Agent skill

Vuln Report

by waybarrios in waybarrios/opencode-power-pack

Turn one confirmed security finding into a disclosure-ready GitHub advisory with root cause, proof of concept, impact, and source evidence.

MITAuto-check passedDevelopment

Install Vuln Report

skills CLI
$ npx skills add waybarrios/opencode-power-pack --skill vuln-report -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install waybarrios/opencode-power-pack vuln-report --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/waybarrios/opencode-power-pack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vuln-report .claude/skills/vuln-report && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vuln-report
GitHub stars
534
Used in
1 other repo
Token cost
~1.9k tokens
SKILL.md length
985 words
Files
2 (incl. references)
Skills in repo
32
Repo updated
First seen
Licence
MIT

At a glance

Turn one confirmed security finding into a disclosure-ready GitHub advisory with root cause, proof of concept, impact, and source evidence.

  • Works in 9 steps: Confirm the report is about one bug only. → Extract the minimum facts needed to… → Separate demonstrated facts from… → …
  • Reporting an established vulnerability
  • SKILL.md covers Overview, Workflow, Required Sections and Evidence Rules, plus 4 more sections
  • Calls git; reaches github.com

What it does

Vuln Report is an agent skill from waybarrios/opencode-power-pack. Turn one confirmed security finding into a disclosure-ready GitHub advisory with root cause, proof of concept, impact, and source evidence. Use for reporting an established vulnerability, not discovering or validating one.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/report-template.md`).

It sits in Development, covering Prototyping and Root cause analysis. It works with GitHub. The repository describes itself as: 54 rigorous skills for Codex, OpenCode, and Pi: code review, security audit, feature development, frontend design, MCP tools, Hugging Face ML/training, and more. The licence is MIT.

When your agent uses it

  • Reporting an established vulnerability
  • Not discovering

Example prompts

  • “/vuln-report”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Confirm the report is about one bug only.
  2. Extract the minimum facts needed to prove the issue
  3. Separate demonstrated facts from inference. State assumptions explicitly.
  4. Draft the report using the required section order from references/report-template.md.
  5. Always embed at least one fenced code snippet from the decisive code path, and explain what each snippet proves.
  6. Always convert repository file references and patch references into GitHub markdown links, and prefer embedding those links directly into…
  7. Add only the optional sections that materially improve accuracy or triage value.
  8. Save the final report as report.md inside a folder named with the bug's severity identifier (C1, H1, M1, etc.) followed by a lowercase…
  9. Remove filler, hedging, and unproven claims before finalizing.

What it can do on your machine

Read from SKILL.md and the folder at commit 9dccb6d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vuln Report loads about 1.9k tokens when it runs, and up to ~2.9k if it reads all its reference files. Until then it costs about 59 tokens; SKILL.md has 985 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from waybarrios/opencode-power-pack at commit 9dccb6d, republished under its MIT licence (© waybarrios). 985 words, ~1,863 tokens.

Download SKILL.mdSave it as .claude/skills/vuln-report/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
vuln-report
description
Turn one confirmed security finding into a disclosure-ready GitHub advisory with root cause, proof of concept, impact, and source evidence. Use for reporting an established vulnerability, not discovering or validating one.
license
MIT (modified; see UPSTREAMS.json)

Vulnerability Report

Overview

Draft one disclosure-ready report for one confirmed bug. Keep the report evidence-driven, concrete, and concise. Prefer the section order and phrasing rules in references/report-template.md.

Workflow

  1. Confirm the report is about one bug only.
  2. Extract the minimum facts needed to prove the issue:
    • vulnerable component or behavior
    • attacker-controlled input or missing validation
    • preconditions and trust boundary
    • exploit result
    • practical impact
    • strongest reproduction path
    • decisive source locations and any relevant fix commit
  3. Separate demonstrated facts from inference. State assumptions explicitly.
  4. Draft the report using the required section order from references/report-template.md.
  5. Always embed at least one fenced code snippet from the decisive code path, and explain what each snippet proves.
  6. Always convert repository file references and patch references into GitHub markdown links, and prefer embedding those links directly into the surrounding explanation instead of listing them separately.
  7. Add only the optional sections that materially improve accuracy or triage value.
  8. Save the final report as report.md inside a folder named with the bug's severity identifier (C1, H1, M1, etc.) followed by a lowercase hyphenated slug derived from the final report title. Use C for Critical, H for High, M for Medium, sequentially numbered if there are multiple bugs of the same severity. Example: C1-cross-site-websocket-hijacking-re-enabled-by-allow-websocket/report.md. Also, ensure the bug report title and internal references use this ID (e.g., '[C1] Cross-Site WebSocket Hijacking'). Do not write reports for Low severity findings — document them in the summary table only.
  9. Remove filler, hedging, and unproven claims before finalizing.

Required Sections

Always include these sections in this order:

  1. Summary
  2. Details
  3. Root Cause
  4. Proof of Concept (PoC)
  5. Impact

If the repository already uses Technical Details with Root Cause nested under it, preserve that local pattern. Otherwise keep Root Cause as its own section.

