SkillAtlasSkill 详情

security

Essays and writing behind this toolkit live at vexjoy.com.

审核状态:已审核Quality 72Security 70

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年9月19日

VexJoy Agent

VexJoy Agent

Essays and writing behind this toolkit live at vexjoy.com.

VexJoy Agent connects plain-English requests to specialist agents, skills, and workflows. /do selects the knowledge and tools needed for your task. Hooks enforce specific checks, and scripts handle repeatable work.

The aim is to give capable models useful domain knowledge without making you learn the toolkit's catalog.

43 domain agents, 59 workflow skills, 78 hooks, 153 scripts. Agents carry knowledge, skills enforce methodology, hooks block incomplete work, scripts handle determinism.

Works across Claude Code (/do), Codex ($do), Factory (/do), Reasonix (/do).

What It Looks Like

$ claude

> /do debug this Go test

  Routing: go-engineer + systematic-debugging
  Phase 1/4: Reproduce: running test, capturing failure...
  Phase 2/4: Hypothesize: 3 candidates from stack trace...
  Phase 3/4: Verify: isolated root cause in connection pool timeout
  Phase 4/4: Fix: patch applied, test passing, PR opened

  ✓ Delivered: PR #847, fix connection pool timeout in health check

The router pairs a Go agent with a debugging skill, then follows the task through verification and delivery.

The Pipeline

  ROUTE        PLAN         EXECUTE      VERIFY       DELIVER      RECORD
 ┌──────┐    ┌──────┐    ┌──────┐    ┌──────┐    ┌──────┐    ┌──────┐
 │ /do  │───▶│ Task │───▶│Agent │───▶│Tests │───▶│  PR  │───▶│Route │
 │Router│    │ Plan │    │+Skill│    │Gates │    │Branch│    │Result│
 └──────┘    └──────┘    └──────┘    └──────┘    └──────┘    └──────┘

/d — Jev-Powered Router

/d routes requests through TypeSafe's Jev classifier. One API call picks the agent, skill, and pipeline — no manifest read into context. Requires Jev; use /do if TypeSafe is not configured.

Setup: install the typesafe MCP plugin and set TYPESAFE_API_KEY in your environment.

> /d fix the flaky test in the payments module

  ROUTING (/d): testing-automation-engineer + testing-preferred-patterns
  Source: jev (confidence: medium)
  Invoking...

Anti-Rationalization

Checks require evidence rather than confidence.

Agent SaysWhat Happens
"Code looks correct, skip tests"Exit gate requires test output. Blocked.
"Trivial change, no verification"Hook blocks completion without evidence.
"Similar to before"Skill demands case-specific proof.
"User is in a hurry"Protocol overrides time pressure.
"I'm confident"Gate demands exit code, not assertion.

Hooks run at configured events. Skills state what to verify; blocking78 hooks enforce the checks they cover. Coverage depends on the runtime and tool path.

Knowledge Work Is First-Class

The content engine researches, drafts in a calibrated voice, checks 397 writing patterns, and adapts finished pieces for each platform. /html produces a self-contained report, slide deck, prototype, chart, or diagram. It needs no coding or setup beyond installation.

It Proves Its Own Changes

Toolkit changes use direct review and relevant checks. Model comparisons can settle specific uncertainties; they are not required for every edit. PHILOSOPHY.md explains the validation policy. what-didnt-work.md records failed experiments, routing reversals, unvalidated A/B citations, disabled lint rules, and program refutations.

The automated nightly evolution loop (/evolve, writes to evolution-reports/) ran regularly through mid-May 2026. It is currently dormant; recent evidence has come from manual PRs instead.

Installation

git clone https://github.com/notque/vexjoy-agent.git ~/vexjoy-agent
cd ~/vexjoy-agent
./install.sh

Installs into ~/.claude/ and mirrors into ~/.codex/, ~/.factory/, and ~/.reasonix/ when the runtime command is on PATH or its home directory exists. Choose symlinks for live updates through git pull, or copies for a stable snapshot.

Want only part of the toolkit? Run ./install.sh --configure to pick which skills, agents, and78 hooks install, or copy .local.example/profile.yaml to .local/profile.yaml and edit. No profile file = full install, unchanged behavior. Credit: @thomasvan. Details: .local.example/README.md.

