Agent skill

Aster Config

by Zfinix in Zfinix/aster

Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits.

Apache-2.0Auto-check passedSecurity

Install Aster Config

skills CLI
$ npx skills add Zfinix/aster --skill aster-config -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Zfinix/aster aster-config --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Zfinix/aster.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/aster-config .claude/skills/aster-config && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aster-config
GitHub stars
113
Token cost
~1.2k tokens
SKILL.md length
395 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
Apache-2.0

At a glance

Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits.

  • Editing aster.yaml
  • SKILL.md covers Review block, Permissions block, Environment variables and Conventions
  • Calls bash; reaches openrouter.ai; needs ASTER_API_KEY
  • Choosing hypothesis/verify models

What it does

Aster Config is an agent skill from Zfinix/aster. Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits. Use when creating or editing aster.yaml, choosing hypothesis/verify models, enabling semgrep or ast-grep, or configuring edit permissions.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Static analysis and SAST. It works with Semgrep and Bash. The repository describes itself as: An open-source agent harness for software work. The licence is Apache-2.0.

When your agent uses it

  • Editing aster.yaml
  • Choosing hypothesis/verify models
  • Enabling semgrep
  • Configuring edit permissions

Example prompts

  • “/aster-config”

Requirements

  • A credential in ASTER_API_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit f77a5b4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • openrouter.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ASTER_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Aster Config loads about 1.2k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 395 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Zfinix/aster at commit f77a5b4, republished under its Apache-2.0 licence (© Zfinix). 395 words, ~1,168 tokens.

Download SKILL.mdSave it as .claude/skills/aster-config/SKILL.md (or your agent's skills folder).
name
aster-config
description
Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, min_confidence, and the permissions block that gates edits. Use when creating or editing aster.yaml, choosing hypothesis/verify models, enabling semgrep or ast-grep, or configuring edit permissions.

Configuring Aster (aster.yaml)

aster init writes the global ~/.aster/aster.yaml (or aster.yaml at the repo root with --local). Every field is optional. Precedence: CLI flags > shell env > repo aster.yaml > global aster.yaml > built-in defaults. aster config path shows which files apply here. API keys are NEVER read from this file; they come from ASTER_API_KEY or the key stored by aster init / aster login, so aster.yaml is safe to commit.

Review block

yaml
review:
  model: openai/gpt-4o-mini                      # fallback for stages with no override
  base_url: https://openrouter.ai/api/v1         # any OpenAI-compatible provider
  hypothesis_model: deepseek/deepseek-v4-flash   # cheap, high-recall pass
  verify_model: anthropic/claude-sonnet-5        # independent adversarial verify
  min_confidence: 0.6                            # drop findings below this (0.0-1.0)
  max_diff_bytes: 200000                         # cap the diff sent to the model
  analyzers: []                                  # [semgrep], [ast-grep], or both
  focus_areas: [correctness, security]           # bias the hypothesis pass
  include: []                                    # empty = everything except exclude
  exclude: ["target/**", "node_modules/**", "**/*.lock", "**/*.min.js"]
  • Split models by stage: a cheap hypothesis_model for recall, a strong verify_model for precision. model fills any stage without an override. ASTER_MODEL env overrides all of it for a run.
  • analyzers adds static-analysis backends whose findings also flow through verification: semgrep needs semgrep/opengrep on PATH; ast-grep needs ast-grep/sg on PATH plus ASTER_ASTGREP_RULES pointing at a rule file.

Permissions block

Gates what the agent edits, reads, and runs:

yaml
permissions:
  mode: edit              # plan | manual | auto | edit | yolo (prompts need the TUI; headless denies)
  allow: []               # e.g. ["Bash(cargo test:*)", "Edit(src/**)"]
  ask: []                 # e.g. ["Edit(migrations/**)"]
  deny: []                # e.g. ["Bash(npm publish:*)", "Edit(infra/**)"]
  use_default_rules: true # ask on .git/**, workflows; ask on sudo/rm/curl in `auto`; refuse secret reads

One rule language for all three tools: Edit(<glob>), Read(<glob>), Bash(<command>:*) for a prefix or Bash(<command>) for an exact line. A bare Edit, Read, or Bash covers everything that tool does. Precedence is deny, ask, allow, built-ins, then mode, so one allow entry overrides a single built-in without dropping the rest.

A Bash rule matches inside bash -lc "…", so chaining does not slip a command past it.

Keep use_default_rules: true unless you have a specific reason; it is what makes the agent confirm before touching CI workflows and git internals, and what stops it reading env and key files.

Show full SKILL.md (161 more words)Show less

Environment variables

Env beats aster.yaml, and CLI flags beat env. Everything is optional except the API key.

