Creator ยท ghostsecurity
Last updated ยท Sep 3, 2026
Ghost Security โ combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary,
Creator ยท ghostsecurity
Last updated ยท Sep 3, 2026
Ghost Security โ combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary,
Creator ยท ghostsecurity
Last updated ยท Sep 3, 2026
Ghost Security โ combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary,
Creator ยท ghostsecurity
Last updated ยท Sep 3, 2026
Ghost Security โ combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary,
Sandbox only
Install targets
Codex install prompt
Install the "ghost-report" agent skill from https://github.com/ghostsecurity/skills/tree/main/plugins/ghost/skills/report. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Ghost Security โ combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary, full security audit, or combined scan results. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"ghostsecurity-ghost-report","task":"Install ghost-report","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Document processing
I need my agent to read PDFs, extract tables, and turn documents into structured data.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add ghostsecurity/skills --skill ghost-report
Maintenance
fresh
3d since push
Risk
Safe to try
Quality score needs review
GitHub quality
405
73/100 Quality ยท 78/100 Trust
Coverage tags
Review notes
Quality score needs review ยท Stars/forks activity: 405 stars, 26 forks; issue activity unavailable in current metadata
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Safe to tryA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
405 GitHub stars
Repo activity
405 stars, 26 forks
Maintenance
3d since push
License
apache-2.0
Install
npx skills add ghostsecurity/skills --skill ghost-report
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add ghostsecurity/skills --skill ghost-reportDo not use when
Agent safety v2
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20ghost-report%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20ghost-report%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/ghostsecurity-ghost-report/install
Agent should check
Copy prompt
Task: Use ghost-report in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20ghost-report%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/ghostsecurity-ghost-report/install
Install command: npx skills add ghostsecurity/skills --skill ghost-report
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/ghostsecurity-ghost-report/install
LLM text format
/api/skills/ghostsecurity-ghost-report/install?format=text
Find alternatives
/api/skills/search?q=ghost-report&limit=3
Agent prompt
Use ghost-report for this task. Review https://www.openagentskill.com/api/skills/ghostsecurity-ghost-report/install, then install with: npx skills add ghostsecurity/skills --skill ghost-reportRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/ghostsecurity-ghost-report
LLM text
/api/registry/manifest/ghostsecurity-ghost-report?format=text
Install alias
/api/registry/install/ghostsecurity-ghost-report
Recommend
/api/registry/recommend?task=Use%20ghost-report%20in%20an%20agent%20workflow&limit=3
Agent fit
Security and compliance
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Security and compliance
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO405 GitHub stars
Stars/forks activity
CHECK405 stars, 26 forks; issue activity unavailable in current metadata
Recent maintenance
PASS3d since push
License clarity
PASSapache-2.0
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Parse messy files
I need my agent to read PDFs, extract tables, and turn documents into structured data.
Publish consistently
I need my agent to turn research and product updates into useful content drafts.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Scrape, clean, and reuse web data
A practical workflow for agents that crawl public pages, extract clean content, normalize data, and hand it to downstream research or RAG workflows.
Inspect, patch, and verify code
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Alternative shortlist
Similar skills that may fit this task.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
๐ต๏ธโโ๏ธ Collect a dossier on a person by username from 3000+ sites
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
--- name: "ghost-report" description: "Ghost Security โ combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary, full security audit, or combined scan results." allowed-tools: Read, Write, Edit, Glob, Grep, Bash license: apache-2.0 metadata: version: 1.1.0 ---
# Combined Security Report
You aggregate findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report. Do all work yourself โ do not spawn subagents or delegate.
$ARGUMENTS
---
## Step 0: Setup
Run this Bash command to compute paths: ```bash repo_name=$(basename "$(pwd)") && remote_url=$(git remote get-url origin 2>/dev/null || pwd) && short_hash=$(printf '%s' "$remote_url" | git hash-object --stdin | cut -c1-8) && repo_id="${repo_name}-${short_hash}" && short_sha=$(git rev-parse --short HEAD 2>/dev/null || date +%Y%m%d) && ghost_repo_dir="$HOME/.ghost/repos/${repo_id}" && scans_dir="${ghost_repo_dir}/scans/${short_sha}" && cache_dir="${ghost_repo_dir}/cache" && skill_dir=$(find . -path '*/skills/report/SKILL.md' 2>/dev/null | head -1 | xargs dirname) && echo "scans_dir=$scans_dir cache_dir=$cache_dir skill_dir=$skill_dir" ```
Store `scans_dir` (commit-level scan directory), `cache_dir`, and `skill_dir`.
