Triage Codeql
netdata/netdata
Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.
A skill your agent uses when fixing compiler warnings, static analyzer findings (clang-tidy, etc.), or runtime errors/crashes in the libYSE codebase.
$ npx skills add yvanvds/yse-soundengine --skill fix-issues -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install yvanvds/yse-soundengine fix-issues --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/yvanvds/yse-soundengine.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/fix-issues .claude/skills/fix-issues && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fix-issues" agent skill from https://github.com/yvanvds/yse-soundengine/tree/dev/.claude/skills/fix-issues into .claude/skills/fix-issues/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-issues", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/yvanvds/yse-soundengine/tree/dev/.claude/skills/fix-issuesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add yvanvds/yse-soundengine --skill fix-issues -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install yvanvds/yse-soundengine fix-issues --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yvanvds/yse-soundengine.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/fix-issues .agents/skills/fix-issues && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fix-issues" agent skill from https://github.com/yvanvds/yse-soundengine/tree/dev/.claude/skills/fix-issues into .agents/skills/fix-issues/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-issues", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yvanvds/yse-soundengine --skill fix-issues -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install yvanvds/yse-soundengine fix-issues --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yvanvds/yse-soundengine.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/fix-issues .cursor/skills/fix-issues && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fix-issues" agent skill from https://github.com/yvanvds/yse-soundengine/tree/dev/.claude/skills/fix-issues into .cursor/skills/fix-issues/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-issues", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/yvanvds/yse-soundengine.git --path .claude/skills/fix-issues--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add yvanvds/yse-soundengine --skill fix-issues -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install yvanvds/yse-soundengine fix-issues --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yvanvds/yse-soundengine.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/fix-issues .gemini/skills/fix-issues && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fix-issues" agent skill from https://github.com/yvanvds/yse-soundengine/tree/dev/.claude/skills/fix-issues into .gemini/skills/fix-issues/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-issues", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install yvanvds/yse-soundengine fix-issuesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add yvanvds/yse-soundengine --skill fix-issues -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/yvanvds/yse-soundengine.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/fix-issues .github/skills/fix-issues && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fix-issues" agent skill from https://github.com/yvanvds/yse-soundengine/tree/dev/.claude/skills/fix-issues into .github/skills/fix-issues/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-issues", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yvanvds/yse-soundengine --skill fix-issues -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install yvanvds/yse-soundengine fix-issues --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yvanvds/yse-soundengine.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/fix-issues .opencode/skills/fix-issues && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fix-issues" agent skill from https://github.com/yvanvds/yse-soundengine/tree/dev/.claude/skills/fix-issues into .opencode/skills/fix-issues/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-issues", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fix-issuesA skill your agent uses when fixing compiler warnings, static analyzer findings (clang-tidy, etc.), or runtime errors/crashes in the libYSE codebase.
Fix Issues is an agent skill from yvanvds/yse-soundengine. Use when fixing compiler warnings, static analyzer findings (clang-tidy, etc.), or runtime errors/crashes in the libYSE codebase. Enforces the project's performance-first stance: never trade audio-thread speed for stylistic cleanliness, never modify vendored dependencies, never broaden scope beyond the reported issues.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Static analysis and SAST. It works with GitHub. The repository describes itself as: advanced 3D sound engine. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 911ea2d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pythonghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fix Issues loads about 3k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 1,630 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from yvanvds/yse-soundengine at commit 911ea2d, republished under its MIT licence (© yvanvds). 1,630 words, ~2,979 tokens.
.claude/skills/fix-issues/SKILL.md (or your agent's skills folder).libYSE is a real-time C++ sound engine. Audio-callback code runs at buffer rate on a dedicated thread and must remain lock-free and allocation-free. "Cleaning up" code here is not free: a well-meaning fix can introduce a glitch, a click, or a crash that is far worse than the original warning.
This skill governs how to triage and fix reported issues. Read it fully before making any change.
All bugs, follow-ups, and known-issue notes live in GitHub Issues on
yvanvds/yse-soundengine. Do not add new entries to a local
KNOWN_ISSUES.md or any other in-repo issue list — that file has been
retired and removed.
gh issue view <n>. Look for prior repro steps, fix sketches, and
workarounds-in-tests already documented.gh issue create --title "..." --label bug --body-file ... rather than
inlining a TODO comment that no one will find later. Workarounds in test
code should reference the issue number (e.g. // see #29) instead of a
file path.Closes #<n> (or Fixes #<n>) in the PR body so
GitHub auto-closes the issue when the PR merges into the default
branch. Verify after merge — auto-close does not fire for PRs
targeting non-default branches (e.g. this repo's dev integration
branch), so a dev PR still needs the manual close below once the
merge to master lands.gh issue close <n> --reason completed after merge, with a
short comment if context is non-obvious (gh issue comment <n> -b "fixed in <sha>"). Use --reason not planned when closing as
wontfix or duplicate.gh issue list --search "<keyword>" —
duplicates are easy to make when descriptions live across multiple
subsystems.The gh CLI is authenticated in the project environment; no MCP server or
extra setup is required.
