Agent skill

Fp Check

by vibeeval in vibeeval/vibecosystem

Systematic false positive verification for security findings.

MITAuto-check passedSecurity

Install Fp Check

skills CLI
$ npx skills add vibeeval/vibecosystem --skill fp-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vibeeval/vibecosystem fp-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/fp-check .claude/skills/fp-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fp-check
GitHub stars
531
Token cost
~1.6k tokens
SKILL.md length
325 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

Systematic false positive verification for security findings.

  • Works in 12 steps: Reproduce the Claim → Evidence-Based Triage → Document the Decision → …
  • Triaging security scan results
  • SKILL.md covers Verification Process, Common False Positive Patterns, Red Flags: When "False… and Verification Techniques, plus 2 more sections
  • Calls git; needs TEST_KEY

What it does

Fp Check is an agent skill from vibeeval/vibecosystem. Systematic false positive verification for security findings. Provides structured methodology to confirm or dismiss scanner results, manual audit findings, and automated alerts. Adapted from Trail of Bits. Use when triaging security scan results or verifying audit findings.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Audit readiness and Security review. The repository describes itself as: AI software team for Claude Code - 138 agents, 295 skills, 73 hooks. Self-learning, multi-agent swarm, autonomous skill evolution. The licence is MIT.

When your agent uses it

  • Triaging security scan results
  • Verifying audit findings

Example prompts

  • “/fp-check”

Requirements

  • A credential in TEST_KEY

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Reproduce the Claim
  2. Evidence-Based Triage
  3. Document the Decision
  4. Scanner Doesn't Understand Context
  5. Framework Protection Not Recognized
  6. Dead Code / Unreachable Path
  7. Test Code Flagged
  8. Intentional Behavior
  9. Data Flow Tracing
  10. Control Flow Analysis
  11. Exploit Attempt
  12. Historical Check

What it can do on your machine

Read from SKILL.md and the folder at commit 3b763b1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • TEST_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fp Check loads about 1.6k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 325 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vibeeval/vibecosystem at commit 3b763b1, republished under its MIT licence (© vibeeval). 325 words, ~1,565 tokens.

Download SKILL.mdSave it as .claude/skills/fp-check/SKILL.md (or your agent's skills folder).
name
fp-check
description
Systematic false positive verification for security findings. Provides structured methodology to confirm or dismiss scanner results, manual audit findings, and automated alerts. Adapted from Trail of Bits. Use when triaging security scan results or verifying audit findings.

False Positive Verification

Not every finding is real. But dismissing a real finding as "false positive" is worse than investigating a false one. This skill provides a systematic approach to verify findings without bias.

Verification Process

Step 1: Reproduce the Claim

Before dismissing anything, attempt to confirm:

FINDING: SQL injection in /api/users
CLAIM: User input reaches database query unsanitized

VERIFICATION:
1. Read the actual code at the reported location
2. Trace the data flow from input to sink
3. Check for sanitization/validation between input and sink
4. Check for framework-level protections (ORM, parameterized queries)
5. Attempt to construct an exploit payload
Step 2: Evidence-Based Triage
VerdictCriteriaEvidence Required
TRUE POSITIVEVulnerability exists and is exploitableCode path + exploit scenario
TRUE POSITIVE (mitigated)Vulnerability exists but other controls prevent exploitationCode path + mitigation proof
FALSE POSITIVE (provable)Finding is wrong due to tool limitationSpecific reason why tool was wrong
FALSE POSITIVE (contextual)Code is technically flagged but context makes it safeContext documentation
NEEDS INVESTIGATIONCannot determine without more analysisWhat additional info is needed
Step 3: Document the Decision
FINDING: [scanner/auditor finding description]
SOURCE: [which tool/person reported it]
LOCATION: file.ts:42

VERDICT: [TRUE POSITIVE | FALSE POSITIVE | NEEDS INVESTIGATION]

EVIDENCE:
  - [What you checked]
  - [What you found]
  - [Why you reached this conclusion]

REASONING:
  [Detailed explanation of why this is/isn't a real finding]

CONFIDENCE: [HIGH | MEDIUM | LOW]
  [If LOW, explain what would increase confidence]