---
## Cache Check
If `<scans_dir>/report.md` already exists, show:
``` Combined security report is at: <scans_dir>/report.md ```
And stop. Do not regenerate it.
---
## Step 1: Read Repo Context
Read `<cache_dir>/repo.md` if it exists. Extract: - Business criticality - Sensitive data types - Component map
If it does not exist, continue without it โ this is not an error.
---
## Step 2: Discover Scan Results
List the contents of `<scans_dir>` to see which scan-type directories exist. Recognized types: - `deps/` โ SCA / dependency vulnerability scan - `secrets/` โ secrets and credentials scan - `code/` โ code security scan (SAST)
If none of these directories exist, report an error:
``` No scan results found in <scans_dir>. Run one or more scan skills first: /ghost-scan-deps /ghost-scan-secrets /ghost-scan-code ```
And stop.
---
## Step 3: Collect Findings
For each scan type that exists, glob `<scans_dir>/<type>/findings/*.md` and read each finding file **in full**. Retain the complete markdown body of every finding โ the report will inline this content directly so readers never need to open individual finding files.
From each finding, also extract these metadata fields for filtering and sorting:
- **ID** โ from `## Metadata` โ `ID` - **Type** โ the scan type (`deps`, `secrets`, or `code`) - **Severity** โ from `## Metadata` โ `Severity` (high, medium, low) - **Status** โ from `## Metadata` โ `Status` (e.g., confirmed-exploitable, unverified, verified, rejected, clean)
---
## Step 4: Filter and Sort
**Filter:** Keep only high-confidence findings: - For `deps` findings: status is `confirmed-exploitable` - For `secrets` findings: status is NOT `clean` and NOT `rejected` - For `code` findings: status is `verified` or `unverified` (NOT `rejected`)
**Exclude** any finding with status `clean`, `rejected`, or `false-positive`.
**Sort** the remaining findings: 1. By severity: high first, then medium, then low 2. Within same severity: deps before secrets before code
---
## Step 5: Read Per-Scan Reports
For `deps` and `secrets` scan types, read `<scans_dir>/<type>/report.md` if present. Extract: - Statistics (candidates scanned, confirmed findings, false positives filtered) - Executive summary highlights
Note: `code` does not produce a `report.md`. For code scan coverage, count the finding files in `<scans_dir>/code/findings/` directly. The "Candidates Scanned" count is the total number of finding files (all statuses). "Confirmed Findings" is the count with status `verified`, `confirmed`, or `unverified`. "False Positives Filtered" is the count with status `rejected`. Do NOT count clean file analyses from the nomination/analysis funnel โ those never became findings.
If a per-scan report does not exist for deps or secrets, note it as unavailable.
---
## Step 6: Generate Report
1. Read `<skill_dir>/report-template.md` 2. Populate the template with collected data: - Fill Scan Information with repository name, commit SHA, date, and which scans ran - Write Executive Summary using repo context and aggregated findings - For all writing elements in this security-focused, objective and fact based report, use a neutral, human tone that balances expertise with ease of reading. Do not use emojis, em-dashes, etc. - For Critical & High findings (severity = high): inline the substantive content from each finding file directly into the report โ include code snippets, assessment tables, remediation commands, and all relevant detail so the report is fully self-contained - For Medium findings: write a full subsection per finding with description, location, code context, and remediation (not a condensed table) - Omit low-severity findings (they remain in per-scan finding files only) - Fill Scan Coverage table from per-scan report statistics (for code, use finding file counts from Step 5) - Add a brief methodology note per scan type that ran (1-2 sentences drawn from per-scan reports) - Do NOT include links to per-scan reports or individual finding files โ all content is inlined 3. Write the report to `<scans_dir>/report.md`
---
## Step 7: Show Output
``` Combined security report is at: <scans_dir>/report.md ```
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for ghost-report, ready for a manual X post.
