Deepsec Documentation Guide
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
A skill your agent uses when the user wants to audit a codebase for security vulnerabilities, perform a security review, do penetration testing, run a 代码审计 or 安全审查, check for security issues, or…
$ npx skills add Tai609/NebulaMat --skill code-security-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Tai609/NebulaMat code-security-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Tai609/NebulaMat.git skills-src && mkdir -p .claude/skills && cp -r skills-src/runtime/skills-bundle/code-security-audit .claude/skills/code-security-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "code-security-audit" agent skill from https://github.com/Tai609/NebulaMat/tree/main/runtime/skills-bundle/code-security-audit into .claude/skills/code-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-security-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Tai609/NebulaMat/tree/main/runtime/skills-bundle/code-security-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Tai609/NebulaMat --skill code-security-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Tai609/NebulaMat code-security-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Tai609/NebulaMat.git skills-src && mkdir -p .agents/skills && cp -r skills-src/runtime/skills-bundle/code-security-audit .agents/skills/code-security-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "code-security-audit" agent skill from https://github.com/Tai609/NebulaMat/tree/main/runtime/skills-bundle/code-security-audit into .agents/skills/code-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-security-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Tai609/NebulaMat --skill code-security-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Tai609/NebulaMat code-security-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Tai609/NebulaMat.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/runtime/skills-bundle/code-security-audit .cursor/skills/code-security-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "code-security-audit" agent skill from https://github.com/Tai609/NebulaMat/tree/main/runtime/skills-bundle/code-security-audit into .cursor/skills/code-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-security-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Tai609/NebulaMat.git --path runtime/skills-bundle/code-security-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Tai609/NebulaMat --skill code-security-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Tai609/NebulaMat code-security-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Tai609/NebulaMat.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/runtime/skills-bundle/code-security-audit .gemini/skills/code-security-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "code-security-audit" agent skill from https://github.com/Tai609/NebulaMat/tree/main/runtime/skills-bundle/code-security-audit into .gemini/skills/code-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-security-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Tai609/NebulaMat code-security-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Tai609/NebulaMat --skill code-security-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Tai609/NebulaMat.git skills-src && mkdir -p .github/skills && cp -r skills-src/runtime/skills-bundle/code-security-audit .github/skills/code-security-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "code-security-audit" agent skill from https://github.com/Tai609/NebulaMat/tree/main/runtime/skills-bundle/code-security-audit into .github/skills/code-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-security-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Tai609/NebulaMat --skill code-security-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Tai609/NebulaMat code-security-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Tai609/NebulaMat.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/runtime/skills-bundle/code-security-audit .opencode/skills/code-security-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "code-security-audit" agent skill from https://github.com/Tai609/NebulaMat/tree/main/runtime/skills-bundle/code-security-audit into .opencode/skills/code-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-security-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
code-security-auditA skill your agent uses when the user wants to audit a codebase for security vulnerabilities, perform a security review, do penetration testing, run a 代码审计 or 安全审查, check for security issues, or…
Code Security Audit is an agent skill from Tai609/NebulaMat. Use when the user wants to audit a codebase for security vulnerabilities, perform a security review, do penetration testing, run a 代码审计 or 安全审查, check for security issues, or verify that security fixes have been applied. Triggers on phrases like "audit this repo", "security review", "find vulnerabilities", "安全审计", "代码审计", "再审计", "verify fixes", "安全扫描".
Its SKILL.md is about 5.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/audit-report-template.md` and `references/vulnerability-patterns.md`).
It sits in Security, covering Security review. The repository describes itself as: NebulaMat scientific materials research workbench.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c906ed5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Code Security Audit loads about 5.3k tokens when it runs, and up to ~9.2k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 1,935 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
2. .env files, config files that might contain secretsHardcoded keys, .env files, credential storage, logging leaks, .gitignore gaps, git historyAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,935 words (~5,348 tokens).
“Systematic security audit of any codebase using parallel domain exploration. Launch independent review agents across three security domains simultaneously, then synthesize findings into a structured audit report with severity ratings and concrete remediation steps.”
SKILL.md and 2 other files (references) in runtime/skills-bundle/code-security-audit of Tai609/NebulaMat.
Open the folder on GitHubat commit c906ed5
Code Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Code Security Audit this skillTai609/NebulaMat | 100 | — | ~5.3k | Automated safety check: Notes | Custom licence | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Kubernetes Network Security Auditkubeshark/kubeshark | 12k | — | ~7.3k | Automated safety check: Notes | Apache-2.0 | |
| Native Dependency Updatemono/SkiaSharp | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT | |
| Semgrep Security Scantrailofbits/skills | 7.4k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Skillward AuditFangcun-AI/SkillWard | 143 | — | ~2.9k | Automated safety check: Pass | Custom licence |
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
kubeshark/kubeshark
Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.
mono/SkiaSharp
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
Fangcun-AI/SkillWard
Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
Tai609/NebulaMat
Read and transcribe the text visible inside an image file (PNG/JPG/JPEG/WebP/BMP/GIF) using the built-in Windows Media.Ocr OCR engine, with NO external credential or network required.
Tai609/NebulaMat
Create, revise, audit, and export submission-grade scientific figures for Nature-family and other high-impact venues in Python (matplotlib/seaborn) or R (ggplot2/patchwork/ComplexHeatmap), including…
Tai609/NebulaMat
Manage a stateful, run-directory-based proof project with Codex: continuation across runs, run-local source bookkeeping, manual GPT Pro handoff packages when a local attempt stalls, and an optional…
Tai609/NebulaMat
Build provenance-controlled facet-specific electrochemical adsorption model cohorts from MatterGen candidates after MatterSim relaxation, including slab terminations, adsorption sites and…
Tai609/NebulaMat
Generate auditable candidate crystal structures with the project's pinned MatterGen runtime, including request construction, model/conditioning selection, GPU-cost bounds, workspace-safe output…
Tai609/NebulaMat
Run governed MatterSim-v1.0.0-5M energy, force, stress, and optional ASE FIRE relaxation for workspace-local standardized structures.
Categories
A skill your agent uses when the user wants to audit a codebase for security vulnerabilities, perform a security review, do penetration testing, run a 代码审计 or 安全审查, check for security issues, or…. Code Security Audit is an agent skill from Tai609/NebulaMat. Use when the user wants to audit a codebase for security vulnerabilities, perform a security review, do penetration testing, run a 代码审计 or 安全审查, check for security issues, or verify that security fixes have been applied.
Code Security Audit fits situations like: the user wants to audit a codebase for security vulnerabilities; perform a security review; do penetration testing; check for security issues.
Run `npx skills add Tai609/NebulaMat --skill code-security-audit -a claude-code`. Or copy the skill folder (runtime/skills-bundle/code-security-audit in Tai609/NebulaMat) into .claude/skills/code-security-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Tai609/NebulaMat --skill code-security-audit -a codex`. Or copy the skill folder (runtime/skills-bundle/code-security-audit in Tai609/NebulaMat) into .agents/skills/code-security-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Tai609/NebulaMat --skill code-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-security-audit, .gemini/skills/code-security-audit, .github/skills/code-security-audit and .opencode/skills/code-security-audit in your project.
Going by SKILL.md and its folder, Code Security Audit needs the command-line tools its instructions call (git). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Code Security Audit has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.
About 5.3k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Code Security Audit: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Semgrep Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Tai609 (a GitHub user) maintains it in Tai609/NebulaMat, which has 100 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 6, 2026.
Source: Tai609/NebulaMat on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.