Evidence Rules

  • Include one or more fenced code snippets in the report, usually in Details or Root Cause.
  • Use the smallest snippet that proves the bug.
  • Introduce each cited code location with a short explanation of why it matters; do not drop raw link lists without commentary.
  • Add GitHub markdown links for source files, line anchors, controllers, helpers, patch commits, or affected surfaces whenever the repository is on GitHub and the target URL is known or can be derived.
  • When constructing GitHub source links, use the latest commit SHA (from git rev-parse HEAD or the most recent commit visible in context) instead of a branch name such as main or master, so links remain stable after future commits.
  • Prefer embedding inline markdown links into explanatory sentences such as The following code in [build_request](https://github.com/org/repo/blob/main/src/executor.rs#L10) reads attacker-controlled input without validation.
  • Keep non-GitHub standards or spec citations as normal markdown links.

Self-Contained Rule

report.md is a disclosure-ready artefact. The reader must understand the vulnerability, the trace, the impact, and the reproduction without opening any sibling working file (drafts, debate transcripts, review notes, internal metadata).

  • Do not write prose pointers such as See draft.md, See debate.md, See adversarial-review.md, See metadata.json, See pN-NNN for full trace, See AP-NNN, Refer to the draft for impact analysis, or for the full trace see .... If that content is needed in the report, inline it.
  • Do not cite internal phase IDs (pN-NNN, p10-NNN, AP-NNN) — these are pipeline bookkeeping, not reader-facing references.
  • Sibling-file references are only allowed for runnable evidence artefacts shipped alongside the report (e.g. poc.<ext>, evidence/<file>), and only inside the Proof of Concept or Impact sections. Quote the decisive lines from logs inline rather than telling the reader to open them.
  • GitHub links to source code (pinned to a commit SHA) are external evidence, not deferred narrative — those are required, not banned.
  • Before finalizing, scan the draft for the banned phrasings above and rewrite any occurrence to inline the content.
Show full SKILL.md (363 more words)Show less

Section Rules

Summary

Open with the vulnerable behavior, attacker control, and outcome in one short paragraph. Name the component only if it improves clarity.

Details

Explain the code path and why the protection fails. Include relevant conditions such as auth mode, stateless mode, parser behavior, MIME confusion, or transport assumptions. Support the explanation with code snippets and GitHub markdown links to the exact source locations.

Root Cause

State the design or implementation mistake in one focused subsection. Prefer causal language such as missing origin validation, unsafe trust in extension-derived MIME, or policy enforced only in one execution mode.

Proof of Concept (PoC)

Use the shortest reliable reproduction. Prefer numbered steps and a runnable request, command, or code block. State the expected result.

Impact

Describe exploitability and consequence, not just severity labels. Cover who is exposed, what an attacker gains, and which environments are most at risk.

Optional Sections

Include an optional section only when it adds concrete triage value.

Allowed optional sections include:

  • short report title at the top
  • vulnerability type
  • CWE
  • CVSS vector or severity guidance
  • attack preconditions or authentication reality
  • affected surfaces or scope notes
  • specification or guidance references
  • patch or fix-commit metadata
  • exploit constraints, non-default assumptions, or deployment qualifiers

Do not add Affected Components or Remediation sections unless the user explicitly asks for them.

Quality Bar

  • Keep one bug per report.
  • Number bugs using severity prefixes (C1, H1, M1) and prefix both the report title and the folder name with this ID. Low severity findings are not reported individually.
  • Save each single-bug report to <ID>-<title-slug>/report.md.
  • Make the exploit story readable without external context — and explicitly without opening any sibling working file (draft.md, debate.md, adversarial-review.md, metadata.json). See the Self-Contained Rule.
  • No pointer prose to sibling narrative files or internal phase IDs (pN-NNN, AP-NNN). Inline the content.
  • Use exact file paths, endpoints, headers, options, or modes when they matter.
  • Distinguish observed behavior from likely impact.
  • Prefer measured severity language over inflated claims.
  • Preserve repository-specific terminology if the source material already uses it.
  • Include fenced code snippets and GitHub markdown links in every report.
  • End with a report that can be pasted into an advisory, audit finding, or maintainer issue with minimal cleanup.

© waybarrios, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/vuln-report of waybarrios/opencode-power-pack.

  • SKILL.md
  • references/report-template.md

Open the folder on GitHubat commit 9dccb6d

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in waybarrios/opencode-power-pack, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Vuln Report next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vuln Report compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vuln Report this skillwaybarrios/opencode-power-pack5341 repos~1.9kAutomated safety check: PassMIT
OpenROAD Bug FixerThe-OpenROAD-Project/OpenROAD3.2k—~784Automated safety check: PassBSD-3-Clause
Octocode Code Researchbgauryy/octocode949—~1.5kAutomated safety check: PassMIT
Triagebot Action Bug Triagewithastro/astro63k—~639Automated safety check: PassCustom licence
CI TriageMentra-Community/MentraOS2.4k—~582Automated safety check: PassApache-2.0
Stereopy Issue ResponderSTOmics/Stereopy293—~1.3kAutomated safety check: PassMIT

Similar skills

  • OpenROAD Bug Fixer

    The-OpenROAD-Project/OpenROAD

    Fixes an OpenROAD bug from a GitHub issue or error code: finds the root cause, implements the fix, adds a regression test and prepares a signed-off commit.