A practical pick for the next repo task: ghost-report: Ghost Security โ combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) in... 405 stars https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=x
Listing + install path for ghost-report: https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=x Install: npx skills add ghostsecurity/skills --skill ghost-report
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to ghostsecurity but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/ghostsecurity-ghost-report/audit)
[](https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)ghostsecurity
@ghostsecurity
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
๐ต๏ธโโ๏ธ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K StarsSandbox only
Install targets
Codex install prompt
Install the "ghost-report" agent skill from https://github.com/ghostsecurity/skills/tree/main/plugins/ghost/skills/report. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Ghost Security โ combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary, full security audit, or combined scan results. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"ghostsecurity-ghost-report","task":"Install ghost-report","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Document processing
I need my agent to read PDFs, extract tables, and turn documents into structured data.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add ghostsecurity/skills --skill ghost-report
Maintenance
fresh
3d since push
Risk
Safe to try
Quality score needs review
GitHub quality
405
73/100 Quality ยท 78/100 Trust
Coverage tags
Review notes
Quality score needs review ยท Stars/forks activity: 405 stars, 26 forks; issue activity unavailable in current metadata
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Safe to tryA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
405 GitHub stars
Repo activity
405 stars, 26 forks
Maintenance
3d since push
License
apache-2.0
Install
npx skills add ghostsecurity/skills --skill ghost-report
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add ghostsecurity/skills --skill ghost-reportDo not use when
Agent safety v2
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20ghost-report%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20ghost-report%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/ghostsecurity-ghost-report/install
Agent should check
Copy prompt
Task: Use ghost-report in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20ghost-report%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/ghostsecurity-ghost-report/install
Install command: npx skills add ghostsecurity/skills --skill ghost-report
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/ghostsecurity-ghost-report/install
LLM text format
/api/skills/ghostsecurity-ghost-report/install?format=text
Find alternatives
/api/skills/search?q=ghost-report&limit=3
Agent prompt
Use ghost-report for this task. Review https://www.openagentskill.com/api/skills/ghostsecurity-ghost-report/install, then install with: npx skills add ghostsecurity/skills --skill ghost-reportRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/ghostsecurity-ghost-report
LLM text
/api/registry/manifest/ghostsecurity-ghost-report?format=text
Install alias
/api/registry/install/ghostsecurity-ghost-report
Recommend
/api/registry/recommend?task=Use%20ghost-report%20in%20an%20agent%20workflow&limit=3
Agent fit
Security and compliance
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Security and compliance
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO405 GitHub stars
Stars/forks activity
CHECK405 stars, 26 forks; issue activity unavailable in current metadata
Recent maintenance
PASS3d since push
License clarity
PASSapache-2.0
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Parse messy files
I need my agent to read PDFs, extract tables, and turn documents into structured data.
Publish consistently
I need my agent to turn research and product updates into useful content drafts.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Scrape, clean, and reuse web data
A practical workflow for agents that crawl public pages, extract clean content, normalize data, and hand it to downstream research or RAG workflows.
Inspect, patch, and verify code
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Alternative shortlist
Similar skills that may fit this task.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
๐ต๏ธโโ๏ธ Collect a dossier on a person by username from 3000+ sites
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
--- name: "ghost-report" description: "Ghost Security โ combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary, full security audit, or combined scan results." allowed-tools: Read, Write, Edit, Glob, Grep, Bash license: apache-2.0 metadata: version: 1.1.0 ---
# Combined Security Report
You aggregate findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report. Do all work yourself โ do not spawn subagents or delegate.
