Commit Security Scan
codexstar69/bug-hunter
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
$ npx skills add trilwu/secskills --skill auditing-code-for-vulnerabilities -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills auditing-code-for-vulnerabilities --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/auditing-code-for-vulnerabilities .claude/skills/auditing-code-for-vulnerabilities && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "auditing-code-for-vulnerabilities" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/auditing-code-for-vulnerabilities into .claude/skills/auditing-code-for-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-code-for-vulnerabilities", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-core/skills/auditing-code-for-vulnerabilitiesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill auditing-code-for-vulnerabilities -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills auditing-code-for-vulnerabilities --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-core/skills/auditing-code-for-vulnerabilities .agents/skills/auditing-code-for-vulnerabilities && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "auditing-code-for-vulnerabilities" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/auditing-code-for-vulnerabilities into .agents/skills/auditing-code-for-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-code-for-vulnerabilities", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill auditing-code-for-vulnerabilities -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills auditing-code-for-vulnerabilities --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-core/skills/auditing-code-for-vulnerabilities .cursor/skills/auditing-code-for-vulnerabilities && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "auditing-code-for-vulnerabilities" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/auditing-code-for-vulnerabilities into .cursor/skills/auditing-code-for-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-code-for-vulnerabilities", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-core/skills/auditing-code-for-vulnerabilities--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill auditing-code-for-vulnerabilities -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills auditing-code-for-vulnerabilities --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-core/skills/auditing-code-for-vulnerabilities .gemini/skills/auditing-code-for-vulnerabilities && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "auditing-code-for-vulnerabilities" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/auditing-code-for-vulnerabilities into .gemini/skills/auditing-code-for-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-code-for-vulnerabilities", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills auditing-code-for-vulnerabilitiesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill auditing-code-for-vulnerabilities -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-core/skills/auditing-code-for-vulnerabilities .github/skills/auditing-code-for-vulnerabilities && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "auditing-code-for-vulnerabilities" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/auditing-code-for-vulnerabilities into .github/skills/auditing-code-for-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-code-for-vulnerabilities", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill auditing-code-for-vulnerabilities -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills auditing-code-for-vulnerabilities --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-core/skills/auditing-code-for-vulnerabilities .opencode/skills/auditing-code-for-vulnerabilities && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "auditing-code-for-vulnerabilities" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-core/skills/auditing-code-for-vulnerabilities into .opencode/skills/auditing-code-for-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auditing-code-for-vulnerabilities", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
auditing-code-for-vulnerabilitiesAudit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
Auditing Code For Vulnerabilities is an agent skill from trilwu/secskills. Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis. Use when reviewing a codebase or diff for security bugs, performing a security audit, hunting for vulnerabilities in a target's source, or validating whether a suspected finding is real.
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/bug-class-checklist.md`).
It sits in Security, covering Threat modeling and Security review. It works with PHP. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
rggitsemgrepcargonpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Auditing Code For Vulnerabilities loads about 3.2k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 90 tokens; SKILL.md has 1,426 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,426 words, ~3,203 tokens.
.claude/skills/auditing-code-for-vulnerabilities/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Finding real bugs in source code is a different job from running a scanner. A scanner matches patterns; an auditor builds a model of what the code is supposed to guarantee and then hunts for the paths where that guarantee breaks. This skill is the methodology for the second job.
testing-web-applications or testing-apisauditing-php-applicationshunting-web-backdoorsanalyzing-binariesauditing-supply-chainreviewing-cryptographyreporting-security-findingsorchestrating-vulnerability-research, which dispatches this skill as the
per-slice hunterAuditing is four passes, not one. Do not skip to pass 3.
1. Context → what does this system protect, and from whom?
2. Attack surface → where does untrusted input enter, and what does it reach?
3. Hunt → trace specific bug classes along those paths
4. Verify → prove exploitability before you write a wordDo not open files at random. Spend the first block of effort answering:
| Question | Where to look |
|---|---|
| What are the security-relevant assets? | README, docs, data models, DB schema |
| Who are the actors and trust tiers? | Auth middleware, role enums, tenant models |
| What are the stated invariants? | Tests, assertions, comments containing "must", "never", "invariant" |
| What has already been fixed here? | git log --grep for security keywords, CVE files, SECURITY.md |
| What is out of scope? | Engagement brief, vendor code, generated files |
# Prior security work is the cheapest source of bug leads
git log --oneline --grep='security\|CVE\|vuln\|injection\|auth bypass\|overflow' -i | head -40
# Stated invariants often mark where the author was nervous
rg -n --stats 'MUST NOT|must never|SECURITY|XXX|HACK|TODO.*(auth|secur|valid)' -i
# Where does privilege actually get checked?
rg -n 'is_admin|require_role|authorize|has_permission|@login_required|checkAccess'Write a short target model before hunting: assets, actors, trust boundaries, and the three invariants whose violation would matter most. Everything after this is a search for counterexamples to those invariants.