Correctness bugs first, cosmetic warnings second, never both in one pass. A dangling pointer and an unused-parameter warning are not the same problem. Fix the bug properly. Silence the cosmetic warning with the smallest possible change.
Performance is non-negotiable on the audio thread. Anything inside or
reachable from process() methods on dspObject / dspSourceObject,
the PortAudio/OpenSL ES callback path, or the lock-free message queue
consumer must not get slower. If a "fix" adds branches, allocations,
virtual dispatch, atomic ops, or mutex acquisitions on this path,
it is the wrong fix.
Stay in scope. Fix only what was reported. Do not refactor, modernize,
reformat, rename, add [[nodiscard]] everywhere, swap containers, sprinkle
noexcept, or "improve" anything adjacent. Each of those is a separate
decision the user has not made.
Never modify vendored dependencies. Anything under dependencies/
(doctest, portaudio headers, rtmidi, libsndfile) is off-limits. Suppress
warnings from these at the CMake target level or with a localized pragma
around the include site, not by editing the header.
For each warning, analyzer finding, or error, decide which bucket it falls into:
Examples: returning a pointer into a destroyed temporary, use-after-free,
uninitialized read, missing override that hides a base method, data race,
mismatched new/delete, signed/unsigned comparison that actually overflows.
These get fixed properly, even if the fix is bigger than a one-liner. A real bug in audio-thread code is the highest priority issue in this codebase because it manifests as glitches/clicks/crashes that are very hard to debug.
Examples: __COUNTER__ is a C2y extension, const qualifier on a return
value type, unused parameters in virtual base methods with empty default
implementations, unused-but-set variables in debug-only paths.
These get silenced with the minimum-impact mechanism (see below). Do not restructure code to satisfy a stylistic warning.
Examples: an overloaded virtual that hides the base, a signed/unsigned comparison in a loop bound, a "may be uninitialized" the compiler isn't sure about.
Investigate. If it is a bug → bucket A. If the compiler is being conservative
and the code is correct → silence with [[maybe_unused]], static_cast,
explicit initialization, using Base::method;, etc. Do not silence by
disabling the warning globally.
The reported file lives under dependencies/. Never edit. Suppress at the
build-system level (target-scoped -Wno-...) or with a #pragma clang diagnostic push/ignored/pop block around the #include of the vendored
header in our own code.
Before applying any fix, identify whether the affected code is on the audio thread. The audio thread is reached through:
process() override on a dspObject or dspSourceObject subclassdevice/portaudioDeviceManager.cpp) and OpenSL ES
equivalentutils/lfQueue.hpp)On the audio thread, these are forbidden as part of a warning fix:
new, malloc, std::vector::push_back on a
vector that wasn't pre-sized, std::string construction, etc.)try/catch or anything that could throwstd::atomic operation that wasn't
already atomic (the project has aBool/aInt/aFlt wrappers — use those
if atomicity is genuinely needed, but warning fixes rarely require it)Off the audio thread (application thread, manager singletons running in
update(), file loading, demo code, tests), normal C++ rules apply, but
still: minimum change to silence the warning.
Ranked from least invasive to most:
[[maybe_unused]], (void)param;,
/*paramName*/ comment, using Base::method;, explicit initialization,
static_cast to the right type.#include: #pragma clang diagnostic push / ignored "-Wfoo" / pop in the file that includes
the third-party header.target_compile_options(yse_tests PRIVATE -Wno-foo) for warnings that only matter in one target (tests are
the typical case). Never apply globally to the engine target.If the warning is platform-specific (e.g. only appears on MSVC, only on MSYS2/Clang64, only on Android NDK), check that the fix doesn't break the other platforms. The CMake build covers Windows and Linux; Android is built separately. Suppression flags must be guarded by compiler/platform conditions when the warning only exists on one toolchain.