$ARGUMENTS
---
## Step 0: Setup
Run this Bash command to compute paths: ```bash repo_name=$(basename "$(pwd)") && remote_url=$(git remote get-url origin 2>/dev/null || pwd) && short_hash=$(printf '%s' "$remote_url" | git hash-object --stdin | cut -c1-8) && repo_id="${repo_name}-${short_hash}" && short_sha=$(git rev-parse --short HEAD 2>/dev/null || date +%Y%m%d) && ghost_repo_dir="$HOME/.ghost/repos/${repo_id}" && scans_dir="${ghost_repo_dir}/scans/${short_sha}" && cache_dir="${ghost_repo_dir}/cache" && skill_dir=$(find . -path '*/skills/report/SKILL.md' 2>/dev/null | head -1 | xargs dirname) && echo "scans_dir=$scans_dir cache_dir=$cache_dir skill_dir=$skill_dir" ```
Store `scans_dir` (commit-level scan directory), `cache_dir`, and `skill_dir`.
---
## Cache Check
If `<scans_dir>/report.md` already exists, show:
``` Combined security report is at: <scans_dir>/report.md ```
And stop. Do not regenerate it.
---
## Step 1: Read Repo Context
Read `<cache_dir>/repo.md` if it exists. Extract: - Business criticality - Sensitive data types - Component map
If it does not exist, continue without it โ this is not an error.
---
## Step 2: Discover Scan Results
List the contents of `<scans_dir>` to see which scan-type directories exist. Recognized types: - `deps/` โ SCA / dependency vulnerability scan - `secrets/` โ secrets and credentials scan - `code/` โ code security scan (SAST)
If none of these directories exist, report an error:
``` No scan results found in <scans_dir>. Run one or more scan skills first: /ghost-scan-deps /ghost-scan-secrets /ghost-scan-code ```
And stop.
---
## Step 3: Collect Findings
For each scan type that exists, glob `<scans_dir>/<type>/findings/*.md` and read each finding file **in full**. Retain the complete markdown body of every finding โ the report will inline this content directly so readers never need to open individual finding files.
From each finding, also extract these metadata fields for filtering and sorting:
- **ID** โ from `## Metadata` โ `ID` - **Type** โ the scan type (`deps`, `secrets`, or `code`) - **Severity** โ from `## Metadata` โ `Severity` (high, medium, low) - **Status** โ from `## Metadata` โ `Status` (e.g., confirmed-exploitable, unverified, verified, rejected, clean)
---
## Step 4: Filter and Sort
**Filter:** Keep only high-confidence findings: - For `deps` findings: status is `confirmed-exploitable` - For `secrets` findings: status is NOT `clean` and NOT `rejected` - For `code` findings: status is `verified` or `unverified` (NOT `rejected`)
**Exclude** any finding with status `clean`, `rejected`, or `false-positive`.
**Sort** the remaining findings: 1. By severity: high first, then medium, then low 2. Within same severity: deps before secrets before code
---
## Step 5: Read Per-Scan Reports
For `deps` and `secrets` scan types, read `<scans_dir>/<type>/report.md` if present. Extract: - Statistics (candidates scanned, confirmed findings, false positives filtered) - Executive summary highlights
Note: `code` does not produce a `report.md`. For code scan coverage, count the finding files in `<scans_dir>/code/findings/` directly. The "Candidates Scanned" count is the total number of finding files (all statuses). "Confirmed Findings" is the count with status `verified`, `confirmed`, or `unverified`. "False Positives Filtered" is the count with status `rejected`. Do NOT count clean file analyses from the nomination/analysis funnel โ those never became findings.
If a per-scan report does not exist for deps or secrets, note it as unavailable.
---
## Step 6: Generate Report
1. Read `<skill_dir>/report-template.md` 2. Populate the template with collected data: - Fill Scan Information with repository name, commit SHA, date, and which scans ran - Write Executive Summary using repo context and aggregated findings - For all writing elements in this security-focused, objective and fact based report, use a neutral, human tone that balances expertise with ease of reading. Do not use emojis, em-dashes, etc. - For Critical & High findings (severity = high): inline the substantive content from each finding file directly into the report โ include code snippets, assessment tables, remediation commands, and all relevant detail so the report is fully self-contained - For Medium findings: write a full subsection per finding with description, location, code context, and remediation (not a condensed table) - Omit low-severity findings (they remain in per-scan finding files only) - Fill Scan Coverage table from per-scan report statistics (for code, use finding file counts from Step 5) - Add a brief methodology note per scan type that ran (1-2 sentences drawn from per-scan reports) - Do NOT include links to per-scan reports or individual finding files โ all content is inlined 3. Write the report to `<scans_dir>/report.md`
---
## Step 7: Show Output
``` Combined security report is at: <scans_dir>/report.md ```
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for ghost-report, ready for a manual X post.
