html-theme

html-theme is a skill for Claude Code, Codex from dradis/dradis-claude. It costs 0 tokens per session (2,976 once invoked), scanned A, original, GPL-2.0.

An HTML report template for Dradis projects, built as an ERB file. Dradis is a platform for organising security assessment findings and project work.

In plain words
What is it for?
Use it to create or redesign Dradis reports with charts, risk summaries, and detailed security findings.
Why use it?
It turns project data into a self-contained report instead of requiring a report layout to be designed from scratch.

Skill for Claude CodeCodex

Part of the dradis-core plugin — 3 skills shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/dradis/dradis-claude/html-theme
Any agent
npx skills add dradis/dradis-claude --skill html-theme
Clone the repo
git clone --depth 1 https://github.com/dradis/dradis-claude

Made for: Claude Code, Codex.

Or install dradis-core, the plugin that ships this one along with the rest of its 3 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for html-theme

README.md
[![agentmods](https://agentmods.dev/badge/skills/dradis/dradis-claude/html-theme.svg)](https://agentmods.dev/skills/dradis/dradis-claude/html-theme)
Your own site
<a href="https://agentmods.dev/skills/dradis/dradis-claude/html-theme"><img src="https://agentmods.dev/badge/skills/dradis/dradis-claude/html-theme.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,976 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin unknown No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.02976
Opus 5 $0.00000 $0.01488
Sonnet 5 $0.00000 $0.00595
Haiku 4.5 $0.00000 $0.00298

Measured 4d ago against content hash 4478730a5c5a, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

html-theme scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/dradis-core/skills/html-theme/SKILL.md · 253 lines

The source is not reproduced here

Licensed GPL-2.0

The repository is licensed GPL-2.0, which this catalogue does not treat as permission to reproduce the file. Read it at the source.

Read it on GitHub

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 253 lines · 0 tokens per session scan A 4478730a5c5a

Subscribe to this mod's changes

html-theme is a skill published in the GitHub repository dradis/dradis-claude (1 stars, last pushed 9d ago), licensed GPL-2.0. It costs nothing until one of its globs matches a file; then it loads 2,976 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

metabigor

Use when operating the metabigor CLI for OSINT recon and infrastructure mapping without API keys. Covers finding network ranges from an ASN, org, domain, or IP (net); enumerating subdomains from certificate logs (cert); enriching IPs with ports/CVEs via Shodan InternetDB (ip); searching public GitHub code for secrets…

j3ssie/metabigor · 143 tokens

report

确认漏洞后产出正式 SRC/0day 提交稿 DOCX 报告的收口 skill。仅在漏洞已确认、准备成稿时使用——负责查重、过分层验证门、按固定 DOCX 骨架生成报告(Heading 2 章节 + Step 式 PoC + 内嵌真实截图)、语义化命名、放对目录、处理驳回追加。不负责挖掘/验证漏洞本身。TRIGGER:用户说"写报告/出报告/成稿/提交稿/生成漏洞报告",或漏洞已验证到位准备交付时;或 /report。EN: Turns confirmed vulnerabilities into submission-ready DOCX reports for SRC/0day platforms (verification…

zhaji2333/CkSKILLS · 0 tokens

xss-frontend-security

当目标存在评论/昵称/富文本/私信/工单/搜索反射/Markdown解析/AI输出渲染/前端DOM操作/postMessage/跨域配置等功能时调用。负责反射型/存储型/DOM XSS、AI/Markdown 渲染型存储 XSS、CSRF、CORS错误配置、Clickjacking 的深度挖掘与绕过。命中跳转页/开放重定向/target 参数驱动 location 跳转时优先测试跳转型 XSS(伪协议升级同源 XSS;仅 http(s) 放行时按 3.2 L3 与 3.4 评估开放重定向单独成洞);命中 AI 对话/分享页 marked 渲染无净化时测 AI 输出型存储 XSS。.

zhaji2333/CkSKILLS · 191 tokens

miniprogram-security

当目标为微信/支付宝/抖音/百度等小程序(含微信云开发/云函数)、需要小程序包获取与反编译、appid/appsecret/接口提取、微信登录链/支付/越权/WebView/rich-text 渲染/云开发漏洞挖掘时调用。负责小程序全生命周期深度挖掘:包还原 → 代码审计 → 接口与密钥提取 → 登录/支付/越权/渲染/云开发专项 → 验证要点。命中场景:openid 替换越权、code 登录绕过、支付金额篡改、云函数未授权、web-view/rich-text XSS。.

zhaji2333/CkSKILLS · 160 tokens

windows-reverse-engineering

当目标为 Windows PE 程序(EXE/DLL/SYS/驱动)、.NET 程序、Windows 服务、内核组件,或需要静态/动态逆向分析挖掘缓冲区溢出、远程命令执行、权限提升、信息泄露、拒绝服务等二进制漏洞时调用。负责反汇编/反编译分析、内存破坏漏洞挖掘、协议逆向、反调试对抗、漏洞利用链构造、shellcode 编写与 PoC 验证。.

zhaji2333/CkSKILLS · 129 tokens

unauth-path-key-hunt

当未授权/零身份测试但路径不在主站 JS、禁止依赖登录 Network 截图、独立 H5/旧域名 NXDOMAIN/品牌迁域、兄弟域或同 IP Host 漏路径、网关 405 或 data 空数组、getRsaKey/JSEncrypt/前端加密被当成鉴权时调用。负责零身份公开面还原路径与密钥、响应指纹分流、加密证伪、迁域复查。JS 拆包见 recon-js-analysis;角色/IDOR 见 auth-access-control;路径已知后的全方法/BOLA 见 api-protocol-security。.

zhaji2333/CkSKILLS · 150 tokens