Finishing a Development Branch
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
Assess an immutable patch artifact's program impact, regression risk, and auto-merge eligibility.
$ npx skills add vlinx-io/VelaTerm --skill assess-patch-risk -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vlinx-io/VelaTerm assess-patch-risk --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vlinx-io/VelaTerm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src-tauri/resources/codex-security/skills/assess-patch-risk .claude/skills/assess-patch-risk && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "assess-patch-risk" agent skill from https://github.com/vlinx-io/VelaTerm/tree/dev/src-tauri/resources/codex-security/skills/assess-patch-risk into .claude/skills/assess-patch-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "assess-patch-risk", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vlinx-io/VelaTerm/tree/dev/src-tauri/resources/codex-security/skills/assess-patch-riskType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vlinx-io/VelaTerm --skill assess-patch-risk -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vlinx-io/VelaTerm assess-patch-risk --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vlinx-io/VelaTerm.git skills-src && mkdir -p .agents/skills && cp -r skills-src/src-tauri/resources/codex-security/skills/assess-patch-risk .agents/skills/assess-patch-risk && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "assess-patch-risk" agent skill from https://github.com/vlinx-io/VelaTerm/tree/dev/src-tauri/resources/codex-security/skills/assess-patch-risk into .agents/skills/assess-patch-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "assess-patch-risk", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vlinx-io/VelaTerm --skill assess-patch-risk -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vlinx-io/VelaTerm assess-patch-risk --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vlinx-io/VelaTerm.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/src-tauri/resources/codex-security/skills/assess-patch-risk .cursor/skills/assess-patch-risk && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "assess-patch-risk" agent skill from https://github.com/vlinx-io/VelaTerm/tree/dev/src-tauri/resources/codex-security/skills/assess-patch-risk into .cursor/skills/assess-patch-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "assess-patch-risk", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vlinx-io/VelaTerm.git --path src-tauri/resources/codex-security/skills/assess-patch-risk--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vlinx-io/VelaTerm --skill assess-patch-risk -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vlinx-io/VelaTerm assess-patch-risk --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vlinx-io/VelaTerm.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/src-tauri/resources/codex-security/skills/assess-patch-risk .gemini/skills/assess-patch-risk && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "assess-patch-risk" agent skill from https://github.com/vlinx-io/VelaTerm/tree/dev/src-tauri/resources/codex-security/skills/assess-patch-risk into .gemini/skills/assess-patch-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "assess-patch-risk", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vlinx-io/VelaTerm assess-patch-riskInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vlinx-io/VelaTerm --skill assess-patch-risk -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vlinx-io/VelaTerm.git skills-src && mkdir -p .github/skills && cp -r skills-src/src-tauri/resources/codex-security/skills/assess-patch-risk .github/skills/assess-patch-risk && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "assess-patch-risk" agent skill from https://github.com/vlinx-io/VelaTerm/tree/dev/src-tauri/resources/codex-security/skills/assess-patch-risk into .github/skills/assess-patch-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "assess-patch-risk", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vlinx-io/VelaTerm --skill assess-patch-risk -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vlinx-io/VelaTerm assess-patch-risk --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vlinx-io/VelaTerm.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/src-tauri/resources/codex-security/skills/assess-patch-risk .opencode/skills/assess-patch-risk && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "assess-patch-risk" agent skill from https://github.com/vlinx-io/VelaTerm/tree/dev/src-tauri/resources/codex-security/skills/assess-patch-risk into .opencode/skills/assess-patch-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "assess-patch-risk", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
assess-patch-riskAssess an immutable patch artifact's program impact, regression risk, and auto-merge eligibility.
Assess Patch Risk is an agent skill from vlinx-io/VelaTerm. Assess an immutable patch artifact's program impact, regression risk, and auto-merge eligibility. Use for generated patch files, provider pull-request diffs, or commit ranges when reviewers need evidence about affected runtime paths, contracts, tests, and recoverability. This skill is read-only and does not generate, edit, apply, push, or merge the patch.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `agents/openai.yaml`, `references/risk-rubric.md` and `scripts/validate_patch_risk_assessment.py`).
It sits in Development, covering Pull requests. The repository describes itself as: VelaTerm = Codex + iTerm2, The Best ADE for AI Coding. The licence is MIT.
10 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 98b5f2f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Assess Patch Risk loads about 2.1k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 1,073 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from vlinx-io/VelaTerm at commit 98b5f2f, republished under its MIT licence (© vlinx-io). 1,073 words, ~2,139 tokens.
