/bumblebee)"
  exit 0
fi

If the binary is missing (fresh machine without Go), gracefully skip with an info-level log line. Do NOT error out or send alerts.

  1. Locate threat-intel catalogs:
bash
BB_CATALOG="$HOME/.claude/tools/bumblebee-threat-intel"
if [ ! -d "$BB_CATALOG" ] || [ -z "$(ls -A "$BB_CATALOG" 2>/dev/null)" ]; then
  # Try seeded catalogs from install dir
  SEED_CATALOG="{{INSTALL_DIR}}/seed-scheduled-tasks/bumblebee-hygiene-scan/threat-intel"
  if [ -d "$SEED_CATALOG" ] && [ -n "$(ls -A "$SEED_CATALOG" 2>/dev/null)" ]; then
    mkdir -p "$BB_CATALOG"
    cp "$SEED_CATALOG"/*.json "$BB_CATALOG/"
  else
    echo "No threat-intel catalogs found, skipping scan"
    exit 0
  fi
fi
  1. Run scan (read-only, ~3 sec):
bash
~/.local/bin/bumblebee scan --profile baseline --exposure-catalog "$BB_CATALOG" > /tmp/bb-weekly.ndjson 2>/tmp/bb-weekly.err
  1. Evaluate findings:
bash
FINDING_COUNT=$(grep -c '"record_type":"finding"' /tmp/bb-weekly.ndjson 2>/dev/null || echo 0)
  1. A zero is only evidence after a positive control. The scan's output is record-type-identical with and without a loaded catalog, and nothing in the NDJSON says whether the catalog loaded -- a mistyped path or an empty catalog dir produces the same reassuring zero as a clean machine (measured 2026-08-24). So before booking a 0 as clean, prove the match path is alive:
bash
# a) pick one certainly-installed package from today's scan
#    (the SCAN record's field is package_name)
grep '"record_type":"package"' /tmp/bb-weekly.ndjson | head -1 | \
  python3 -c "import sys,json; d=json.load(sys.stdin); print(d['ecosystem'], d['package_name'], d['version'])"
# b) write a one-entry synthetic catalog into a TEMP dir. CAREFUL: the CATALOG
#    entry's field is `package`, NOT `package_name` -- the two schemas differ,
#    and the wrong key makes the control itself fail silently (it then looks
#    exactly like a broken catalog load). Copy schema_version from a real
#    catalog file.
mkdir -p /tmp/bb-synth && cat > /tmp/bb-synth/synthetic.json << 'JSON'
{"schema_version": "<copy from a real catalog file>", "entries": [
  {"id": "SYNTH-1", "name": "synthetic control", "ecosystem": "<from a>",
   "package": "<from a>", "versions": ["<from a>"], "severity": "low", "source": "synthetic"}
]}
JSON
~/.local/bin/bumblebee scan --profile baseline --exposure-catalog /tmp/bb-synth | \
  grep -c '"record_type":"finding"'   # must be > 0
rm -rf /tmp/bb-synth

If the control yields findings, today's real 0 is a real zero. If the control yields 0, do NOT report clean -- report INSTRUMENT FAILURE (and check your synthetic file's field names first: that is the cheaper of the two causes). Never put the synthetic file into the real catalog dir.

  1. Telegram ONLY if finding > 0: send alert with finding details (ecosystem, package, version, which threat catalog matched). If 0 findings AND the positive control passed: stay silent (heartbeat style, transcript line only). A zero without the control is UNVERIFIED and must be reported as such, not as clean.

  2. Monthly threat-intel refresh (once per ~30 days). Key the 30-day rule on a refresh-check marker, NOT on the catalog files' mtime: catalog file mtime never changes while upstream is unchanged, so an mtime rule re-clones on every weekly run once the files age past 30 days (measured 2026-09-07: 35-day-old files, upstream byte-identical -- the clone was pure waste). Compare content, copy only on change, and stamp the marker either way:

bash
MARKER="$BB_CATALOG/.last-refresh-check"
if [ -z "$(find "$MARKER" -mtime -30 2>/dev/null)" ]; then
  cd /tmp && rm -rf bb-ti-update
  git clone -q --depth 1 https://github.com/perplexityai/bumblebee.git bb-ti-update 2>/dev/null
  if [ -d bb-ti-update/threat_intel ]; then
    LOCAL_SUM=$(cat "$BB_CATALOG"/*.json 2>/dev/null | shasum -a 256 | cut -d' ' -f1)
    UPSTREAM_SUM=$(cat bb-ti-update/threat_intel/*.json | shasum -a 256 | cut -d' ' -f1)
    if [ "$LOCAL_SUM" != "$UPSTREAM_SUM" ]; then
      cp bb-ti-update/threat_intel/*.json "$BB_CATALOG/"
    fi
  fi
  rm -rf bb-ti-update
  touch "$MARKER"
fi