Enumerate entry points, then rank them. An entry point matters in proportion to how far it reaches before it is validated.
# HTTP/RPC routes
rg -n '@(app|router)\.(get|post|put|delete|patch)|app\.(get|post)\(|@RequestMapping|http\.HandleFunc'
# Deserialization, template rendering, and dynamic execution sinks
rg -n 'pickle\.loads|yaml\.load\(|Marshal|unserialize|ObjectInputStream|eval\(|new Function|exec\(|Runtime\.getRuntime'
# Command, SQL, and path sinks
rg -n 'os\.system|subprocess.*shell\s*=\s*True|child_process\.exec\(|execSync|Statement\.execute|\.raw\(|fmt\.Sprintf.*SELECT'
# Where authentication is decided rather than enforced
rg -n 'verify=False|InsecureSkipVerify|jwt\.decode\(.*verify.*False|algorithms=\[.*none'Rank entry points by: reachable without authentication > reachable by a low privilege tier > reachable only by an admin. Then follow the highest-ranked ones inward. Depth beats breadth — one fully traced path is worth twenty grep hits.
Grep hits are candidates, not findings. The commands above are a cheap wide
net; each match is an unresolved lead until you have traced it. Persist the
candidate set — a worklist of (file:line, bug class, entry point) — and drive
every entry to an explicit verdict: traced-safe, confirmed, or needs-PoC.
Widen the net cheaply, then spend expensive reasoning per candidate — never the
reverse. The failure mode is not a missing grep pattern; it is enumerating
fifty candidates, eyeballing five, and calling the tree clean. On a large
codebase, fold the project's own conventions into the net — its ORM's raw-query
escape hatch, its auth decorator's name, its templating call — because the
highest-yield sinks are the ones generic patterns miss.
For each promising path, trace taint from source to sink and ask what the code assumes. The high-yield classes, in rough order of how often they survive to production:
Authorization, not authentication. Most real breaches are missing object level checks, not broken login. For every handler that takes an ID, ask: is the object scoped to the caller's tenant/user, or only looked up by ID? Check the query, not the decorator.
Trust-boundary confusion. Data validated at one layer and re-parsed at another. Look for values that cross a serialization boundary — a validated string re-parsed as a URL, a path, a template, or a query.
State and concurrency. Check-then-use gaps, non-atomic balance updates, idempotency keys that are not actually unique, retry paths that replay side effects. Search for reads followed by writes with no lock or transaction.
Injection into a secondary interpreter. SQL, shell, LDAP, XPath, template engines, log formats, and regex. The question is never "is there a filter" but "does the filter and the interpreter agree on the grammar."
Memory safety (C/C++/unsafe Rust/CGo). Length arithmetic before bounds
checks, memcpy with an attacker-influenced size, off-by-one in loop bounds,
signed/unsigned conversions, use-after-free on error paths.
Error and cleanup paths. The happy path is usually reviewed; the except,
catch, defer, and goto fail branches are not. Audit them specifically.
Secrets and cryptographic misuse. Hardcoded keys, non-constant-time
comparison of tokens, predictable IDs from Math.random/rand(), missing
signature verification. Deep crypto review belongs in reviewing-cryptography.
A bug is a template, not an incident. When you confirm one, immediately search for its siblings — the same mistake made by the same author, the same copied block, the same missing check on a neighbouring route.
# You found one unscoped lookup. Find every other one.
rg -n 'find_by_id|findOne\(\{ *_id|get_object_or_404' -A3 | rg -v 'tenant|owner|user_id'Variant analysis is where audits produce disproportionate value. Budget time for it explicitly — roughly one unit of variant search per confirmed finding.
A finding you cannot demonstrate is a hypothesis. Before it goes in the report, answer all four:
POST /api/export unauthenticated."If a proof of concept is in scope, write the smallest one that proves control of the sink — not a weaponized exploit.
The four checks above confirm a finding; this pass tries to kill it. Run it on every confirmed candidate before it reaches the report — a report's credibility is set by its worst false positive, not its best true finding.
Is it already fixed? The tree you are reading may lag the fix, or the fix may sit on a branch you have not pulled. Confirm the vulnerable code is what actually ships before you file it.
git log -S'<dangerous token>' --oneline -- <file> # when this line changed, and toward what
git log --oneline <checkout>..origin/main -- <file> # a fix on main you are not reading
git blame -L <line>,<line> <file> # the commit that introduced it, for contextRe-derive it adversarially. Argue the opposite case: assume the code is safe and go find the control that makes it so — the middleware, the DB constraint, the caller that already sanitizes. A finding that survives a genuine attempt to disprove it is one you can defend.
