sumsec-illustrations

sumsec-illustrations is a skill for Claude Code, Codex from SummerSec/SumSec-Skills. It costs 316 tokens per session (3,381 once invoked), scanned A, original, Apache-2.0.

An illustration guide for creating Chinese technical-article artwork, image prompts, and editing suggestions, often using a recurring security-researcher character.

In plain words
What is it for?
It is for planning or generating article images about security research, AI agents, engineering practices, and related subjects.
Why use it?
It helps turn technical ideas, workflows, and security topics into clear, memorable editorial illustrations.

Skill for Claude CodeCodex

Written for Claude Code and Codex: ${CLAUDE_SKILL_DIR} variable, but also agents/openai.yaml present.

Part of the writing-zh plugin — 2 skills shipped together

Good fit It is for planning or generating article images about security research, AI agents, engineering practices, and related subjects.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/summersec/sumsec-skills/sumsec-illustrations
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add SummerSec/SumSec-Skills --skill sumsec-illustrations
Clone the repo
git clone --depth 1 https://github.com/SummerSec/SumSec-Skills

Made for: Claude Code, Codex.

Or install writing-zh, the plugin that ships this one along with the rest of its 2 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for sumsec-illustrations

README.md
[![agentmods](https://agentmods.dev/badge/skills/summersec/sumsec-skills/sumsec-illustrations.svg)](https://agentmods.dev/skills/summersec/sumsec-skills/sumsec-illustrations)
Your own site
<a href="https://agentmods.dev/skills/summersec/sumsec-skills/sumsec-illustrations"><img src="https://agentmods.dev/badge/skills/summersec/sumsec-skills/sumsec-illustrations.svg" alt="Measured on agentmods" height="20"></a>
Per session 316 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 3,381 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00316 $0.03381
Opus 5 $0.00158 $0.01690
Sonnet 5 $0.00063 $0.00676
Haiku 4.5 $0.00032 $0.00338

Measured 4d ago against content hash d48f71eb20c4, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade A, and why

sumsec-illustrations scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

writing-zh/skills/sumsec-illustrations/SKILL.md · 135 lines

How it starts

The opening of the file, as written. The whole thing — 135 lines — stays where its author put it; the contents beside it link to each section on GitHub.

SumSec Observer 正文配图

核心定位

为 sumsec.me 风格中文文章设计和生成 16:9 横版正文配图,也可产出单张图的生成 prompt 或修改建议。目标不是做商业插画、PPT 信息图或可爱卡通,而是把安全研究、AI Agent、Skill 仓库、工具链和工程实践里的关键判断、流程、结构、状态或隐喻,变成一张清爽、冷幽默、有记忆点、可读但不说明书的手绘解释图。

默认人物角色是“SumSec Observer”:SumSec 在白纸工程草图里的个人化分身。它是克制、冷静、长期写 sumsec.me、做安全研究、Agent 工程和个人 Skill 仓库的人,而不是品牌吉祥物。${CLAUDE_SKILL_DIR}/assets/sumsec-observer-target.png 是 SumSec Observer 的人物生成形象模板图;所有实际生图/重生成都必须参考它来约束人物一致性。生成正文配图时可以换构图,但不要重设计角色。

稳定外观必须贴近目标图:年轻成人比例、自然挺直的脊背与稳定站姿、深炭干净轮廓线、少量发丝线、深墨或深棕黑短发、略凌乱侧分、柔软碎发压住部分额头、细框眼镜、窄而清醒的低情绪眼神、安静克制的轻微工作疲惫感、干净下颌、无胡子/胡茬/小胡子。稳定服装与物件必须保留:浅冷灰高领轻量连帽夹克、暗青蓝内衬和拉绳、黑色内搭、深色裤子、胸前暗青蓝斜挎包带、侧身灰褐工具包、黑色夹板/平板、日志纸、便签、小夹子、细小青蓝线缆、红橙证据标签、小工作证式 SummerSec 铭牌、两枚青蓝 S 戒指和一个黑色 S 工具芯片。人物本身不能只是黑白线稿;默认要有克制的色彩锚点:浅冷灰夹克、暗青蓝内衬/包带、很浅的暖肤色面部与手部、深墨色头发、灰褐工具包。SummerSec 铭牌默认优先做成胸前工作证/调查牌,挂在胸前拉链旁、夹克胸口或斜挎包带经过胸前的位置;全身构图中可移到工具包或卡扣,但仍要小而可读。SummerSec 徽记以人物手指上的两个低调 S 徽记戒指作为固定识别件出现,也可作为工具芯片、证据封签或小铭牌参与结构,但不能取代人物。