Provider and models:

  • ASTER_API_KEY - the provider API key (required; never read from aster.yaml)
  • ASTER_BASE_URL - OpenAI-compatible endpoint
  • ASTER_MODEL - fallback model for every stage
  • ASTER_HYPOTHESIS_MODEL / ASTER_VERIFY_MODEL - per-stage overrides

Request tuning:

  • ASTER_TIMEOUT_SECS / ASTER_MAX_RETRIES / ASTER_DEADLINE_SECS - HTTP timeout, retry count, overall deadline
  • ASTER_MAX_TOKENS / ASTER_SEED / ASTER_REASONING_EFFORT - completion caps, deterministic seed, reasoning effort
  • ASTER_LANGUAGE - language every reply is written in; unset follows the user
  • ASTER_PRICE_PROMPT_PER_M / ASTER_PRICE_COMPLETION_PER_M - $ per million tokens, for cost reporting

Review:

  • ASTER_ANALYZERS - comma-separated analyzer list, e.g. semgrep,ast-grep (empty = LLM only)
  • ASTER_ASTGREP_RULES - path to the ast-grep rule file
  • ASTER_VERIFY_CONCURRENCY - parallel verification workers
  • ASTER_REPO - repo name used in the summary (defaults to local)

Conventions

  • aster init -y writes the defaults with no wizard; --force overwrites an existing file.
  • Deny-first: deny beats ask, which beats allow, which beats the built-ins.
  • A headless run cannot answer a prompt, so anything reaching ask is refused there. Automation wants mode: edit with tight allow rules.

© Zfinix, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/aster-config of Zfinix/aster.

Open the folder on GitHubat commit f77a5b4

Compare with similar skills

Aster Config next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Aster Config compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Aster Config this skillZfinix/aster113—~1.2kAutomated safety check: PassApache-2.0
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Kedro Plugins Security Reviewkedro-org/kedro-plugins119—~3.1kAutomated safety check: PassApache-2.0
Sarif Parsingtrailofbits/skills7.4k3 repos~4.4kAutomated safety check: NotesCC-BY-SA-4.0
Detection Breadthdeonmenezes/mantishack504—~510Automated safety check: PassApache-2.0

Similar skills

  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated today
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Kedro Plugins Security Review

    kedro-org/kedro-plugins

    Run a security scan on the kedro-plugins codebase or a pull request.

    119 GitHub stars~3.1k tokensUpdated today
    SecurityAuto-check passed
  • Sarif Parsing

    trailofbits/skills

    Official

    Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.

    7.4k GitHub starsUsed in 3 repos~4.4k tokens
    SecurityAuto-check: notes
  • Detection Breadth

    deonmenezes/mantishack

    When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

    504 GitHub stars~510 tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Semgrep Rule Creator

    skrun-dev/skrun

    Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.

    210 GitHub stars~1.3k tokensUpdated 16 days ago
    SecurityAuto-check passed

More from Zfinix/aster

All 19 skills in this repo
  • Artifact Design

    Zfinix/aster

    Designing and building any user-facing surface: a web page, landing page, dashboard, report, HTML document, email, or a component inside an existing app.

    112 GitHub stars~2.8k tokensUpdated 2 days ago
    Auto-check passed
  • Drive aster chat programmatically and manage sessions and memory: one-shot --print/--json answers, --messages-json for caller-owned history, --continue and --session persistence, --allow-edits…

    112 GitHub stars~591 tokensUpdated 2 days ago
    Auto-check passed
  • Aster CLI

    Zfinix/aster

    Guidance for using the aster CLI to work in a codebase with an AI agent: chat and edit code, run AI code reviews, apply fixes, and manage sessions, memory, and skills.

    112 GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed
  • Aster Fix Workflow

    Zfinix/aster

    Pipe aster review findings into aster fix to generate and apply patches safely, using review --json, fix --findings-json, dry-run inspection, --apply, and permission gating.

    112 GitHub stars~534 tokensUpdated 2 days ago
    Auto-check passed
  • Aster Planning

    Zfinix/aster

    Create and execute structured plans for multi-step tasks. An agent skill from Zfinix/aster.

    112 GitHub stars~1k tokensUpdated 2 days ago
    Auto-check passed
  • Aster Review CI

    Zfinix/aster

    Run aster code reviews non-interactively in CI, GitHub Actions, or from another agent.

    112 GitHub stars~640 tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Aster Config

What does Aster Config do?

Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits. Aster Config is an agent skill from Zfinix/aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits.

When should I use Aster Config?

Aster Config fits situations like: editing aster.yaml; choosing hypothesis/verify models; enabling semgrep; configuring edit permissions.

How do I install Aster Config in Claude Code?

Run `npx skills add Zfinix/aster --skill aster-config -a claude-code`. Or copy the skill folder (skills/aster-config in Zfinix/aster) into .claude/skills/aster-config in your project. Claude Code loads it when a task matches its description.

How do I install Aster Config in Codex?

Run `npx skills add Zfinix/aster --skill aster-config -a codex`. Or copy the skill folder (skills/aster-config in Zfinix/aster) into .agents/skills/aster-config in your project. Codex loads it when a task matches its description.

Can I use Aster Config in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Zfinix/aster --skill aster-config -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aster-config, .gemini/skills/aster-config, .github/skills/aster-config and .opencode/skills/aster-config in your project.

What does Aster Config need to run?

Going by SKILL.md and its folder, Aster Config needs the command-line tools its instructions call (bash) and credentials named ASTER_API_KEY. Our summary lists: A credential in ASTER_API_KEY.

Does Aster Config access the network?

SKILL.md names 1 domain. In commands or code: openrouter.ai; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Aster Config safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Aster Config use?

Aster Config is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Aster Config use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Aster Config?

Skills that share tags, products or a category with Aster Config: Kedro Security Review (kedro-org/kedro, 11k stars), Semgrep Security Scan (trailofbits/skills, 7.4k stars), Kedro Plugins Security Review (kedro-org/kedro-plugins, 119 stars) and Sarif Parsing (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Aster Config?

Zfinix (a GitHub user) maintains it in Zfinix/aster, which has 113 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 9, 2026.

Source: Zfinix/aster on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.