Common False Positive Patterns

1. Scanner Doesn't Understand Context
Scanner says: "Hardcoded password detected"
Actual code: const DEFAULT_LABEL = "password"
Verdict: FALSE POSITIVE -- it's a UI label, not a credential
Evidence: Variable is used only in form field label rendering
2. Framework Protection Not Recognized
Scanner says: "SQL injection in query"
Actual code: db.query("SELECT * FROM users WHERE id = $1", [userId])
Verdict: FALSE POSITIVE -- parameterized query prevents injection
Evidence: $1 is a parameter placeholder, userId is bound safely
3. Dead Code / Unreachable Path
Scanner says: "XSS in renderUserInput()"
Actual code: renderUserInput() exists but is never called
Verdict: FALSE POSITIVE -- function is dead code
Evidence: grep shows no callers; function should be removed anyway
WARNING: Verify it's truly unreachable, not just unused currently
4. Test Code Flagged
Scanner says: "Hardcoded API key"
Actual code: const TEST_KEY = "test-key-123" in test/fixtures.ts
Verdict: FALSE POSITIVE -- test fixture, not production code
Evidence: File is in test directory, key is clearly a test value
WARNING: Verify the key isn't a real key used in test environment
5. Intentional Behavior
Scanner says: "Insecure random number generation"
Actual code: Math.random() used for UI animation timing
Verdict: FALSE POSITIVE -- not used for security purposes
Evidence: Used only for visual jitter in animation, no security impact

Red Flags: When "False Positive" Is Actually Real

Do NOT dismiss if:

Red FlagWhy It Matters
"It's behind a VPN"VPNs get compromised, zero trust is the standard
"Only admins can reach it"Admin accounts get compromised
"The input is from our other service"Services can be compromised too
"We sanitize it elsewhere"Verify the "elsewhere" actually runs
"It's just a low severity"Low severity findings chain into high impact
"The scanner is always wrong about this"Verify EACH instance independently
"We've never been exploited"Survivorship bias

Verification Techniques

1. Data Flow Tracing

Follow the data from source to sink:

Source (user input) -> [validation?] -> [transformation?] -> [sanitization?] -> Sink (dangerous operation)

If ANY step is missing or bypassable, it's a TRUE POSITIVE.
2. Control Flow Analysis

Check all paths to the vulnerable code:

Can the code be reached without authentication?
Can the code be reached with different parameters?
Can the code be reached through an alternative route?
3. Exploit Attempt

Construct a minimal proof:

Input: [specific malicious input]
Expected: [what should happen if vulnerable]
Actual: [what actually happens]
Blocked by: [what prevents exploitation, if anything]
4. Historical Check
bash
# Has this code had real vulnerabilities before?
git log --grep="fix\|vuln\|security\|CVE" -- <file>

# Has the scanner been wrong about this pattern before?
# Check past triage decisions for this rule

Batch Triage Template

For large scan results:

markdown
# Security Scan Triage - [Date]

Scanner: [tool name and version]
Scan target: [repo/branch/commit]
Total findings: [N]

## Summary
| Verdict | Count |
|---------|-------|
| True Positive | X |
| True Positive (mitigated) | X |
| False Positive | X |
| Needs Investigation | X |

## True Positives (Action Required)
1. [SEVERITY] file.ts:42 -- [description] -- [recommended fix]

## False Positives (Documented)
1. file.ts:88 -- [reason it's false positive]

## Needs Investigation
1. file.ts:120 -- [what additional info is needed]

Integration with vibecosystem

  • security-reviewer agent: Use fp-check after running security scans
  • sast-scanner agent: Triage Semgrep results with this methodology
  • code-reviewer agent: When flagging potential issues, verify first
  • verifier agent: Include false positive check in quality gate

Inspired by Trail of Bits fp-check plugin.

© vibeeval, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/fp-check of vibeeval/vibecosystem.

Open the folder on GitHubat commit 3b763b1

Compare with similar skills

Fp Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fp Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fp Check this skillvibeeval/vibecosystem531—~1.6kAutomated safety check: PassMIT
Xray Pre Auditccashwell/evm-cortex131—~25kAutomated safety check: PassMIT
Isms Audit Expertdavila7/claude-code-templates32k1 repos~3.1kAutomated safety check: PassMIT
Common LLM SecurityHoangNguyen0403/agent-skills-standard571—~921Automated safety check: PassMIT
Audit PrepPlamenTSV/plamen303—~3.7kAutomated safety check: PassMIT
Deps Vetoliver-kriska/claude-elixir-phoenix565—~1.5kAutomated safety check: PassMIT

Similar skills

  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Isms Audit Expert

    davila7/claude-code-templates

    Senior ISMS Audit Expert for internal and external information security management system auditing.

