Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/dyoshikawa/rulesync/security-scan-diffnpx skills add dyoshikawa/rulesync --skill security-scan-diffgit clone --depth 1 https://github.com/dyoshikawa/rulesyncWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00020 | $0.00682 |
| Opus 5 | $0.00010 | $0.00341 |
| Sonnet 5 | $0.00004 | $0.00136 |
| Haiku 4.5 | $0.00002 | $0.00068 |
Grade B, and why
security-scan-diff scanned grade B with 3 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Downloads and executes remote codemediumSupply chain
curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.
- Malicious command execution (`curl | bash`, `eval`, base64 decode execution) Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
- Malicious command execution (`curl | bash`, `eval`, base64 decode execution) Runs shell commandslowCapability
Expected in a hook, worth knowing in a rule or an instructions file.
- Arbitrary code execution (`eval`, `Function` constructor, suspicious `child_process` usage) How it starts
The opening of the file, as written. The whole thing — 77 lines — stays where its author put it; the contents beside it link to each section on GitHub.
target_ref = $ARGUMENTS
If target_ref is not provided, ask the user which tag or commit to compare against HEAD.
Overview
Thoroughly check for malicious code in the diff between ${target_ref} and the latest commit (HEAD).
Steps
-
Verify the target ref exists and get the diff scope.
- Run
git log ${target_ref}..HEAD --onelineto list commits. - Run
git diff ${target_ref}..HEAD --statto get file change statistics. - Categorize changed files into: CI/CD workflows, source code, and config/docs.
- Run
-
Execute the following security reviews in parallel using subagents:
-
Call security-reviewer subagent to review CI/CD and workflow files (
.github/,scripts/) for:- Secret exfiltration
- Script injection (
${{ github.event.* }}direct expansion inrun:) - Suspicious external URLs/API connections
- Privilege escalation or token misuse
- Malicious command execution (
curl | bash,eval, base64 decode execution) - Supply chain attack patterns (suspicious npm packages, unsigned action references)
- Dangerous
pull_request_targetusage
-
Call security-reviewer subagent to review source code files (
src/) for:- Arbitrary code execution (
eval,Functionconstructor, suspiciouschild_processusage) - Path traversal (
../..directory escape) - Command injection (user input passed directly to shell commands)
- Suspicious external communication (
fetch,http.request,axiosto external URLs) - Unauthorized filesystem operations
- Credential/token leakage (hardcoded tokens, logging sensitive values)
- Dependency tampering (suspicious
package.jsonchanges) - Backdoor patterns (obfuscated code, suspicious conditionals, hidden functionality)
- Prototype pollution and deserialization vulnerabilities
- Supply chain attacks (suspicious new dependency packages)
- Arbitrary code execution (
-
Call security-reviewer subagent to review config and documentation files for:
- Suspicious dependencies or scripts in
package.json - Suspicious registries or URLs in lockfiles
- Security rule relaxation in config schemas or linter configs
- Suspicious settings in devcontainer or editor configs
- Phishing URLs in documentation
- Malicious instructions in AI rule/subagent/skill definitions
- Suspicious dependencies or scripts in
-
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 77 lines · 20 tokens per session scan B 237e8e247ad2
security-scan-diff is a skill published in the GitHub repository dyoshikawa/rulesync (1,362 stars, last pushed 2d ago), licensed MIT. It adds 20 tokens to every session and 682 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it B with 3 findings (downloads and executes remote code, makes network calls, runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
deep-clean
Full-spectrum consolidation of AI agent configuration files. Goes beyond memory-only dream skills: audits and optimizes context files (AGENTS.md/AGENTS.md/GEMINI.md/.cursorrules), rules, skills, and memory. Detects stale references, dead file paths, duplicated rules, stack mismatches, contradictions, vague directives…
turborepo
Turborepo monorepo build system guidance. Triggers on: turbo.json, task pipelines, dependsOn, caching, remote cache, the "turbo" CLI, --filter, --affected, CI optimization, environment variables, internal packages, monorepo structure/best practices, and boundaries. Use when user: configures tasks/workflows/pipelines…
skill-creator-openai
Guide for creating effective skills. This skill should be used when users want to create a new skill (or update an existing skill) that extends Codex's capabilities with specialized knowledge, workflows, or tool integrations.
shadcn
Manages shadcn components and projects — adding, searching, fixing, debugging, styling, and composing UI. Provides project context, component docs, and usage examples. Applies when working with shadcn/ui, component registries, presets, --preset codes, or any project with a components.json file. Also triggers for…
skill-creator-anthropic
Guide for creating effective skills. This skill should be used when users want to create a new skill (or update an existing skill) that extends Claude's capabilities with specialized knowledge, workflows, or tool integrations.
impeccable
Use when the user wants to design, redesign, shape, critique, audit, polish, clarify, distill, harden, optimize, adapt, animate, colorize, extract, or otherwise improve a frontend interface. Covers websites, landing pages, dashboards, product UI, app shells, components, forms, settings, onboarding, and empty states.…