Kedro Security Review
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits.
$ npx skills add Zfinix/aster --skill aster-config -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Zfinix/aster aster-config --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Zfinix/aster.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/aster-config .claude/skills/aster-config && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "aster-config" agent skill from https://github.com/Zfinix/aster/tree/main/skills/aster-config into .claude/skills/aster-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aster-config", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Zfinix/aster/tree/main/skills/aster-configType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Zfinix/aster --skill aster-config -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Zfinix/aster aster-config --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Zfinix/aster.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/aster-config .agents/skills/aster-config && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "aster-config" agent skill from https://github.com/Zfinix/aster/tree/main/skills/aster-config into .agents/skills/aster-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aster-config", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Zfinix/aster --skill aster-config -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Zfinix/aster aster-config --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Zfinix/aster.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/aster-config .cursor/skills/aster-config && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "aster-config" agent skill from https://github.com/Zfinix/aster/tree/main/skills/aster-config into .cursor/skills/aster-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aster-config", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Zfinix/aster.git --path skills/aster-config--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Zfinix/aster --skill aster-config -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Zfinix/aster aster-config --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Zfinix/aster.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/aster-config .gemini/skills/aster-config && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "aster-config" agent skill from https://github.com/Zfinix/aster/tree/main/skills/aster-config into .gemini/skills/aster-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aster-config", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Zfinix/aster aster-configInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Zfinix/aster --skill aster-config -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Zfinix/aster.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/aster-config .github/skills/aster-config && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "aster-config" agent skill from https://github.com/Zfinix/aster/tree/main/skills/aster-config into .github/skills/aster-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aster-config", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Zfinix/aster --skill aster-config -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Zfinix/aster aster-config --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Zfinix/aster.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/aster-config .opencode/skills/aster-config && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "aster-config" agent skill from https://github.com/Zfinix/aster/tree/main/skills/aster-config into .opencode/skills/aster-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aster-config", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
aster-configReference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits.
Aster Config is an agent skill from Zfinix/aster. Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits. Use when creating or editing aster.yaml, choosing hypothesis/verify models, enabling semgrep or ast-grep, or configuring edit permissions.
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Static analysis and SAST. It works with Semgrep and Bash. The repository describes itself as: An open-source agent harness for software work. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit f77a5b4. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bashFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
openrouter.aiFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
ASTER_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Aster Config loads about 1.2k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 395 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Zfinix/aster at commit f77a5b4, republished under its Apache-2.0 licence (© Zfinix). 395 words, ~1,168 tokens.
.claude/skills/aster-config/SKILL.md (or your agent's skills folder).aster init writes the global ~/.aster/aster.yaml (or aster.yaml at the repo root with --local). Every field is optional. Precedence: CLI flags > shell env > repo aster.yaml > global aster.yaml > built-in defaults. aster config path shows which files apply here. API keys are NEVER read from this file; they come from ASTER_API_KEY or the key stored by aster init / aster login, so aster.yaml is safe to commit.
review:
model: openai/gpt-4o-mini # fallback for stages with no override
base_url: https://openrouter.ai/api/v1 # any OpenAI-compatible provider
hypothesis_model: deepseek/deepseek-v4-flash # cheap, high-recall pass
verify_model: anthropic/claude-sonnet-5 # independent adversarial verify
min_confidence: 0.6 # drop findings below this (0.0-1.0)
max_diff_bytes: 200000 # cap the diff sent to the model
analyzers: [] # [semgrep], [ast-grep], or both
focus_areas: [correctness, security] # bias the hypothesis pass
include: [] # empty = everything except exclude
exclude: ["target/**", "node_modules/**", "**/*.lock", "**/*.min.js"]hypothesis_model for recall, a strong verify_model for precision. model fills any stage without an override. ASTER_MODEL env overrides all of it for a run.analyzers adds static-analysis backends whose findings also flow through verification: semgrep needs semgrep/opengrep on PATH; ast-grep needs ast-grep/sg on PATH plus ASTER_ASTGREP_RULES pointing at a rule file.Gates what the agent edits, reads, and runs:
permissions:
mode: edit # plan | manual | auto | edit | yolo (prompts need the TUI; headless denies)
allow: [] # e.g. ["Bash(cargo test:*)", "Edit(src/**)"]
ask: [] # e.g. ["Edit(migrations/**)"]
deny: [] # e.g. ["Bash(npm publish:*)", "Edit(infra/**)"]
use_default_rules: true # ask on .git/**, workflows; ask on sudo/rm/curl in `auto`; refuse secret readsOne rule language for all three tools: Edit(<glob>), Read(<glob>), Bash(<command>:*) for a prefix or Bash(<command>) for an exact line. A bare Edit, Read, or Bash covers everything that tool does. Precedence is deny, ask, allow, built-ins, then mode, so one allow entry overrides a single built-in without dropping the rest.