    3.2k GitHub stars~784 tokensUpdated today
    DevelopmentAuto-check passed
  • Octocode Code Research

    bgauryy/octocode

    Researches code with evidence: traces callers, imports and cross-repo links, diagnoses failures and reports findings with exact file and line references and a confidence label.

    949 GitHub stars~1.5k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Official

    Takes a bug report for the triagebot-action GitHub Action through reproduction, root-cause diagnosis, an intended-behavior check and a fix attempt.

    63k GitHub stars~639 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • CI Triage

    Mentra-Community/MentraOS

    Triage failing GitHub PR checks: list failures with gh, fetch capped Actions logs, skip non-Actions checks, and summarize root cause.

    2.4k GitHub stars~582 tokensUpdated today
    DevelopmentAuto-check passed
  • Stereopy Issue Responder

    STOmics/Stereopy

    Generates professional maintainer-grade responses for Stereopy GitHub issues.

    293 GitHub stars~1.3k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Reviewing Pull Requests

    Shopify/shopify-app-js

    Official

    Reviews pull requests for Shopify/shopify-app-js with comprehensive analysis including semver compliance (MAJOR/MINOR/PATCH classification), single responsibility validation, pattern consistency…

    541 GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from waybarrios/opencode-power-pack

All 32 skills in this repo
  • Hf Cloud Sagemaker Iam Preflight

    waybarrios/opencode-power-pack

    Verify or select a SageMaker execution role before creating models, endpoints, or training jobs.

    534 GitHub stars~1.6k tokensUpdated 5 days ago
    Auto-check passed
  • Huggingface LLM Trainer

    waybarrios/opencode-power-pack

    Train or fine-tune language models with TRL or Unsloth on Hugging Face Jobs, including SFT, DPO, GRPO, reward models, and GGUF conversion.

    534 GitHub stars~3k tokensUpdated 5 days ago
    Auto-check passed
  • Huggingface Vision Trainer

    waybarrios/opencode-power-pack

    Train object-detection, image-classification, or SAM segmentation models on Hugging Face Jobs.

    534 GitHub stars~2.7k tokensUpdated 5 days ago
    Auto-check passed
  • Codeql

    waybarrios/opencode-power-pack

    Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF.

    534 GitHub starsUsed in 2 repos~3.7k tokens
    Auto-check passed
  • Semgrep

    waybarrios/opencode-power-pack

    Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.

    534 GitHub stars~2.4k tokensUpdated 5 days ago
    Auto-check passed
  • Insecure Defaults

    waybarrios/opencode-power-pack

    Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production.

    534 GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed

Works with

Categories

Questions about Vuln Report

What does Vuln Report do?

Turn one confirmed security finding into a disclosure-ready GitHub advisory with root cause, proof of concept, impact, and source evidence. Vuln Report is an agent skill from waybarrios/opencode-power-pack. Turn one confirmed security finding into a disclosure-ready GitHub advisory with root cause, proof of concept, impact, and source evidence.

When should I use Vuln Report?

Vuln Report fits situations like: reporting an established vulnerability; not discovering.

How do I install Vuln Report in Claude Code?

Run `npx skills add waybarrios/opencode-power-pack --skill vuln-report -a claude-code`. Or copy the skill folder (skills/vuln-report in waybarrios/opencode-power-pack) into .claude/skills/vuln-report in your project. Claude Code loads it when a task matches its description.

How do I install Vuln Report in Codex?

Run `npx skills add waybarrios/opencode-power-pack --skill vuln-report -a codex`. Or copy the skill folder (skills/vuln-report in waybarrios/opencode-power-pack) into .agents/skills/vuln-report in your project. Codex loads it when a task matches its description.

Can I use Vuln Report in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add waybarrios/opencode-power-pack --skill vuln-report -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vuln-report, .gemini/skills/vuln-report, .github/skills/vuln-report and .opencode/skills/vuln-report in your project.

What does Vuln Report need to run?

Going by SKILL.md and its folder, Vuln Report needs the command-line tools its instructions call (git).

Does Vuln Report access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Vuln Report safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vuln Report use?

Vuln Report is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vuln Report use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1k tokens, read only when the agent opens those files.

What are the alternatives to Vuln Report?

Skills that share tags, products or a category with Vuln Report: OpenROAD Bug Fixer (The-OpenROAD-Project/OpenROAD, 3.2k stars), Octocode Code Research (bgauryy/octocode, 949 stars), Triagebot Action Bug Triage (withastro/astro, 63k stars) and CI Triage (Mentra-Community/MentraOS, 2.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vuln Report?

waybarrios (a GitHub user) maintains it in waybarrios/opencode-power-pack, which has 534 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on October 6, 2026.

Source: waybarrios/opencode-power-pack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.