__COUNTER__ warning hitting 38 times is
one issue, not 38). Note the file path of each.ctest --preset tests-debug. Confirm warning count drops as expected and no new warnings
appear. Spot-check at least one demo runs (audio-thread regressions
typically show up at runtime, not at compile time).gh issue close <n> --reason completed — see "Close on landing" above). Partial fixes stay open
with an updated body.A baseline check set lives at .clang-tidy. Invoke
analysis through the project wrapper rather than calling clang-tidy
directly — the wrapper picks the right compile_commands.json and avoids
the "doctest/doctest.h not found" failure mode on test files:
python yse.py analyze YseEngine/dsp/lfo.cpp # one file
python yse.py analyze YseEngine/device/ # one directory
python yse.py analyze # whole project (slow)Per CLAUDE.md item 6, run python yse.py analyze <changed-files> before
committing and clear any new findings on the modified code. The
baseline is 43 distinct pre-existing findings across YseEngine/ and
Tests/ (measured 2026-09-28, 2 in headers; the ~280 header findings #426
surfaced were cleared by #573) — don't fix in passing during unrelated work.
Note that a header finding is reported once per include spelling, not once
per header: clang-tidy dedupes on the literal path, so the same warning shows
up again as YseEngine/channel/../classes.hpp after
YseEngine/classes.hpp. Judge "did I add a finding?" by the file:line, not by
the line count.
-Wfoo that wasn't
on before) without an accompanying issueaFlt, MULTICHANNELBUFFER, the message
queue, dspObject::link()) with standard-library equivalentsIf any of those would actually help, raise them as a separate proposal, not as part of a warning-fix pass.
For runtime errors (assertions, segfaults, audio glitches, hangs) the same priorities apply but with different emphasis:
© yvanvds, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/fix-issues of yvanvds/yse-soundengine.
Open the folder on GitHubat commit 911ea2d
Fix Issues next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fix Issues this skillyvanvds/yse-soundengine | 238 | — | ~3k | Automated safety check: Pass | MIT | |
| Triage Codeqlnetdata/netdata | 81k | — | ~1.8k | Automated safety check: Notes | GPL-3.0 | |
| Agentic GitHub Actions Auditortrailofbits/skills | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Openclaw CI Limitsopenclaw/openclaw | 392k | — | ~13k | Automated safety check: Pass | MIT | |
| Implementing GitHub Advanced Security For Code Scanningmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| Pipeline Security Gatesrevfactory/harness-100 | 1.3k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 |
netdata/netdata
Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
openclaw/openclaw
Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe…
mukul975/Anthropic-Cybersecurity-Skills
Configures GitHub Advanced Security (code scanning with CodeQL, secret scanning, dependency review, and Dependabot alerts) to perform automated static analysis and vulnerability detection across…
revfactory/harness-100
CI/CD pipeline security gate design guide. An agent skill from revfactory/harness-100.
bitwarden/ai-plugins
This skill should be used when the user asks to "triage security findings", "fix an Aikido finding", "review Aikido issues", "dismiss a false positive", "check SAST/IaC alerts", or needs to work…
yvanvds/yse-soundengine
A skill your agent uses when extending the C API at YseEngine/capi/ — wrapping a new engine class, method, enum, or callback — or when auditing the C API for drift from the engine's public surface.
yvanvds/yse-soundengine
Use after an issue's PR has been merged to wrap up the issue branch — close the issue, switch back to dev, fast-forward, and delete the local and remote feature branches.
yvanvds/yse-soundengine
A skill your agent uses when the user asks to cut a new release of libYSE — phrases like "release a new version", "cut a patch/minor/major release", "publish a new release", "ship X.Y.Z".
Works with
Categories
A skill your agent uses when fixing compiler warnings, static analyzer findings (clang-tidy, etc.), or runtime errors/crashes in the libYSE codebase. Fix Issues is an agent skill from yvanvds/yse-soundengine.), or runtime errors/crashes in the libYSE codebase.
Fix Issues fits situations like: fixing compiler warnings; static analyzer findings (clang-tidy; runtime errors/crashes in the libYSE codebase.
Run `npx skills add yvanvds/yse-soundengine --skill fix-issues -a claude-code`. Or copy the skill folder (.claude/skills/fix-issues in yvanvds/yse-soundengine) into .claude/skills/fix-issues in your project. Claude Code loads it when a task matches its description.
Run `npx skills add yvanvds/yse-soundengine --skill fix-issues -a codex`. Or copy the skill folder (.claude/skills/fix-issues in yvanvds/yse-soundengine) into .agents/skills/fix-issues in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yvanvds/yse-soundengine --skill fix-issues -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fix-issues, .gemini/skills/fix-issues, .github/skills/fix-issues and .opencode/skills/fix-issues in your project.
Going by SKILL.md and its folder, Fix Issues needs the command-line tools its instructions call (python and gh). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Fix Issues is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Fix Issues: Triage Codeql (netdata/netdata, 81k stars), Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars), Openclaw CI Limits (openclaw/openclaw, 392k stars) and Implementing GitHub Advanced Security For Code Scanning (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
yvanvds (a GitHub user) maintains it in yvanvds/yse-soundengine, which has 238 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 29, 2026.
Source: yvanvds/yse-soundengine on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.