    32k GitHub starsUsed in 1 repo~3.1k tokens
    SecurityAuto-check passed
  • Common LLM Security

    HoangNguyen0403/agent-skills-standard

    OWASP LLM Top 10 (2025) audit checklist for AI applications, agent tools, RAG pipelines, and prompt construction.

    571 GitHub stars~921 tokensUpdated today
    SecurityAuto-check passed
  • Audit Prep

    PlamenTSV/plamen

    Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

    303 GitHub stars~3.7k tokensUpdated 13 days ago
    SecurityAuto-check passed
  • Deps Vet

    oliver-kriska/claude-elixir-phoenix

    Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner.

    565 GitHub stars~1.5k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Phx Deps Vet

    oliver-kriska/claude-elixir-phoenix

    Record a vetted Hex package version in hexvet.exs after a security review — manages the audit ledger, not the scanner.

    565 GitHub stars~1.5k tokensUpdated 4 days ago
    SecurityAuto-check passed

More from vibeeval/vibecosystem

All 12 skills in this repo
  • Agent Benchmark

    vibeeval/vibecosystem

    Framework for measuring and tracking agent response quality over time.

    531 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Differential Review

    vibeeval/vibecosystem

    Security-focused differential code review with blast radius analysis, risk-adaptive depth (DEEP/FOCUSED/SURGICAL), git history correlation, and structured finding format.

    531 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Factcheck Guard

    vibeeval/vibecosystem

    A skill your agent uses when making any factual claim about the codebase — existence, absence, or behavior.

    531 GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check passed
  • N8n Workflows

    vibeeval/vibecosystem

    n8n otomasyon workflow'lari. An agent skill from vibeeval/vibecosystem.

    531 GitHub stars~3.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Notepad System

    vibeeval/vibecosystem

    A skill your agent uses when context compression is imminent, when resuming a session, or when preserving critical decisions across long tasks.

    531 GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Property Based Testing

    vibeeval/vibecosystem

    Property-based testing (PBT) patterns with fast-check (JS/TS), Hypothesis (Python), and gopter (Go).

    531 GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Fp Check

What does Fp Check do?

Systematic false positive verification for security findings. Fp Check is an agent skill from vibeeval/vibecosystem. Systematic false positive verification for security findings.

When should I use Fp Check?

Fp Check fits situations like: triaging security scan results; verifying audit findings.

How do I install Fp Check in Claude Code?

Run `npx skills add vibeeval/vibecosystem --skill fp-check -a claude-code`. Or copy the skill folder (skills/fp-check in vibeeval/vibecosystem) into .claude/skills/fp-check in your project. Claude Code loads it when a task matches its description.

How do I install Fp Check in Codex?

Run `npx skills add vibeeval/vibecosystem --skill fp-check -a codex`. Or copy the skill folder (skills/fp-check in vibeeval/vibecosystem) into .agents/skills/fp-check in your project. Codex loads it when a task matches its description.

Can I use Fp Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vibeeval/vibecosystem --skill fp-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fp-check, .gemini/skills/fp-check, .github/skills/fp-check and .opencode/skills/fp-check in your project.

What does Fp Check need to run?

Going by SKILL.md and its folder, Fp Check needs the command-line tools its instructions call (git) and credentials named TEST_KEY. Our summary lists: A credential in TEST_KEY.

Does Fp Check access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Fp Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fp Check use?

Fp Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fp Check use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fp Check?

Skills that share tags, products or a category with Fp Check: Xray Pre Audit (ccashwell/evm-cortex, 131 stars), Isms Audit Expert (davila7/claude-code-templates, 32k stars), Common LLM Security (HoangNguyen0403/agent-skills-standard, 571 stars) and Audit Prep (PlamenTSV/plamen, 303 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fp Check?

vibeeval (a GitHub user) maintains it in vibeeval/vibecosystem, which has 531 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on August 8, 2026.

Source: vibeeval/vibecosystem on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.