Confirm the sink still receives your value. Re-trace the last hop. A refactor often slips a validator or an encoder between source and sink that a first read glides past.
Drop what dies here, and say so in your coverage notes. A candidate you cannot revalidate is a note to yourself, not a finding.
These are the thoughts that turn an audit into a formality. Each one is wrong.
Static analysis is for coverage and for variant search after you know the pattern. Write a rule once you have a confirmed bug, and let it find the rest.
# Semgrep: broad pass, then a rule you write for your specific finding
semgrep --config=auto --severity=ERROR --json -o semgrep.json .
semgrep --config=./rules/my-variant-rule.yaml .
# CodeQL for dataflow questions grep cannot answer
codeql database create db --language=<lang> && codeql database analyze db --format=sarif-latest -o out.sarif
# Language-specific
bandit -r . -f json # Python
gosec -fmt=json ./... # Go
cargo audit && cargo geiger # Rust deps + unsafe surface
npm audit --json # JS depsTriage every tool finding through the four verification questions above. A report of unverified scanner output is worse than no report — it burns the reader's trust and buries the real bugs.
Track coverage as you go, and state it honestly:
## Coverage
| Component | Files | Depth | Notes |
|-----------|-------|------------|--------------------------------|
| auth/ | 12 | Full trace | All routes traced to sinks |
| billing/ | 30 | Partial | Webhook handlers only |
| vendor/ | - | Excluded | Out of scope per brief |
## Findings
F1. [High] Tenant isolation bypass in GET /api/reports/:id — <impact> — <repro>Say what you did not cover. An audit that claims full coverage it did not achieve is the most damaging artifact you can produce.
references/bug-class-checklist.md — per-language hunting checklistsreporting-security-findings — severity scoring and write-up format© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in secskills-core/skills/auditing-code-for-vulnerabilities of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Auditing Code For Vulnerabilities next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Auditing Code For Vulnerabilities this skilltrilwu/secskills | 156 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Commit Security Scancodexstar69/bug-hunter | 519 | — | ~629 | Automated safety check: Pass | MIT | |
| Threat Mitigation Mappingwshobson/agents | 40k | 8 repos | ~742 | Automated safety check: Pass | MIT | |
| Audit Browser Security Boundariesnordstjernen-web/northstar-browser | 116 | — | ~920 | Automated safety check: Pass | GPL-3.0 | |
| Security Auditblueberrycongee/termcanvas | 406 | — | ~966 | Automated safety check: Notes | MIT | |
| Security Reviewcodexstar69/bug-hunter | 519 | — | ~567 | Automated safety check: Pass | MIT |
codexstar69/bug-hunter
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.
wshobson/agents
Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.
nordstjernen-web/northstar-browser
Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.
blueberrycongee/termcanvas
Security audit skill. An agent skill from blueberrycongee/termcanvas.
codexstar69/bug-hunter
Run a focused STRIDE-based security review using Bug Hunter-native artifacts.
Factory-AI/factory-plugins
Analyze code changes for security vulnerabilities using LLM reasoning and threat model patterns.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
trilwu/secskills
Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring.
Works with
Categories
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis. Auditing Code For Vulnerabilities is an agent skill from trilwu/secskills. Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
Auditing Code For Vulnerabilities fits situations like: reviewing a codebase; diff for security bugs; performing a security audit; hunting for vulnerabilities in a targets source.
Run `npx skills add trilwu/secskills --skill auditing-code-for-vulnerabilities -a claude-code`. Or copy the skill folder (secskills-core/skills/auditing-code-for-vulnerabilities in trilwu/secskills) into .claude/skills/auditing-code-for-vulnerabilities in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill auditing-code-for-vulnerabilities -a codex`. Or copy the skill folder (secskills-core/skills/auditing-code-for-vulnerabilities in trilwu/secskills) into .agents/skills/auditing-code-for-vulnerabilities in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill auditing-code-for-vulnerabilities -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auditing-code-for-vulnerabilities, .gemini/skills/auditing-code-for-vulnerabilities, .github/skills/auditing-code-for-vulnerabilities and .opencode/skills/auditing-code-for-vulnerabilities in your project.
Going by SKILL.md and its folder, Auditing Code For Vulnerabilities needs the command-line tools its instructions call (rg, git, semgrep, cargo and npm). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Auditing Code For Vulnerabilities is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Auditing Code For Vulnerabilities: Commit Security Scan (codexstar69/bug-hunter, 519 stars), Threat Mitigation Mapping (wshobson/agents, 40k stars), Audit Browser Security Boundaries (nordstjernen-web/northstar-browser, 116 stars) and Security Audit (blueberrycongee/termcanvas, 406 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 156 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.