CLIEntry Point
Claude Code/do
Codex$do
Factory/do
Reasonix/do

Jev Auto-Compact plugin (optional, requires TYPESAFE_API_KEY):

claude plugin marketplace add ./plugins/jev-auto-compact
claude plugin install jev-auto-compact@jev-auto-compact -y

Replaces LLM-generated compaction summaries with Jev-judged verbatim pruning. Once context reaches 60%, Jev evaluates each old tool call (keep, truncate result, or drop) and returns the pruned transcript with zero rewriting, in about a second instead of one to three minutes. The threshold matters: every compaction is a cold KV-cache rewrite of the prefix, so compacting every turn multiplies cost. Evidence lives in learning.db (python153 scripts/jev-compact-evidence.py).

Proof it works: python153 scripts/jev-compact-evidence.py prints every compaction from two sources side by side — the plugin's claim and the engine's own compact_boundary record (tokens before/after, duration). A Jev compaction shows as a sub-second engine record next to a matching plugin claim; a built-in LLM compaction shows as a 30–150s record. Rows live in ~/.claude/learning/learning.db (compaction_events, session_usage).

Full setup: docs/start-here.md

Codex CLI Parity

Mirrors agents, skills, and supported78 hooks into ~/.codex/. The original six-hook allowlist was correct for Codex v0.114, when tool hooks only intercepted Bash. Current support requires Codex v0.144.1+ and classifies the 62 Claude hook registrations as 26 native, 27 adapter-backed, and 9 unsupported (53 supported). These are registration counts, not unique hook files. The installer also preserves explicit per-subagent model routing for GPT-5.6 Sol by setting the MultiAgent V2 compatibility keys documented in openai/codex#31814.

Codex now exposes apply_patch to tool78 hooks. VexJoy's adapter converts each patch operation into the Write/Edit payload expected by existing guards, but it cannot intercept writes performed through unified_exec, unmatched MCP tools, WebSearch, or other unsupported tool paths. PreCompact and Stop adapters also receive less telemetry than Claude Code: Codex does not provide Claude's conversation_history or session_data. This is expanded compatibility, not full Claude parity.

After install or any hook-definition change, run /hooks in Codex and review the new definitions before trusting them. Codex hash-trusts hook commands and skips changed, unreviewed definitions.

Gemini CLI / Antigravity CLI Support (removed)

Gemini CLI support removed (deprecated upstream, transitioned to Antigravity CLI); Antigravity support pending CLI maturity. Per Google's transition announcement, Gemini CLI stops serving requests on 2026-06-18 for Google AI Pro / Ultra and free Gemini Code Assist for individuals. Gemini API integrations (image-gen backends, sprite pipeline, GEMINI_API_KEY) are unaffected and stay in the toolkit.

If a prior install mirrored into ~/.gemini/, remove the stale mirrors with:

rm -rf ~/.gemini/skills ~/.gemini/agents ~/.gemini/hooks ~/.gemini/scripts ~/.gemini/antigravity/plugins/vexjoy-agent
Factory CLI Support

Mirrors agents (as "droids"), skills, and all78 hooks into ~/.factory/. Hook config merges into ~/.factory/settings.json with paths rewritten.

Reasonix Support

Mirrors skills, 153 scripts, and the allowlisted 78 hooks (scripts/reasonix-hooks-allowlist.txt) into ~/.reasonix/ (no agent or custom-command surface, so neither is installed; the /do router rides in as a skill). Reasonix fires only 4 events (PreToolUse, PostToolUse, UserPromptSubmit, Stop), so only hooks for those events are allowlisted. Hook config is written to the hooks key of ~/.reasonix/settings.json in Reasonix's native flat shape (one entry per hook, match regex over the tool name); the generator builds absolute python3 commands, so no path rewrite is applied. MCP/model/permissions in ~/.reasonix/config.json are user-owned and left untouched.

Token-saving mode

The toolkit supplies its own routing, domain knowledge, methodology, and enforcement. The default system prompt duplicates most of that.

claude --system-prompt "."

Strips built-in tool-use instructions. The toolkit's agents, skills,78 hooks, and CLAUDE.md provide equivalent coverage.