Pitfalls

  • Findings ONLY appear with --exposure-catalog flag (otherwise always 0). The catalogs live in ~/.claude/tools/bumblebee-threat-intel/.
  • The scan is fail-open on the catalog: with a mistyped catalog path or an empty catalog dir the output is record-type-identical to a healthy run, and nothing in it says the catalog did not load. A zero without the step-5 positive control is a number nobody has checked.
  • If Go is not available (< 1.25 or not installed), the binary cannot be built. The task must GRACEFULLY SKIP, not crash.
  • 0 findings does NOT mean absolute safety, only that the threats in the currently loaded catalogs are not present. Do not quote a fixed threat count from memory -- it goes stale (a "6 threats" figure survived here while the real catalogs held 12 files / 1099 entries); if the number is needed, count it from the loaded catalog files' entries arrays.
  • Do NOT spam: 0 findings = no Telegram message.
  • The vendored catalogs in seed-scheduled-tasks are a bootstrap fallback. The monthly refresh keeps them current.
  • SILENT-SKIP BLIND SPOT (measured 2026-08-10): if the binary is missing -- no Go toolchain on the machine (go: command not found), or it was simply never built -- step 1 exits 0 every single Monday while the catalogs sit there looking healthy. "Graceful skip + no Telegram" then means the coverage gap is permanently invisible: no alert, no transcript anyone reads, week after week. RULE: on a skip, before exit 0, check whether a hot memory about the gap already exists (GET /api/memories?q=bumblebee&strict=1) and write one if not. The &strict=1 is the whole check (MEMKERESVAK917): without it the search is forgiving, so when no memory matches it answers with whatever the leftover filler words pulled in, and the absence test reads that as "already exists" and never writes. Measured on the owner store with a naturally phrased query of exactly this shape -- q=bumblebee binary hianyzik Go toolchain nincs -- the endpoint answered X-Memory-Search: strict=false; relaxed=true; hits=50. Fifty rows, none of them the memory being looked for. With strict=1 an empty answer means exactly what it looks like. That is what surfaces it in the Dream Engine / napindito Top-3 instead of it vanishing. The no-Telegram rule bans spam, NOT record-keeping.
  • Do NOT run step 7 (catalog refresh) when the binary is missing. Refreshing threat intel for a scanner that cannot run is pure churn -- and a git clone + cp over the catalog dir is a mutation with zero payoff. Fix the binary first, refresh after.
  • Building the binary means installing a whole Go toolchain (brew install go) on the user's machine. That is a user decision, not an autonomous one -- escalate and wait, do not self-install.
Show full SKILL.md (37 more words)Show less

Verification

  • Scan exits 0, scan_summary record shows status=complete.
  • A 0-finding result was accompanied by a passing positive control (step 5), or the report says the zero is UNVERIFIED.
  • Finding > 0 triggers Telegram alert; verified 0 findings = silence.

© Szotasz, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files in seed-scheduled-tasks/bumblebee-hygiene-scan of Szotasz/marveen.

  • SKILL.md
  • task-config.json
  • threat-intel/antv-mini-shai-hulud.json
  • threat-intel/gemstuffer.json
  • threat-intel/mini-shai-hulud.json
  • threat-intel/node-ipc-credential-stealer.json
  • threat-intel/nx-console-vscode-2026-05-18.json
  • threat-intel/shopsprint-decimal-typosquat.json

Open the folder on GitHubat commit e1ac6cc

Compare with similar skills

Bumblebee Hygiene Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bumblebee Hygiene Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bumblebee Hygiene Scan this skillSzotasz/marveen117—~2.1kAutomated safety check: PassMIT
Perplexity Web MCP Bridgejacob-bd/perplexity-web-mcp198—~7.6kAutomated safety check: PassMIT
Scrapingbee CLIScrapingBee/scrapingbee-cli108—~3.2kAutomated safety check: NotesMIT
Zapier Workflowsdavila7/claude-code-templates33k2 repos~4.9kAutomated safety check: PassMIT
Perplexitydavila7/claude-code-templates33k1 repos~965Automated safety check: PassMIT
Perplexity SearchescapeWu/perplexity-ai171—~1.8kAutomated safety check: PassMIT

Similar skills

  • Perplexity Web MCP Bridge

    jacob-bd/perplexity-web-mcp

    Searches the web and queries premium AI models through Perplexity's own web interface, tracking quota carefully across quick, Pro and Deep Research tiers.

    198 GitHub stars~7.6k tokensUpdated 6 days ago
    Productivity & AutomationAuto-check passed
  • Scrapingbee CLI

    ScrapingBee/scrapingbee-cli

    Fetch and read any web page, search the web, crawl a site, or pull structured data out of pages.

    108 GitHub stars~3.2k tokensUpdated 4 days ago
    Productivity & AutomationAuto-check: notes
  • Zapier Workflows

    davila7/claude-code-templates

    Manage and trigger pre-built Zapier workflows and MCP tool orchestration.

