Security Audit Scanner
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
Builds attack trees that map how an attacker could reach a goal, with AND and OR nodes and cost, time, skill and detection ratings, to find defense gaps.
$ npx skills add wshobson/agents --skill attack-tree-construction -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install wshobson/agents attack-tree-construction --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/security-scanning/skills/attack-tree-construction .claude/skills/attack-tree-construction && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "attack-tree-construction" agent skill from https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/attack-tree-construction into .claude/skills/attack-tree-construction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attack-tree-construction", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/attack-tree-constructionType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add wshobson/agents --skill attack-tree-construction -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install wshobson/agents attack-tree-construction --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/security-scanning/skills/attack-tree-construction .agents/skills/attack-tree-construction && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "attack-tree-construction" agent skill from https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/attack-tree-construction into .agents/skills/attack-tree-construction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attack-tree-construction", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wshobson/agents --skill attack-tree-construction -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install wshobson/agents attack-tree-construction --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/security-scanning/skills/attack-tree-construction .cursor/skills/attack-tree-construction && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "attack-tree-construction" agent skill from https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/attack-tree-construction into .cursor/skills/attack-tree-construction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attack-tree-construction", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/wshobson/agents.git --path plugins/security-scanning/skills/attack-tree-construction--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add wshobson/agents --skill attack-tree-construction -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install wshobson/agents attack-tree-construction --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/security-scanning/skills/attack-tree-construction .gemini/skills/attack-tree-construction && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "attack-tree-construction" agent skill from https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/attack-tree-construction into .gemini/skills/attack-tree-construction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attack-tree-construction", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install wshobson/agents attack-tree-constructionInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add wshobson/agents --skill attack-tree-construction -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/security-scanning/skills/attack-tree-construction .github/skills/attack-tree-construction && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "attack-tree-construction" agent skill from https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/attack-tree-construction into .github/skills/attack-tree-construction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attack-tree-construction", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wshobson/agents --skill attack-tree-construction -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install wshobson/agents attack-tree-construction --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/security-scanning/skills/attack-tree-construction .opencode/skills/attack-tree-construction && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "attack-tree-construction" agent skill from https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/attack-tree-construction into .opencode/skills/attack-tree-construction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attack-tree-construction", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
attack-tree-constructionBuilds attack trees that map how an attacker could reach a goal, with AND and OR nodes and cost, time, skill and detection ratings, to find defense gaps.
The skill teaches an agent to draw an attack tree from a single root goal, branching into OR nodes where any child achieves the goal, AND nodes where every child is required, and leaf nodes for atomic attack steps. Each step is rated on cost, time, required skill and likelihood of detection so that paths can be compared and prioritized.
It frames trees as a defensive tool for visualizing complex scenarios, finding defense gaps, explaining risk to stakeholders, planning defensive spending, planning penetration tests and reviewing security architecture. Best practices include starting from a clear attacker goal, being exhaustive, covering insider threats and mitigations, respecting AND dependencies, keeping the tree current and having a red team review it. Templates and worked examples sit in `references/details.md`.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 46891e7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Attack Tree Construction loads about 623 tokens when it runs, and up to ~5.6k if it reads all its reference files. Until then it costs about 49 tokens; SKILL.md has 186 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from wshobson/agents at commit 46891e7, republished under its MIT licence (© wshobson). 186 words, ~623 tokens.
.claude/skills/attack-tree-construction/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Systematic attack path visualization and analysis.
[Root Goal]
|
┌────────────┴────────────┐
│ │
[Sub-goal 1] [Sub-goal 2]
(OR node) (AND node)
│ │
┌─────┴─────┐ ┌─────┴─────┐
│ │ │ │
[Attack] [Attack] [Attack] [Attack]
(leaf) (leaf) (leaf) (leaf)| Type | Symbol | Description |
|---|---|---|
| OR | Oval | Any child achieves goal |
| AND | Rectangle | All children required |
| Leaf | Box | Atomic attack step |
| Attribute | Description | Values |
|---|---|---|
| Cost | Resources needed | $, $$, $$$ |
| Time | Duration to execute | Hours, Days, Weeks |
| Skill | Expertise required | Low, Medium, High |
| Detection | Likelihood of detection | Low, Medium, High |
Full template library lives in references/details.md. Read that file when you need concrete templates for this skill.