Four Layers

LayerCountDoes
Agents43Domain knowledge: idiom tables, failure mode catalogs, error-to-fix mappings
Skills59Phased methodology with gates. Can't skip steps. Each phase has exit criteria requiring evidence.
Hooks78Fire on lifecycle events. Block incomplete work. Zero LLM cost.
Scripts153Determinism: test runners, linters, validators. No LLM judgment.

Full skill catalog: docs/skills.md.

┌─────────────────────────────────────────────────┐
│  SKILL.md                                       │
│  ┌─ Frontmatter ─────────────────────────────┐  │
│  │ triggers, pairs_with, success-criteria     │  │
│  └────────────────────────────────────────────┘  │
│  Reference Loading Table (conditional imports)   │
│  Phased Instructions (numbered, with gates)      │
│  Verification (evidence requirements)            │
└─────────────────────────────────────────────────┘

Built with the Toolkit

A game built entirely by Claude Code using these agents, skills, and pipelines:

Choose Your Path

I just want to use it Install, learn /do, done.

I do knowledge work Writing, research, data analysis, moderation, HTML artifacts. No code.

I'm a developer Architecture, extension points, adding agents and skills.

I'm an AI power user Routing tables, pipelines,78 hooks, telemetry DB.

I'm an AI agent Machine-dense inventory. Tables, paths, schemas.

I'm on LinkedIn 🚀 Thought leadership. Agree? 👇

Philosophy

  • Zero-expertise operation. Say what you want. The system classifies, dispatches, enforces, delivers.
  • LLMs orchestrate, programs execute. Deterministic work belongs to153 scripts. LLM judgment handles design decisions, diagnosis, review.
  • Density. Every word carries instruction, rule, or decision. Cut everything else.
  • Breadth over depth. Right context ensures correctness. Unfocused context adds cost.
  • Structural enforcement. Exit codes enforce what instructions can't. Quality gates are automated, not advisory.
  • Everything pipelines. Complex work decomposes into phases. Phases have gates. Gates prevent cascading failures.

Full design philosophy: PHILOSOPHY.md

Maintenance

One report-only script surfaces upkeep work; it prints a digest and never edits, deletes, or blocks.

  • python153 scripts/stale-skill-scan.py --top 20 ranks stale skills and agents as pruning candidates. Run it quarterly; see docs/deprecation-template.md.

Scheduled work follows the same boundary as everything else: judgment uses agents; repeatable plumbing uses153 scripts.

NeedUse
Run a deterministic command on a schedulescripts/agent-scheduler.py with runner: "command"
Run an agent judgment on a schedule, webhook, or file changescripts/agent-scheduler.py with the default runner: "claude"
Install or remove a user crontab entry safelyscripts/crontab-manager.py
Audit shell cron reliabilitycron-automation
Keep one interactive objective moving until criteria verifyobjective-loop

Contributing

See CONTRIBUTING.md.

License

MIT. See LICENSE.

其他

中风险

  • 来源需自行核对维护者身份。
  • 包含脚本或命令调用,安装前请复核。
  • 可能需要外部 token、网络权限或第三方服务。
  • 未检测到高风险命令。
  • 扫描发现:1 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/notque/vexjoy-agent.git
  3. 将 "skills/review/security" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/notque/vexjoy-agent.git
  3. 将 "skills/review/security" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/notque/vexjoy-agent.git
  3. 将 "skills/review/security" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/notque/vexjoy-agent.git
  3. 将 "skills/review/security" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/notque/vexjoy-agent.git
  3. 将 "skills/review/security" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: security
description: "Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks."
user-invocable: true
allowed-tools:
  - Read
  - Write
  - Bash
  - Grep
  - Glob
  - Edit
  - Task
  - Agent
agent: reviewer-system
routing:
  force_route: true
  not_for: "general code review (use review), non-security quality checks (use code-quality) — only for security-specific work: vulnerability scanning, threat modeling, supply-chain audits, auth reviews"
  triggers:
    - "security review"
    - "review my changes for security"
    - "review my changes"
    - "review for security"
    - "security scan"
    - "review for vulnerabilities"
    - "scan for vulnerabilities"
    - "check for security issues"
    - "security issues"
    - "audit for vulnerabilities"
    - "audit auth"
    - "audit vulnerabilities"
    - "threat model"
    - "security audit"
    - "supply chain scan"
    - "deny list"
    - "security posture"
    - "injection scan"
    - "surface scan"
    - "audit hooks"
    - "audit skills"
  category: security
  pairs_with:
    - review
    - reviewer-system

Security Skill

Two modes: diff review (scan current git changes for vulnerabilities) and threat model (audit a system's full attack surface). Load the reference for the mode the request matches.

