security is agent-read markdown (skill) from notque/vexjoy-agent: Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Security Skill
Two modes: **diff review** (scan current git changes for vulnerabilities) and
**threat model** (audit a system's full attack surface). Load the reference for
the mode the request matches.
## Reference Loading Table
| Signal | Load | Why |
|---|---|---|
| Review git changes, scan a diff, check for vulnerabilities | `references/coverage.md` | 40 vulnerability classes for LLM-depth review of changed code |
| Threat model, attack surface, supply-chain audit, deny list, security posture | `references/threat-model.md` | 5-phase threat model workflow with deterministic scripts and artifact gates |
## Default Mode: Diff Review
When the request is about reviewing changes (not a full threat model), run the
diff review directly. This is the common case.
# Security Review Skill
Run a two-layer security review over the current git changes: a deterministic
regex scan for known vulnerability classes, then an LLM-depth Security review of
the diff. Report a single BLOCK / FIX / APPROVE verdict.
**The LLM-depth review runs inside the current Claude session** — the same
subscription that loaded this skill. There is no separate model call, no
…
Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
A 17 of 17 checks passed. Deterministic, no model, same answer every run.
pass: Frontmatter block present
pass: Frontmatter declares a name
pass: Frontmatter declares a description
pass: Size between 200 bytes and 200 KB (10477 bytes)
pass: No zero-width or bidi control characters
pass: No instruction hidden inside an HTML comment
pass: No link to an exfiltration or paste host
pass: No credential-shaped string
pass: No instruction to send local credentials anywhere
pass: No text hidden with inline styles
pass: No prompt-injection phrasing
pass: No curl or wget piped into a shell
pass: No recursive delete of root, home or parent
pass: No instruction to read or print local credentials
pass: No base64 blob over 200 characters
pass: No link to a raw IP address
pass: No script tag
Source
GitHub
notque/vexjoy-agent · 424 stars · license MIT · pushed 2026-09-23 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_uph2d6seclntq24b
GET https://markdownregistry.com/api/v1/resolve?ref=notque/vexjoy-agent/security
GET https://markdownregistry.com/api/v1/blob/d202643f5ef38b439cb79930a0dbcf05c47d9852749dd09cec834c716878be01
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
boshu2/agentops · skills/security/SKILL.md · Review code or scan for security vulnerabilities, secrets, dependencies and prompt risks. Use when: concrete exposure…
boshu2/agentops · images/gemini/skills/security/SKILL.md · Review code or scan for security vulnerabilities, secrets, dependencies and prompt risks. Use when: concrete exposure…
boshu2/agentops · skills-codex/security/SKILL.md · Review code or scan for security vulnerabilities, secrets, dependencies and prompt risks. Use when: concrete exposure…
openhands/extensions · skills/security/SKILL.md · Security best practices for secure coding, authentication, authorization, and data protection. Use when developing…