先读这些参考

按任务需要读取,不要一次塞满上下文;工具调用语义中以 ${CLAUDE_SKILL_DIR} 为根定位资源。

  • ${CLAUDE_SKILL_DIR}/references/style-dna.md:风格 DNA、颜色、文字、禁忌。
  • ${CLAUDE_SKILL_DIR}/references/sumsec-observer.md:SumSec Observer 的个人形象、稳定外观、动作库和禁忌。
  • ${CLAUDE_SKILL_DIR}/references/composition-patterns.md:结构类型、原创隐喻方法和反复刻规则。
  • ${CLAUDE_SKILL_DIR}/references/prompt-template.md:单张生图提示词模板。
  • ${CLAUDE_SKILL_DIR}/references/qa-checklist.md:生成后检查和迭代规则。
  • ${CLAUDE_SKILL_DIR}/assets/sumsec-observer-target.png:SumSec Observer 人物生成形象模板图;优先提取表情、发型、夹克结构、暗青蓝包带、工具包、夹板、日志纸、证据牌、戒指、工具芯片与设定图信息密度。只要进入“实际生成图片 / 重生成图片 / 局部改图后输出成图”流程,就必须参考这张图来保持人物情绪、衣服物件系统和身份锚点;若当前生图工具支持参考图输入,优先把它一起提供给工具,但这不是硬门槛。生成正文配图时不要复刻整张 character sheet 布局;用户明确要“角色设定图 / 个人形象 prompt / 提取图片提示词”时,可复用“大半身 + 3/4 工作姿态 + 小图标形态 + 戒指/工具芯片 callout”的设定图结构。 不要依赖旧案例图生成角色;本 skill 当前以文字规则定义 SumSec 专属人物角色。

工作流

1. 消化正文

先读用户给的正文、链接、Notion 页面、Markdown 文件或截图内容。提炼:

  • 核心观点是什么
  • 哪些段落承担认知转折
  • 哪些内容适合用图解释
  • 哪些地方只适合文字,不需要图

不要平均配图。优先选择“认知锚点”,例如:核心判断、两个断点、输入输出闭环、分流、前后对比、一鱼多吃、承接路径、常见坑、角色状态变化。

2. 判断输出类型

  • 用户说“分析怎么配图 / 哪些地方需要配图 / shot list”:只输出配图策略,不生成图片。
  • 用户说“给我 prompt / 优化个人形象 prompt / SumSec Observer 设定 / 设计一套人物形象 / 提取这张图的提示词”:输出可直接用于生图的角色 prompt、character sheet prompt 或单图 prompt,优先读取 ${CLAUDE_SKILL_DIR}/references/sumsec-observer.md${CLAUDE_SKILL_DIR}/references/prompt-template.md。如果用户给的是 ${CLAUDE_SKILL_DIR}/assets/sumsec-observer-target.png 或同类角色设定图,使用“角色设定图提示”分支:保留大半身、3/4 工作姿态、小图标形态、双 S 戒指、工具芯片、手写 callout、冷灰夹克、暗青蓝包带、工具包和工作中气质;说明这是基于画面反推的稳定 prompt,不要声称是原始 prompt。若后续真的执行生图,仍必须参考 ${CLAUDE_SKILL_DIR}/assets/sumsec-observer-target.png;若工具支持参考图输入,可一并传入,但不是强制。
  • 用户给参考图并说“提取人物特征 / 基于这个角色 / 增加铭牌”:先提取可复用人物锚点,再把变化写成局部增量;优先保持深色凌乱短发、细框眼镜、冷灰夹克、暗青蓝包带、斜挎工具包、双 S 戒指和胸前工作证式 SummerSec 铭牌,不把参考图里的标题、布局说明或边角小样照搬到成图。
  • 用户说“生成 / 输出 / 做图 / 帮我生成”:直接生成图片,不停下来等确认。
  • 用户给已有图并说“去标题 / 改图 / 更像 SumSec”:给局部编辑或重生成 prompt,优先保持构图,只修问题。

Read the full file on GitHub · 135 lines

Files

What ships with it

7 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 135 lines · 316 tokens per session scan A d48f71eb20c4

Subscribe to this mod's changes

sumsec-illustrations is a skill published in the GitHub repository SummerSec/SumSec-Skills (8 stars, last pushed 23d ago), licensed Apache-2.0. It adds 316 tokens to every session and 3,381 once invoked, about $0.0016 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

gpt-image-2-style-library

Choose GPT-Image2 / gpt-image-2 visual styles and industrial prompt templates from the awesome-gpt-image-2 style library. Use when an agent needs to create, rewrite, classify, or improve image-generation prompts with repository-backed templates, categories, style tags, scene tags, pitfalls, and example cases.

freestylefly/awesome-gpt-image-2 · 72 tokens

dsh-web-pet-developer

Create a pet for the dsh-pet plugin and integrate it into the dsh web GUI — author a v2 pet.json manifest plus an 8-column x 9-row atlas per the Codex/hatch-pet contract (live2d pets, voice packs and status decorations included), drop it into the pet-center user directory or contribute it as a built-in asset under…

zhu1090093659/dsh-web · 162 tokens

superdesign

Design or redesign frontend UI, presentations, and graphics on the Superdesign canvas with a choice of leading AI models. Use whenever the user wants to design a page, feature, flow, slide deck, or brand-new product; improve or reproduce existing UI; compare design results across top models; explore visual variants…

superdesigndev/superdesign-skill · 115 tokens

yao-image

Image expert. ALWAYS invoke this skill when you need to read, analyze, describe, or generate images. Use for screenshots, photos, charts, diagrams, AI-generated images, or any visual content.

YaoApp/yao · 44 tokens

yao-audio

Audio expert. ALWAYS invoke this skill when the user asks to transcribe, recognize, or convert speech/audio to text.

YaoApp/yao · 29 tokens

agent-first-screenshots

Agent-first screenshots — an agent drives the real app via CDP and produces clean, defect-free product screenshots (newsletters, landing pages, social, decks, PR). Dual-channel verification (DOM + pixels + vision) in a capture loop. Use for any "take/redo screenshots of the app" task.

Devin-AXIS/iPolloWork · 69 tokens