OpenROAD Bug Fixer
The-OpenROAD-Project/OpenROAD
Fixes an OpenROAD bug from a GitHub issue or error code: finds the root cause, implements the fix, adds a regression test and prepares a signed-off commit.
Turn one confirmed security finding into a disclosure-ready GitHub advisory with root cause, proof of concept, impact, and source evidence.
$ npx skills add waybarrios/opencode-power-pack --skill vuln-report -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install waybarrios/opencode-power-pack vuln-report --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/waybarrios/opencode-power-pack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vuln-report .claude/skills/vuln-report && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vuln-report" agent skill from https://github.com/waybarrios/opencode-power-pack/tree/main/skills/vuln-report into .claude/skills/vuln-report/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vuln-report", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/waybarrios/opencode-power-pack/tree/main/skills/vuln-reportType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add waybarrios/opencode-power-pack --skill vuln-report -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install waybarrios/opencode-power-pack vuln-report --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/waybarrios/opencode-power-pack.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/vuln-report .agents/skills/vuln-report && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vuln-report" agent skill from https://github.com/waybarrios/opencode-power-pack/tree/main/skills/vuln-report into .agents/skills/vuln-report/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vuln-report", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add waybarrios/opencode-power-pack --skill vuln-report -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install waybarrios/opencode-power-pack vuln-report --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/waybarrios/opencode-power-pack.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/vuln-report .cursor/skills/vuln-report && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vuln-report" agent skill from https://github.com/waybarrios/opencode-power-pack/tree/main/skills/vuln-report into .cursor/skills/vuln-report/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vuln-report", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/waybarrios/opencode-power-pack.git --path skills/vuln-report--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add waybarrios/opencode-power-pack --skill vuln-report -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install waybarrios/opencode-power-pack vuln-report --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/waybarrios/opencode-power-pack.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/vuln-report .gemini/skills/vuln-report && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vuln-report" agent skill from https://github.com/waybarrios/opencode-power-pack/tree/main/skills/vuln-report into .gemini/skills/vuln-report/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vuln-report", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install waybarrios/opencode-power-pack vuln-reportInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add waybarrios/opencode-power-pack --skill vuln-report -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/waybarrios/opencode-power-pack.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/vuln-report .github/skills/vuln-report && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vuln-report" agent skill from https://github.com/waybarrios/opencode-power-pack/tree/main/skills/vuln-report into .github/skills/vuln-report/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vuln-report", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add waybarrios/opencode-power-pack --skill vuln-report -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install waybarrios/opencode-power-pack vuln-report --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/waybarrios/opencode-power-pack.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/vuln-report .opencode/skills/vuln-report && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vuln-report" agent skill from https://github.com/waybarrios/opencode-power-pack/tree/main/skills/vuln-report into .opencode/skills/vuln-report/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vuln-report", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vuln-reportTurn one confirmed security finding into a disclosure-ready GitHub advisory with root cause, proof of concept, impact, and source evidence.
Vuln Report is an agent skill from waybarrios/opencode-power-pack. Turn one confirmed security finding into a disclosure-ready GitHub advisory with root cause, proof of concept, impact, and source evidence. Use for reporting an established vulnerability, not discovering or validating one.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/report-template.md`).
It sits in Development, covering Prototyping and Root cause analysis. It works with GitHub. The repository describes itself as: 54 rigorous skills for Codex, OpenCode, and Pi: code review, security audit, feature development, frontend design, MCP tools, Hugging Face ML/training, and more. The licence is MIT.
9 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9dccb6d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vuln Report loads about 1.9k tokens when it runs, and up to ~2.9k if it reads all its reference files. Until then it costs about 59 tokens; SKILL.md has 985 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from waybarrios/opencode-power-pack at commit 9dccb6d, republished under its MIT licence (© waybarrios). 985 words, ~1,863 tokens.
.claude/skills/vuln-report/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Draft one disclosure-ready report for one confirmed bug. Keep the report evidence-driven, concrete, and concise. Prefer the section order and phrasing rules in references/report-template.md.
report.md inside a folder named with the bug's severity identifier (C1, H1, M1, etc.) followed by a lowercase hyphenated slug derived from the final report title. Use C for Critical, H for High, M for Medium, sequentially numbered if there are multiple bugs of the same severity. Example: C1-cross-site-websocket-hijacking-re-enabled-by-allow-websocket/report.md. Also, ensure the bug report title and internal references use this ID (e.g., '[C1] Cross-Site WebSocket Hijacking'). Do not write reports for Low severity findings — document them in the summary table only.Always include these sections in this order:
SummaryDetailsRoot CauseProof of Concept (PoC)ImpactIf the repository already uses Technical Details with Root Cause nested under it, preserve that local pattern. Otherwise keep Root Cause as its own section.
Details or Root Cause.git rev-parse HEAD or the most recent commit visible in context) instead of a branch name such as main or master, so links remain stable after future commits.The following code in [build_request](https://github.com/org/repo/blob/main/src/executor.rs#L10) reads attacker-controlled input without validation.report.md is a disclosure-ready artefact. The reader must understand the vulnerability, the trace, the impact, and the reproduction without opening any sibling working file (drafts, debate transcripts, review notes, internal metadata).