A practical pick for the next repo task: ghost-report: Ghost Security โ combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) in... 405 stars https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=x
Listing + install path for ghost-report: https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=x Install: npx skills add ghostsecurity/skills --skill ghost-report
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to ghostsecurity but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/ghostsecurity-ghost-report/audit)
[](https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)ghostsecurity
@ghostsecurity
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
๐ต๏ธโโ๏ธ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K StarsSandbox only
Install targets
Codex install prompt
Install the "ghost-report" agent skill from https://github.com/ghostsecurity/skills/tree/main/plugins/ghost/skills/report. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Ghost Security โ combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary, full security audit, or combined scan results. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"ghostsecurity-ghost-report","task":"Install ghost-report","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Document processing
I need my agent to read PDFs, extract tables, and turn documents into structured data.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add ghostsecurity/skills --skill ghost-report
Maintenance
fresh
3d since push
Risk
Safe to try
Quality score needs review
GitHub quality
405
73/100 Quality ยท 78/100 Trust
Coverage tags
Review notes
Quality score needs review ยท Stars/forks activity: 405 stars, 26 forks; issue activity unavailable in current metadata
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Safe to tryA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
405 GitHub stars
Repo activity
405 stars, 26 forks
Maintenance
3d since push
License
apache-2.0
Install
npx skills add ghostsecurity/skills --skill ghost-report
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add ghostsecurity/skills --skill ghost-reportDo not use when
Agent safety v2
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20ghost-report%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20ghost-report%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/ghostsecurity-ghost-report/install
Agent should check
Copy prompt
Task: Use ghost-report in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20ghost-report%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/ghostsecurity-ghost-report/install
Install command: npx skills add ghostsecurity/skills --skill ghost-report
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/ghostsecurity-ghost-report/install
LLM text format
/api/skills/ghostsecurity-ghost-report/install?format=text
Find alternatives
/api/skills/search?q=ghost-report&limit=3
Agent prompt
Use ghost-report for this task. Review https://www.openagentskill.com/api/skills/ghostsecurity-ghost-report/install, then install with: npx skills add ghostsecurity/skills --skill ghost-reportRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/ghostsecurity-ghost-report
LLM text
/api/registry/manifest/ghostsecurity-ghost-report?format=text
Install alias
/api/registry/install/ghostsecurity-ghost-report
Recommend
/api/registry/recommend?task=Use%20ghost-report%20in%20an%20agent%20workflow&limit=3
Agent fit
Security and compliance
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Security and compliance
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO405 GitHub stars
Stars/forks activity
CHECK405 stars, 26 forks; issue activity unavailable in current metadata
Recent maintenance
PASS3d since push
License clarity
PASSapache-2.0
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Parse messy files
I need my agent to read PDFs, extract tables, and turn documents into structured data.
Publish consistently
I need my agent to turn research and product updates into useful content drafts.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Scrape, clean, and reuse web data
A practical workflow for agents that crawl public pages, extract clean content, normalize data, and hand it to downstream research or RAG workflows.
Inspect, patch, and verify code
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Alternative shortlist
Similar skills that may fit this task.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
๐ต๏ธโโ๏ธ Collect a dossier on a person by username from 3000+ sites
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
--- name: "ghost-report" description: "Ghost Security โ combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary, full security audit, or combined scan results." allowed-tools: Read, Write, Edit, Glob, Grep, Bash license: apache-2.0 metadata: version: 1.1.0 ---
# Combined Security Report
You aggregate findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report. Do all work yourself โ do not spawn subagents or delegate.
