Xray Pre Audit
ccashwell/evm-cortex
A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.
Systematic false positive verification for security findings.
$ npx skills add vibeeval/vibecosystem --skill fp-check -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vibeeval/vibecosystem fp-check --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/fp-check .claude/skills/fp-check && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fp-check" agent skill from https://github.com/vibeeval/vibecosystem/tree/main/skills/fp-check into .claude/skills/fp-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fp-check", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vibeeval/vibecosystem/tree/main/skills/fp-checkType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vibeeval/vibecosystem --skill fp-check -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vibeeval/vibecosystem fp-check --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/fp-check .agents/skills/fp-check && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fp-check" agent skill from https://github.com/vibeeval/vibecosystem/tree/main/skills/fp-check into .agents/skills/fp-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fp-check", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vibeeval/vibecosystem --skill fp-check -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vibeeval/vibecosystem fp-check --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/fp-check .cursor/skills/fp-check && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fp-check" agent skill from https://github.com/vibeeval/vibecosystem/tree/main/skills/fp-check into .cursor/skills/fp-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fp-check", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vibeeval/vibecosystem.git --path skills/fp-check--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vibeeval/vibecosystem --skill fp-check -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vibeeval/vibecosystem fp-check --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/fp-check .gemini/skills/fp-check && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fp-check" agent skill from https://github.com/vibeeval/vibecosystem/tree/main/skills/fp-check into .gemini/skills/fp-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fp-check", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vibeeval/vibecosystem fp-checkInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vibeeval/vibecosystem --skill fp-check -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/fp-check .github/skills/fp-check && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fp-check" agent skill from https://github.com/vibeeval/vibecosystem/tree/main/skills/fp-check into .github/skills/fp-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fp-check", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vibeeval/vibecosystem --skill fp-check -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vibeeval/vibecosystem fp-check --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/fp-check .opencode/skills/fp-check && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fp-check" agent skill from https://github.com/vibeeval/vibecosystem/tree/main/skills/fp-check into .opencode/skills/fp-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fp-check", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fp-checkSystematic false positive verification for security findings.
Fp Check is an agent skill from vibeeval/vibecosystem. Systematic false positive verification for security findings. Provides structured methodology to confirm or dismiss scanner results, manual audit findings, and automated alerts. Adapted from Trail of Bits. Use when triaging security scan results or verifying audit findings.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Audit readiness and Security review. The repository describes itself as: AI software team for Claude Code - 138 agents, 295 skills, 73 hooks. Self-learning, multi-agent swarm, autonomous skill evolution. The licence is MIT.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 3b763b1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
TEST_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fp Check loads about 1.6k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 325 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from vibeeval/vibecosystem at commit 3b763b1, republished under its MIT licence (© vibeeval). 325 words, ~1,565 tokens.
.claude/skills/fp-check/SKILL.md (or your agent's skills folder).Not every finding is real. But dismissing a real finding as "false positive" is worse than investigating a false one. This skill provides a systematic approach to verify findings without bias.
Before dismissing anything, attempt to confirm:
FINDING: SQL injection in /api/users
CLAIM: User input reaches database query unsanitized
VERIFICATION:
1. Read the actual code at the reported location
2. Trace the data flow from input to sink
3. Check for sanitization/validation between input and sink
4. Check for framework-level protections (ORM, parameterized queries)
5. Attempt to construct an exploit payload| Verdict | Criteria | Evidence Required |
|---|---|---|
| TRUE POSITIVE | Vulnerability exists and is exploitable | Code path + exploit scenario |
| TRUE POSITIVE (mitigated) | Vulnerability exists but other controls prevent exploitation | Code path + mitigation proof |
| FALSE POSITIVE (provable) | Finding is wrong due to tool limitation | Specific reason why tool was wrong |
| FALSE POSITIVE (contextual) | Code is technically flagged but context makes it safe | Context documentation |
| NEEDS INVESTIGATION | Cannot determine without more analysis | What additional info is needed |
FINDING: [scanner/auditor finding description]
SOURCE: [which tool/person reported it]
LOCATION: file.ts:42
VERDICT: [TRUE POSITIVE | FALSE POSITIVE | NEEDS INVESTIGATION]
EVIDENCE:
- [What you checked]
- [What you found]
- [Why you reached this conclusion]
REASONING:
[Detailed explanation of why this is/isn't a real finding]
CONFIDENCE: [HIGH | MEDIUM | LOW]
[If LOW, explain what would increase confidence]Scanner says: "Hardcoded password detected"
Actual code: const DEFAULT_LABEL = "password"
Verdict: FALSE POSITIVE -- it's a UI label, not a credential
Evidence: Variable is used only in form field label renderingScanner says: "SQL injection in query"
Actual code: db.query("SELECT * FROM users WHERE id = $1", [userId])
Verdict: FALSE POSITIVE -- parameterized query prevents injection
Evidence: $1 is a parameter placeholder, userId is bound safelyScanner says: "XSS in renderUserInput()"
Actual code: renderUserInput() exists but is never called
Verdict: FALSE POSITIVE -- function is dead code
Evidence: grep shows no callers; function should be removed anyway
WARNING: Verify it's truly unreachable, not just unused currentlyScanner says: "Hardcoded API key"
Actual code: const TEST_KEY = "test-key-123" in test/fixtures.ts
Verdict: FALSE POSITIVE -- test fixture, not production code
Evidence: File is in test directory, key is clearly a test value
WARNING: Verify the key isn't a real key used in test environmentScanner says: "Insecure random number generation"
Actual code: Math.random() used for UI animation timing
Verdict: FALSE POSITIVE -- not used for security purposes
Evidence: Used only for visual jitter in animation, no security impactDo NOT dismiss if:
| Red Flag | Why It Matters |
|---|---|
| "It's behind a VPN" | VPNs get compromised, zero trust is the standard |
| "Only admins can reach it" | Admin accounts get compromised |
| "The input is from our other service" | Services can be compromised too |
| "We sanitize it elsewhere" | Verify the "elsewhere" actually runs |
| "It's just a low severity" | Low severity findings chain into high impact |
| "The scanner is always wrong about this" | Verify EACH instance independently |
| "We've never been exploited" | Survivorship bias |
Follow the data from source to sink:
Source (user input) -> [validation?] -> [transformation?] -> [sanitization?] -> Sink (dangerous operation)
If ANY step is missing or bypassable, it's a TRUE POSITIVE.Check all paths to the vulnerable code:
Can the code be reached without authentication?