Reference Loading Table

SignalLoadWhy
Review git changes, scan a diff, check for vulnerabilitiesreferences/coverage.md40 vulnerability classes for LLM-depth review of changed code
Threat model, attack surface, supply-chain audit, deny list, security posturereferences/threat-model.md5-phase threat model workflow with deterministic scripts and artifact gates

Default Mode: Diff Review

When the request is about reviewing changes (not a full threat model), run the diff review directly. This is the common case.

Security Review Skill

Run a two-layer security review over the current git changes: a deterministic regex scan for known vulnerability classes, then an LLM-depth Security review of the diff. Report a single BLOCK / FIX / APPROVE verdict.

The LLM-depth review runs inside the current Claude session — the same subscription that loaded this skill. There is no separate model call, no ANTHROPIC_API_KEY, no Agent SDK, and no network request. The "reviewer" is the session agent executing the steps below, exactly like every other skill here.

Detection reaches parity with Anthropic's security-guidance plugin: the scanner ports its 25 deterministic patterns, and the LLM pass applies its full review taxonomy (loaded on demand from references/coverage.md).

Reference Loading Table

SignalLoadWhy
Running Phase 3 (LLM-depth review); classifying a finding; needing the vuln taxonomy, severity rubric, FP exclusions, or per-language guidancereferences/coverage.md40 vulnerability classes + 4-tier severity + false-positive exclusions + per-language guidance + the 12 high-miss reviewer classes + the finding output schema.

Instructions

Phase 1: SCOPE

Goal: Determine the changed files to review before scanning.

Step 1: List changed files — scope to the working-tree and staged changes so the review covers exactly what the user is about to commit, not the whole repo.

# Tracked changes (working tree + index) plus staged adds:
git diff --name-only HEAD
git diff --cached --name-only --diff-filter=ACM

Step 2: Read repository CLAUDE.md to load project conventions the reviewer must respect (e.g. secrets-handling rules, allowed patterns).

Gate: Changed files listed. When the list is empty, report "no changes to review" and stop — there is nothing to scan.

Phase 2: DETERMINISTIC SCAN

Goal: Run the regex engine first so judgment time is spent on real signal, not on patterns a script catches deterministically.

Step 1: Run the scanner over the changed files. It is the single source of detection rules (secrets, SQL injection, shell injection, dangerous eval, unsafe deserialization). Exit 1 means at least one HIGH/CRITICAL finding.

# Staged-files convenience (matches the commit-time hook):
python3 scripts/security-review-scan.py --staged --format json

# Or an explicit list from Phase 1:
python3 scripts/security-review-scan.py --files <changed-files> --format json

Step 2: Record the findings by severity. CRITICAL and HIGH are blocking-class; MEDIUM is advisory. Keep the file:line and rule for each.

Gate: Scanner ran and JSON parsed. Proceed with the findings in hand.

Phase 3: LLM-DEPTH REVIEW

Goal: Catch what regex cannot — authorization gaps, injection through data flow, missing input validation, secrets in non-obvious forms. This is the session agent's review of the diff; compose the existing parallel-code-review Security reviewer over the changed files.

Step 1: Load references/coverage.md — the full review taxonomy (40 vulnerability classes, the 4-tier severity rubric, the false-positive exclusion list, per-language guidance, and the 12 high-miss reviewer classes). Review to this taxonomy so the session-agent pass reaches parity with the plugin's reviewer. If claude-security-guidance.md exists (precedence: ~/.claude/ → <cwd>/.claude/ → <cwd>/.claude/*.local.md), read it as ADDITIVE context — it may add checks or raise a class's severity, and must not suppress findings.

Step 2: Dispatch the Security reviewer (the Reviewer 1 — Security role from parallel-code-review) over the changed files via the Task tool, applying the coverage.md taxonomy. Surface medium and above. Output: findings in the coverage.md schema (filePath, category, vulnerableCode, explanation, fix, severity) with file:line references.