$ARGUMENTS
---
## Step 0: Setup
Run this Bash command to compute paths: ```bash repo_name=$(basename "$(pwd)") && remote_url=$(git remote get-url origin 2>/dev/null || pwd) && short_hash=$(printf '%s' "$remote_url" | git hash-object --stdin | cut -c1-8) && repo_id="${repo_name}-${short_hash}" && short_sha=$(git rev-parse --short HEAD 2>/dev/null || date +%Y%m%d) && ghost_repo_dir="$HOME/.ghost/repos/${repo_id}" && scans_dir="${ghost_repo_dir}/scans/${short_sha}" && cache_dir="${ghost_repo_dir}/cache" && skill_dir=$(find . -path '*/skills/report/SKILL.md' 2>/dev/null | head -1 | xargs dirname) && echo "scans_dir=$scans_dir cache_dir=$cache_dir skill_dir=$skill_dir" ```
Store `scans_dir` (commit-level scan directory), `cache_dir`, and `skill_dir`.
---
## Cache Check
If `<scans_dir>/report.md` already exists, show:
``` Combined security report is at: <scans_dir>/report.md ```
And stop. Do not regenerate it.
---
## Step 1: Read Repo Context
Read `<cache_dir>/repo.md` if it exists. Extract: - Business criticality - Sensitive data types - Component map
If it does not exist, continue without it โ this is not an error.
---
## Step 2: Discover Scan Results
List the contents of `<scans_dir>` to see which scan-type directories exist. Recognized types: - `deps/` โ SCA / dependency vulnerability scan - `secrets/` โ secrets and credentials scan - `code/` โ code security scan (SAST)
If none of these directories exist, report an error:
``` No scan results found in <scans_dir>. Run one or more scan skills first: /ghost-scan-deps /ghost-scan-secrets /ghost-scan-code ```
And stop.
---
## Step 3: Collect Findings
For each scan type that exists, glob `<scans_dir>/<type>/findings/*.md` and read each finding file **in full**. Retain the complete markdown body of every finding โ the report will inline this content directly so readers never need to open individual finding files.
From each finding, also extract these metadata fields for filtering and sorting:
- **ID** โ from `## Metadata` โ `ID` - **Type** โ the scan type (`deps`, `secrets`, or `code`) - **Severity** โ from `## Metadata` โ `Severity` (high, medium, low) - **Status** โ from `## Metadata` โ `Status` (e.g., confirmed-exploitable, unverified, verified, rejected, clean)
---
## Step 4: Filter and Sort
**Filter:** Keep only high-confidence findings: - For `deps` findings: status is `confirmed-exploitable` - For `secrets` findings: status is NOT `clean` and NOT `rejected` - For `code` findings: status is `verified` or `unverified` (NOT `rejected`)
**Exclude** any finding with status `clean`, `rejected`, or `false-positive`.
**Sort** the remaining findings: 1. By severity: high first, then medium, then low 2. Within same severity: deps before secrets before code
---
## Step 5: Read Per-Scan Reports
For `deps` and `secrets` scan types, read `<scans_dir>/<type>/report.md` if present. Extract: - Statistics (candidates scanned, confirmed findings, false positives filtered) - Executive summary highlights
Note: `code` does not produce a `report.md`. For code scan coverage, count the finding files in `<scans_dir>/code/findings/` directly. The "Candidates Scanned" count is the total number of finding files (all statuses). "Confirmed Findings" is the count with status `verified`, `confirmed`, or `unverified`. "False Positives Filtered" is the count with status `rejected`. Do NOT count clean file analyses from the nomination/analysis funnel โ those never became findings.
If a per-scan report does not exist for deps or secrets, note it as unavailable.
---
## Step 6: Generate Report
1. Read `<skill_dir>/report-template.md` 2. Populate the template with collected data: - Fill Scan Information with repository name, commit SHA, date, and which scans ran - Write Executive Summary using repo context and aggregated findings - For all writing elements in this security-focused, objective and fact based report, use a neutral, human tone that balances expertise with ease of reading. Do not use emojis, em-dashes, etc. - For Critical & High findings (severity = high): inline the substantive content from each finding file directly into the report โ include code snippets, assessment tables, remediation commands, and all relevant detail so the report is fully self-contained - For Medium findings: write a full subsection per finding with description, location, code context, and remediation (not a condensed table) - Omit low-severity findings (they remain in per-scan finding files only) - Fill Scan Coverage table from per-scan report statistics (for code, use finding file counts from Step 5) - Add a brief methodology note per scan type that ran (1-2 sentences drawn from per-scan reports) - Do NOT include links to per-scan reports or individual finding files โ all content is inlined 3. Write the report to `<scans_dir>/report.md`
---
## Step 7: Show Output
``` Combined security report is at: <scans_dir>/report.md ```
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for ghost-report, ready for a manual X post.