See draft.md, See debate.md, See adversarial-review.md, See metadata.json, See pN-NNN for full trace, See AP-NNN, Refer to the draft for impact analysis, or for the full trace see .... If that content is needed in the report, inline it.pN-NNN, p10-NNN, AP-NNN) — these are pipeline bookkeeping, not reader-facing references.poc.<ext>, evidence/<file>), and only inside the Proof of Concept or Impact sections. Quote the decisive lines from logs inline rather than telling the reader to open them.Open with the vulnerable behavior, attacker control, and outcome in one short paragraph. Name the component only if it improves clarity.
Explain the code path and why the protection fails. Include relevant conditions such as auth mode, stateless mode, parser behavior, MIME confusion, or transport assumptions. Support the explanation with code snippets and GitHub markdown links to the exact source locations.
State the design or implementation mistake in one focused subsection. Prefer causal language such as missing origin validation, unsafe trust in extension-derived MIME, or policy enforced only in one execution mode.
Use the shortest reliable reproduction. Prefer numbered steps and a runnable request, command, or code block. State the expected result.
Describe exploitability and consequence, not just severity labels. Cover who is exposed, what an attacker gains, and which environments are most at risk.
Include an optional section only when it adds concrete triage value.
Allowed optional sections include:
CWECVSS vector or severity guidanceDo not add Affected Components or Remediation sections unless the user explicitly asks for them.
<ID>-<title-slug>/report.md.draft.md, debate.md, adversarial-review.md, metadata.json). See the Self-Contained Rule.pN-NNN, AP-NNN). Inline the content.© waybarrios, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/vuln-report of waybarrios/opencode-power-pack.
Open the folder on GitHubat commit 9dccb6d
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in waybarrios/opencode-power-pack, which our catalogue first saw on October 7, 2026.
Vuln Report next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vuln Report this skillwaybarrios/opencode-power-pack | 534 | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| OpenROAD Bug FixerThe-OpenROAD-Project/OpenROAD | 3.2k | — | ~784 | Automated safety check: Pass | BSD-3-Clause | |
| Octocode Code Researchbgauryy/octocode | 949 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Triagebot Action Bug Triagewithastro/astro | 63k | — | ~639 | Automated safety check: Pass | Custom licence | |
| CI TriageMentra-Community/MentraOS | 2.4k | — | ~582 | Automated safety check: Pass | Apache-2.0 | |
| Stereopy Issue ResponderSTOmics/Stereopy | 293 | — | ~1.3k | Automated safety check: Pass | MIT |
The-OpenROAD-Project/OpenROAD
Fixes an OpenROAD bug from a GitHub issue or error code: finds the root cause, implements the fix, adds a regression test and prepares a signed-off commit.
bgauryy/octocode
Researches code with evidence: traces callers, imports and cross-repo links, diagnoses failures and reports findings with exact file and line references and a confidence label.
withastro/astro
Takes a bug report for the triagebot-action GitHub Action through reproduction, root-cause diagnosis, an intended-behavior check and a fix attempt.
Mentra-Community/MentraOS
Triage failing GitHub PR checks: list failures with gh, fetch capped Actions logs, skip non-Actions checks, and summarize root cause.
STOmics/Stereopy
Generates professional maintainer-grade responses for Stereopy GitHub issues.
Shopify/shopify-app-js
Reviews pull requests for Shopify/shopify-app-js with comprehensive analysis including semver compliance (MAJOR/MINOR/PATCH classification), single responsibility validation, pattern consistency…
waybarrios/opencode-power-pack
Verify or select a SageMaker execution role before creating models, endpoints, or training jobs.
waybarrios/opencode-power-pack
Train or fine-tune language models with TRL or Unsloth on Hugging Face Jobs, including SFT, DPO, GRPO, reward models, and GGUF conversion.
waybarrios/opencode-power-pack
Train object-detection, image-classification, or SAM segmentation models on Hugging Face Jobs.
waybarrios/opencode-power-pack
Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF.
waybarrios/opencode-power-pack
Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.
waybarrios/opencode-power-pack
Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production.
Works with
Categories
Turn one confirmed security finding into a disclosure-ready GitHub advisory with root cause, proof of concept, impact, and source evidence. Vuln Report is an agent skill from waybarrios/opencode-power-pack. Turn one confirmed security finding into a disclosure-ready GitHub advisory with root cause, proof of concept, impact, and source evidence.
Vuln Report fits situations like: reporting an established vulnerability; not discovering.
Run `npx skills add waybarrios/opencode-power-pack --skill vuln-report -a claude-code`. Or copy the skill folder (skills/vuln-report in waybarrios/opencode-power-pack) into .claude/skills/vuln-report in your project. Claude Code loads it when a task matches its description.
Run `npx skills add waybarrios/opencode-power-pack --skill vuln-report -a codex`. Or copy the skill folder (skills/vuln-report in waybarrios/opencode-power-pack) into .agents/skills/vuln-report in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add waybarrios/opencode-power-pack --skill vuln-report -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vuln-report, .gemini/skills/vuln-report, .github/skills/vuln-report and .opencode/skills/vuln-report in your project.
Going by SKILL.md and its folder, Vuln Report needs the command-line tools its instructions call (git).
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Vuln Report is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Vuln Report: OpenROAD Bug Fixer (The-OpenROAD-Project/OpenROAD, 3.2k stars), Octocode Code Research (bgauryy/octocode, 949 stars), Triagebot Action Bug Triage (withastro/astro, 63k stars) and CI Triage (Mentra-Community/MentraOS, 2.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
waybarrios (a GitHub user) maintains it in waybarrios/opencode-power-pack, which has 534 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on October 6, 2026.
Source: waybarrios/opencode-power-pack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.