    33k GitHub starsUsed in 2 repos~4.9k tokens
    Productivity & AutomationAuto-check passed
  • Perplexity

    davila7/claude-code-templates

    Web search and research using Perplexity AI. An agent skill from davila7/claude-code-templates.

    33k GitHub starsUsed in 1 repo~965 tokens
    Productivity & AutomationAuto-check passed
  • Perplexity Search

    escapeWu/perplexity-ai

    Searches the live web with citations through perplexity-mcp v2 tools or a bundled Python REST client, with focused ask, deep research and detached tasks.

    171 GitHub stars~1.8k tokensUpdated 14 days ago
    Productivity & AutomationAuto-check passed
  • Google Calendar via Telegram

    k1p1l0/claude-telegram-supercharged

    Manages Google Calendar from a Telegram chat: lists the schedule, creates and updates events, finds free time and sends daily briefings and reminders.

    132 GitHub stars~791 tokensUpdated 15 days ago
    Productivity & AutomationAuto-check passed

More from Szotasz/marveen

All 18 skills in this repo
  • Fleet Helper

    Szotasz/marveen

    Shared, dependency-free Python helpers for the agent fleet - dashboard API (memory, messages, kanban), Telegram MarkdownV2 escaping, and rule-based Mail.app triage.

    117 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • GitHub PR Rebase Merge

    Szotasz/marveen

    Merge a stack of GitHub PRs sequentially when they share files and will cause cascading conflicts.

    117 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Handoff

    Szotasz/marveen

    Generate a HANDOFF.md context transfer document for session continuity.

    117 GitHub stars~1.5k tokensUpdated today
    Auto-check: notes
  • Retrospective

    Szotasz/marveen

    Analyze the current session for improvement opportunities in skills, memory, and workflow.

    117 GitHub stars~1.5k tokensUpdated today
    Auto-check: notes
  • A Marveen Bridge és a "Szolgáltatás-lapok" ajánlása és elmagyarázása a gazdának.

    117 GitHub stars~1.4k tokensUpdated today
    Auto-check: warnings
  • Skill Factory

    Szotasz/marveen

    Turn any workflow, conversation, or demonstrated process into a reusable SKILL.md.

    117 GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Questions about Bumblebee Hygiene Scan

What does Bumblebee Hygiene Scan do?

Weekly supply-chain hygiene scan (Perplexity Bumblebee). An agent skill from Szotasz/marveen. Bumblebee Hygiene Scan is an agent skill from Szotasz/marveen. Weekly supply-chain hygiene scan (Perplexity Bumblebee).

When should I use Bumblebee Hygiene Scan?

Bumblebee Hygiene Scan fits situations like: tasks that involve Supply chain security; tasks that involve Web search; tasks that involve Scheduled and recurring tasks.

How do I install Bumblebee Hygiene Scan in Claude Code?

Run `npx skills add Szotasz/marveen --skill bumblebee-hygiene-scan -a claude-code`. Or copy the skill folder (seed-scheduled-tasks/bumblebee-hygiene-scan in Szotasz/marveen) into .claude/skills/bumblebee-hygiene-scan in your project. Claude Code loads it when a task matches its description.

How do I install Bumblebee Hygiene Scan in Codex?

Run `npx skills add Szotasz/marveen --skill bumblebee-hygiene-scan -a codex`. Or copy the skill folder (seed-scheduled-tasks/bumblebee-hygiene-scan in Szotasz/marveen) into .agents/skills/bumblebee-hygiene-scan in your project. Codex loads it when a task matches its description.

Can I use Bumblebee Hygiene Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Szotasz/marveen --skill bumblebee-hygiene-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bumblebee-hygiene-scan, .gemini/skills/bumblebee-hygiene-scan, .github/skills/bumblebee-hygiene-scan and .opencode/skills/bumblebee-hygiene-scan in your project.

What does Bumblebee Hygiene Scan need to run?

Going by SKILL.md and its folder, Bumblebee Hygiene Scan needs the command-line tools its instructions call (git, python3, go and brew). Our summary lists: Python 3.

Does Bumblebee Hygiene Scan access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Bumblebee Hygiene Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bumblebee Hygiene Scan use?

Bumblebee Hygiene Scan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bumblebee Hygiene Scan use?

About 2.1k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bumblebee Hygiene Scan?

Skills that share tags, products or a category with Bumblebee Hygiene Scan: Perplexity Web MCP Bridge (jacob-bd/perplexity-web-mcp, 198 stars), Scrapingbee CLI (ScrapingBee/scrapingbee-cli, 108 stars), Zapier Workflows (davila7/claude-code-templates, 33k stars) and Perplexity (davila7/claude-code-templates, 33k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bumblebee Hygiene Scan?

Szotasz (a GitHub user) maintains it in Szotasz/marveen, which has 117 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 10, 2026.

Source: Szotasz/marveen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.