A Bash rule matches inside bash -lc "…", so chaining does not slip a command past it.
Keep use_default_rules: true unless you have a specific reason; it is what makes the agent confirm before touching CI workflows and git internals, and what stops it reading env and key files.
Env beats aster.yaml, and CLI flags beat env. Everything is optional except the API key.
Provider and models:
ASTER_API_KEY - the provider API key (required; never read from aster.yaml)ASTER_BASE_URL - OpenAI-compatible endpointASTER_MODEL - fallback model for every stageASTER_HYPOTHESIS_MODEL / ASTER_VERIFY_MODEL - per-stage overridesRequest tuning:
ASTER_TIMEOUT_SECS / ASTER_MAX_RETRIES / ASTER_DEADLINE_SECS - HTTP timeout, retry count, overall deadlineASTER_MAX_TOKENS / ASTER_SEED / ASTER_REASONING_EFFORT - completion caps, deterministic seed, reasoning effortASTER_LANGUAGE - language every reply is written in; unset follows the userASTER_PRICE_PROMPT_PER_M / ASTER_PRICE_COMPLETION_PER_M - $ per million tokens, for cost reportingReview:
ASTER_ANALYZERS - comma-separated analyzer list, e.g. semgrep,ast-grep (empty = LLM only)ASTER_ASTGREP_RULES - path to the ast-grep rule fileASTER_VERIFY_CONCURRENCY - parallel verification workersASTER_REPO - repo name used in the summary (defaults to local)aster init -y writes the defaults with no wizard; --force overwrites an existing file.deny beats ask, which beats allow, which beats the built-ins.ask is refused there. Automation wants mode: edit with tight allow rules.© Zfinix, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/aster-config of Zfinix/aster.
Open the folder on GitHubat commit f77a5b4
Aster Config next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Aster Config this skillZfinix/aster | 113 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Kedro Security Reviewkedro-org/kedro | 11k | — | ~3.3k | Automated safety check: Pass | Custom licence | |
| Semgrep Security Scantrailofbits/skills | 7.4k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Kedro Plugins Security Reviewkedro-org/kedro-plugins | 119 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Sarif Parsingtrailofbits/skills | 7.4k | 3 repos | ~4.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Detection Breadthdeonmenezes/mantishack | 504 | — | ~510 | Automated safety check: Pass | Apache-2.0 |
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
kedro-org/kedro-plugins
Run a security scan on the kedro-plugins codebase or a pull request.
trailofbits/skills
Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.
deonmenezes/mantishack
When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain
skrun-dev/skrun
Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.
Zfinix/aster
Designing and building any user-facing surface: a web page, landing page, dashboard, report, HTML document, email, or a component inside an existing app.
Zfinix/aster
Drive aster chat programmatically and manage sessions and memory: one-shot --print/--json answers, --messages-json for caller-owned history, --continue and --session persistence, --allow-edits…
Zfinix/aster
Guidance for using the aster CLI to work in a codebase with an AI agent: chat and edit code, run AI code reviews, apply fixes, and manage sessions, memory, and skills.
Zfinix/aster
Pipe aster review findings into aster fix to generate and apply patches safely, using review --json, fix --findings-json, dry-run inspection, --apply, and permission gating.
Zfinix/aster
Create and execute structured plans for multi-step tasks. An agent skill from Zfinix/aster.
Zfinix/aster
Run aster code reviews non-interactively in CI, GitHub Actions, or from another agent.
Categories
Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits. Aster Config is an agent skill from Zfinix/aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits.
Aster Config fits situations like: editing aster.yaml; choosing hypothesis/verify models; enabling semgrep; configuring edit permissions.
Run `npx skills add Zfinix/aster --skill aster-config -a claude-code`. Or copy the skill folder (skills/aster-config in Zfinix/aster) into .claude/skills/aster-config in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Zfinix/aster --skill aster-config -a codex`. Or copy the skill folder (skills/aster-config in Zfinix/aster) into .agents/skills/aster-config in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Zfinix/aster --skill aster-config -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aster-config, .gemini/skills/aster-config, .github/skills/aster-config and .opencode/skills/aster-config in your project.
Going by SKILL.md and its folder, Aster Config needs the command-line tools its instructions call (bash) and credentials named ASTER_API_KEY. Our summary lists: A credential in ASTER_API_KEY.
SKILL.md names 1 domain. In commands or code: openrouter.ai; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Aster Config is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Aster Config: Kedro Security Review (kedro-org/kedro, 11k stars), Semgrep Security Scan (trailofbits/skills, 7.4k stars), Kedro Plugins Security Review (kedro-org/kedro-plugins, 119 stars) and Sarif Parsing (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Zfinix (a GitHub user) maintains it in Zfinix/aster, which has 113 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 9, 2026.
Source: Zfinix/aster on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.