.claude/skills/assess-patch-risk/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Explain what can change if the patch merges and whether the available evidence supports merging it. Keep these concepts separate:
Read references/risk-rubric.md before assigning ratings or an auto-merge label.
hold_for_evidence if the artifact is incomplete or its identity changes. Do not assess a mutable raw working tree directly; require the caller to provide an immutable patch artifact instead.no_op when evidence proves no live effect, wrong ownership, duplication, or supersession. Describe rollback, persistent-state effects, migrations, and operational recovery. Report the risk of not merging separately; use unknown when motivating context is unavailable.hold_for_evidence with at most three concrete actions, the evidence each action seeks, and how each possible result changes the recommendation. Do not wait or poll indefinitely.Return exactly one recommendation:
merge: source evidence supports the patch and no decision-critical defect or unknown remains;revise: the patch, its tests, or a material documentation contract must change;no_op: evidence shows the patch has no required live effect or belongs elsewhere;block: affirmative evidence establishes a material safety failure; orhold_for_evidence: unavailable evidence can still change the decision.Return a workflow label with every recommendation. For merge, choose:
auto_merge_candidate: every strict gate in the rubric passes; orhuman_review_required: the patch is mergeable but does not qualify for automatic merge.For revise, no_op, block, or hold_for_evidence, use the recommendation itself as the workflow label.
The label is advisory. It never grants permission to merge or overrides repository policy, required checks, or ownership review.
Return both a concise Markdown report and a JSON object conforming to ../../schemas/patch-risk-assessment.schema.json. Include:
This skill lives at <plugin-root>/skills/assess-patch-risk/SKILL.md, so <plugin-root> is two directories up. Resolve <python_command> to the configured Python interpreter ("$PYTHON" in POSIX shells or & "$env:PYTHON" in PowerShell), otherwise use python on Windows and python3 on Unix-like hosts.
Before returning the result, validate the JSON from any working directory with:
<python_command> <plugin-root>/skills/assess-patch-risk/scripts/validate_patch_risk_assessment.py <assessment.json>Pass - as <assessment.json> to read the assessment from standard input without creating a file.
Correct structural or invariant errors by revisiting the evidence; never change a recommendation merely to make validation pass. Return the validated JSON in the response. Write it to disk only when the caller requests an artifact, and keep every assessment-created file outside the subject checkout and its Git directories.
Keep the explanation evidence-backed. Patch size, caller count, green CI, or test count alone never proves low risk.
hold_for_evidence for an already established defect; use revise or block.© vlinx-io, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in src-tauri/resources/codex-security/skills/assess-patch-risk of vlinx-io/VelaTerm.
Open the folder on GitHubat commit 98b5f2f
Assess Patch Risk next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Assess Patch Risk this skillvlinx-io/VelaTerm | 270 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Finishing a Development Branchobra/superpowers | 296k | 5 repos | ~1.9k | Automated safety check: Pass | MIT | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Check PRonyx-dot-app/onyx | 32k | 2 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Understand Diff AnalysisEgonex-AI/Understand-Anything | 86k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| PR Design DocOpenHands/OpenHands | 90k | — | ~2.4k | Automated safety check: Pass | MIT |
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
onyx-dot-app/onyx
Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.
Egonex-AI/Understand-Anything
Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.
OpenHands/OpenHands
For a non-trivial pull request, write a self-contained HTML design doc under the temporary .pr/ directory and link a visibility-appropriate preview in the PR description, so maintainers grasp the…
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
vlinx-io/VelaTerm
Explicitly spawn a standalone child session under the current vlx-term session, passing the task in as its first message (mirrors spawntask).
vlinx-io/VelaTerm
A skill your agent uses when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan.
vlinx-io/VelaTerm
Define, review, or update SECURITY.md guidance for a repository or component.
vlinx-io/VelaTerm
Track validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories.
vlinx-io/VelaTerm
Use only when the user explicitly requests verification that a security fix remediates a reported vulnerability.
vlinx-io/VelaTerm
Open a file or URL in the vlx-term center pane (mirrors the vopen command).
Categories
Assess an immutable patch artifact's program impact, regression risk, and auto-merge eligibility. Assess Patch Risk is an agent skill from vlinx-io/VelaTerm. Assess an immutable patch artifact's program impact, regression risk, and auto-merge eligibility.
Assess Patch Risk fits situations like: generated patch files; provider pull-request diffs; commit ranges when reviewers need evidence about affected runtime paths.
Run `npx skills add vlinx-io/VelaTerm --skill assess-patch-risk -a claude-code`. Or copy the skill folder (src-tauri/resources/codex-security/skills/assess-patch-risk in vlinx-io/VelaTerm) into .claude/skills/assess-patch-risk in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vlinx-io/VelaTerm --skill assess-patch-risk -a codex`. Or copy the skill folder (src-tauri/resources/codex-security/skills/assess-patch-risk in vlinx-io/VelaTerm) into .agents/skills/assess-patch-risk in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vlinx-io/VelaTerm --skill assess-patch-risk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/assess-patch-risk, .gemini/skills/assess-patch-risk, .github/skills/assess-patch-risk and .opencode/skills/assess-patch-risk in your project.
Going by SKILL.md and its folder, Assess Patch Risk needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Assess Patch Risk is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Assess Patch Risk: Finishing a Development Branch (obra/superpowers, 296k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars), Check PR (onyx-dot-app/onyx, 32k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 86k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vlinx-io (a GitHub user) maintains it in vlinx-io/VelaTerm, which has 270 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.
Source: vlinx-io/VelaTerm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.