Can the code be reached with different parameters?
Can the code be reached through an alternative route?Construct a minimal proof:
Input: [specific malicious input]
Expected: [what should happen if vulnerable]
Actual: [what actually happens]
Blocked by: [what prevents exploitation, if anything]# Has this code had real vulnerabilities before?
git log --grep="fix\|vuln\|security\|CVE" -- <file>
# Has the scanner been wrong about this pattern before?
# Check past triage decisions for this ruleFor large scan results:
# Security Scan Triage - [Date]
Scanner: [tool name and version]
Scan target: [repo/branch/commit]
Total findings: [N]
## Summary
| Verdict | Count |
|---------|-------|
| True Positive | X |
| True Positive (mitigated) | X |
| False Positive | X |
| Needs Investigation | X |
## True Positives (Action Required)
1. [SEVERITY] file.ts:42 -- [description] -- [recommended fix]
## False Positives (Documented)
1. file.ts:88 -- [reason it's false positive]
## Needs Investigation
1. file.ts:120 -- [what additional info is needed]Inspired by Trail of Bits fp-check plugin.
© vibeeval, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/fp-check of vibeeval/vibecosystem.
Open the folder on GitHubat commit 3b763b1
Fp Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fp Check this skillvibeeval/vibecosystem | 531 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Xray Pre Auditccashwell/evm-cortex | 131 | — | ~25k | Automated safety check: Pass | MIT | |
| Isms Audit Expertdavila7/claude-code-templates | 32k | 1 repos | ~3.1k | Automated safety check: Pass | MIT | |
| Common LLM SecurityHoangNguyen0403/agent-skills-standard | 571 | — | ~921 | Automated safety check: Pass | MIT | |
| Audit PrepPlamenTSV/plamen | 303 | — | ~3.7k | Automated safety check: Pass | MIT | |
| Deps Vetoliver-kriska/claude-elixir-phoenix | 565 | — | ~1.5k | Automated safety check: Pass | MIT |
ccashwell/evm-cortex
A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.
davila7/claude-code-templates
Senior ISMS Audit Expert for internal and external information security management system auditing.
HoangNguyen0403/agent-skills-standard
OWASP LLM Top 10 (2025) audit checklist for AI applications, agent tools, RAG pipelines, and prompt construction.
PlamenTSV/plamen
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
oliver-kriska/claude-elixir-phoenix
Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner.
oliver-kriska/claude-elixir-phoenix
Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner.
vibeeval/vibecosystem
Framework for measuring and tracking agent response quality over time.
vibeeval/vibecosystem
Security-focused differential code review with blast radius analysis, risk-adaptive depth (DEEP/FOCUSED/SURGICAL), git history correlation, and structured finding format.
vibeeval/vibecosystem
A skill your agent uses when making any factual claim about the codebase — existence, absence, or behavior.
vibeeval/vibecosystem
n8n otomasyon workflow'lari. An agent skill from vibeeval/vibecosystem.
vibeeval/vibecosystem
A skill your agent uses when context compression is imminent, when resuming a session, or when preserving critical decisions across long tasks.
vibeeval/vibecosystem
Property-based testing (PBT) patterns with fast-check (JS/TS), Hypothesis (Python), and gopter (Go).
Categories
Systematic false positive verification for security findings. Fp Check is an agent skill from vibeeval/vibecosystem. Systematic false positive verification for security findings.
Fp Check fits situations like: triaging security scan results; verifying audit findings.
Run `npx skills add vibeeval/vibecosystem --skill fp-check -a claude-code`. Or copy the skill folder (skills/fp-check in vibeeval/vibecosystem) into .claude/skills/fp-check in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vibeeval/vibecosystem --skill fp-check -a codex`. Or copy the skill folder (skills/fp-check in vibeeval/vibecosystem) into .agents/skills/fp-check in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vibeeval/vibecosystem --skill fp-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fp-check, .gemini/skills/fp-check, .github/skills/fp-check and .opencode/skills/fp-check in your project.
Going by SKILL.md and its folder, Fp Check needs the command-line tools its instructions call (git) and credentials named TEST_KEY. Our summary lists: A credential in TEST_KEY.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Fp Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Fp Check: Xray Pre Audit (ccashwell/evm-cortex, 131 stars), Isms Audit Expert (davila7/claude-code-templates, 32k stars), Common LLM Security (HoangNguyen0403/agent-skills-standard, 571 stars) and Audit Prep (PlamenTSV/plamen, 303 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vibeeval (a GitHub user) maintains it in vibeeval/vibecosystem, which has 531 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on August 8, 2026.
Source: vibeeval/vibecosystem on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.