© wshobson, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in plugins/security-scanning/skills/attack-tree-construction of wshobson/agents.
Open the folder on GitHubat commit 46891e7
We found 17 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 7 other GitHub owners. This page covers the copy in wshobson/agents, which our catalogue first saw on October 7, 2026.
Attack Tree Construction next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Attack Tree Construction this skillwshobson/agents | 40k | 7 repos | ~623 | Automated safety check: Pass | MIT | |
| Security Audit Scannerruvnet/ruflo | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | |
| CSO Security Auditgarrytan/gstack | 136k | — | ~4.5k | Automated safety check: Pass | MIT | |
| Behavioral State Analysisquillai-network/quillshield_skills | 129 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Commit Security Scancodexstar69/bug-hunter | 519 | — | ~629 | Automated safety check: Pass | MIT | |
| CybersecurityAgriciDaniel/claude-cybersecurity | 227 | — | ~11k | Automated safety check: Warn | MIT |
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
garrytan/gstack
Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled.
quillai-network/quillshield_skills
Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).
codexstar69/bug-hunter
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.
AgriciDaniel/claude-cybersecurity
Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.
garagon/nanostack
Use before shipping to production. An agent skill from garagon/nanostack.
wshobson/agents
Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.
wshobson/agents
Covers building subscription billing: billing cycles, subscription states, invoice generation, proration, tax handling and dunning for failed payments.
wshobson/agents
Profiles slow Python code with cProfile and memory profilers, then applies targeted fixes for CPU, memory, I/O and query bottlenecks.
wshobson/agents
Covers portfolio risk measurement with VaR, CVaR, Sharpe, Sortino and drawdown, plus guidance on limits, stress tests and tail risk.
wshobson/agents
Plans memory headroom, works through out-of-memory failures and watches temperature and power during long ML training jobs on NVIDIA DGX Spark.
wshobson/agents
Writes unit tests for shell scripts with Bats: error-condition tests, fixtures and mocks, cross-shell checks, parallel runs, helper files and CI integration.
Categories
Builds attack trees that map how an attacker could reach a goal, with AND and OR nodes and cost, time, skill and detection ratings, to find defense gaps. The skill teaches an agent to draw an attack tree from a single root goal, branching into OR nodes where any child achieves the goal, AND nodes where every child is required, and leaf nodes for atomic attack steps. Each step is rated on cost, time, required skill and likelihood of detection so that paths can be compared and prioritized.
Attack Tree Construction fits situations like: mapping the ways an attacker could reach a specific goal against a system; showing stakeholders where defenses are weakest and what to fund first; preparing the scope of a penetration test; reviewing a security architecture for gaps.
Run `npx skills add wshobson/agents --skill attack-tree-construction -a claude-code`. Or copy the skill folder (plugins/security-scanning/skills/attack-tree-construction in wshobson/agents) into .claude/skills/attack-tree-construction in your project. Claude Code loads it when a task matches its description.
Run `npx skills add wshobson/agents --skill attack-tree-construction -a codex`. Or copy the skill folder (plugins/security-scanning/skills/attack-tree-construction in wshobson/agents) into .agents/skills/attack-tree-construction in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wshobson/agents --skill attack-tree-construction -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/attack-tree-construction, .gemini/skills/attack-tree-construction, .github/skills/attack-tree-construction and .opencode/skills/attack-tree-construction in your project.
SKILL.md names no scripts, command-line tools or credentials: Attack Tree Construction is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Attack Tree Construction is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 623 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Attack Tree Construction: Security Audit Scanner (ruvnet/ruflo, 74k stars), CSO Security Audit (garrytan/gstack, 136k stars), Behavioral State Analysis (quillai-network/quillshield_skills, 129 stars) and Commit Security Scan (codexstar69/bug-hunter, 519 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
wshobson (a GitHub user) maintains it in wshobson/agents, which has 40,254 GitHub stars. The repository holds 142 skills in this directory. The repository was last updated on October 5, 2026.
Source: wshobson/agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.