Step 3: Merge the LLM findings with the Phase 2 scanner findings. Deduplicate — when both flag the same file:line, keep one entry at the higher severity. Independent confirmation by both layers raises confidence.

Gate: Security reviewer returned results and findings are merged. Issue a verdict only from a completed review — a missing reviewer may hold the only CRITICAL finding.

Phase 4: VERDICT

Goal: Produce a single clear recommendation.

Step 1: Determine the verdict from the merged findings:

ConditionVerdict
Any CRITICAL findingBLOCK
HIGH findings, no CRITICALFIX (resolve before commit)
Only MEDIUM/LOW findingsAPPROVE (with suggestions)

Step 2: Output the structured report:

## Security Review Complete

### Severity Matrix
| Severity | Count | Source (scanner / reviewer / both) |
|----------|-------|------------------------------------|
| Critical | N | ... |
| High     | N | ... |
| Medium   | N | ... |

### Findings
#### CRITICAL (Block)
1. [source] description — file:line

#### HIGH (Fix before commit)
1. [source] description — file:line

#### MEDIUM (Should fix)
1. [source] description — file:line

### VERDICT
**BLOCK / FIX / APPROVE** — [1-2 sentence rationale]

Gate: Structured report delivered with an explicit verdict. Review complete.


Automatic Coverage (hooks)

This skill is the on-demand (PULL) path. The same review also runs automatically (PUSH) via hooks/security-review-hook.py, wired in .claude/settings.json:

EventBehavior
PreToolUse (Bash git commit)Scans STAGED files with the same scanner. A HIGH/CRITICAL finding blocks the commit (deny). Clean commits pass.
StopRe-wakes the session with the working-tree diff and an instruction to run this pipeline. Advisory — never blocks.

Bypass / kill switches (commit-time block only, deliberate overrides):

Env varEffect
VEXJOY_SECURITY_REVIEW_SKIP=1Allow a commit through despite findings (one-off override).
VEXJOY_SECURITY_REVIEW_DISABLE=1Disable the hook entirely (both events).

The hook fails open on any internal error — a hook crash never blocks a commit.


Extensibility (custom rules + project guidance)

Both extension points are additive and discovered in this precedence order: ~/.claude/<name> → <cwd>/.claude/<name> → <cwd>/.claude/<name>.local.<ext>.

FileEffect
security-patterns.{yaml,json}Custom regex/substring rules merged into the scanner's built-ins. Shape: {"patterns": [{"rule_name", "regex"|"substrings", "severity"?, "paths"?, "exclude_paths"?}]}. Capped at 50. ReDoS-prone or invalid rules are skipped with a stderr warning (non-fatal). PyYAML is used only if importable — JSON always works (stdlib-only).
claude-security-guidance.mdMarkdown surfaced to the Phase 3 review as ADDITIVE context. It may add checks or raise a class's severity; it must not suppress findings — if it says to ignore a class, flag the vulnerability anyway and note the conflict.

Built-in scanner rules always run and cannot be disabled by a config file.


Error Handling

Scanner reports findings but the code is intentional

Cause: A regex rule flagged a test fixture, an example, or a deliberately hardcoded local value. Solution: Confirm context in Phase 3. Downgrade in the report with a one-line justification. For a commit the user knows is safe, document the VEXJOY_SECURITY_REVIEW_SKIP=1 override rather than editing the scanner rules.

Security reviewer times out or returns nothing

Cause: Task agent exceeded its budget, or the diff was too large. Solution: Report the Phase 2 scanner findings immediately (a partial review beats no review), note the LLM-depth gap in the verdict, and offer to re-run the Security reviewer on a reduced file set.

Scanner unavailable

Cause: scripts/security-review-scan.py missing from the working tree. Solution: Run the Phase 3 LLM-depth review alone and state in the verdict that the deterministic layer did not run.


References

  • Detection rules: scripts/security-review-scan.py (single source of truth)
  • Review taxonomy (40 classes + severity + FP filters + language guidance): references/coverage.md
  • Security reviewer role: skills/review/parallel-code-review/SKILL.md (Reviewer 1)
  • Auto-run hook: hooks/security-review-hook.py
  • Design contract: adr/local-security-review.md

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!