A practical pick for the next repo task: ghost-report: Ghost Security โ combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) in... 405 stars https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=x
Listing + install path for ghost-report: https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=x Install: npx skills add ghostsecurity/skills --skill ghost-report
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to ghostsecurity but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/ghostsecurity-ghost-report/audit)
[](https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)ghostsecurity
@ghostsecurity
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
๐ต๏ธโโ๏ธ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K StarsSandbox only
Install targets
Codex install prompt
Install the "ghost-report" agent skill from https://github.com/ghostsecurity/skills/tree/main/plugins/ghost/skills/report. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Ghost Security โ combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary, full security audit, or combined scan results. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"ghostsecurity-ghost-report","task":"Install ghost-report","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Document processing
I need my agent to read PDFs, extract tables, and turn documents into structured data.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add ghostsecurity/skills --skill ghost-report
Maintenance
fresh
3d since push
Risk
Safe to try
Quality score needs review
GitHub quality
405
73/100 Quality ยท 78/100 Trust
Coverage tags
Review notes
Quality score needs review ยท Stars/forks activity: 405 stars, 26 forks; issue activity unavailable in current metadata
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Safe to tryA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
405 GitHub stars
Repo activity
405 stars, 26 forks
Maintenance
3d since push
License
apache-2.0
Install
npx skills add ghostsecurity/skills --skill ghost-report
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add ghostsecurity/skills --skill ghost-reportDo not use when
Agent safety v2
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20ghost-report%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20ghost-report%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/ghostsecurity-ghost-report/install
Agent should check
Copy prompt
Task: Use ghost-report in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20ghost-report%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/ghostsecurity-ghost-report/install
Install command: npx skills add ghostsecurity/skills --skill ghost-report
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/ghostsecurity-ghost-report/install
LLM text format
/api/skills/ghostsecurity-ghost-report/install?format=text
Find alternatives
/api/skills/search?q=ghost-report&limit=3
Agent prompt
Use ghost-report for this task. Review https://www.openagentskill.com/api/skills/ghostsecurity-ghost-report/install, then install with: npx skills add ghostsecurity/skills --skill ghost-reportRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/ghostsecurity-ghost-report
LLM text
/api/registry/manifest/ghostsecurity-ghost-report?format=text
Install alias
/api/registry/install/ghostsecurity-ghost-report
Recommend
/api/registry/recommend?task=Use%20ghost-report%20in%20an%20agent%20workflow&limit=3
Agent fit
Security and compliance
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Security and compliance
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO405 GitHub stars
Stars/forks activity
CHECK405 stars, 26 forks; issue activity unavailable in current metadata
Recent maintenance
PASS3d since push
License clarity
PASSapache-2.0
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Parse messy files
I need my agent to read PDFs, extract tables, and turn documents into structured data.
Publish consistently
I need my agent to turn research and product updates into useful content drafts.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Scrape, clean, and reuse web data
A practical workflow for agents that crawl public pages, extract clean content, normalize data, and hand it to downstream research or RAG workflows.
Inspect, patch, and verify code
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Alternative shortlist
Similar skills that may fit this task.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
๐ต๏ธโโ๏ธ Collect a dossier on a person by username from 3000+ sites
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
--- name: "ghost-report" description: "Ghost Security โ combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary, full security audit, or combined scan results." allowed-tools: Read, Write, Edit, Glob, Grep, Bash license: apache-2.0 metadata: version: 1.1.0 ---
# Combined Security Report
You aggregate findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report. Do all work yourself โ do not spawn subagents or delegate.
$ARGUMENTS
---
## Step 0: Setup
Run this Bash command to compute paths: ```bash repo_name=$(basename "$(pwd)") && remote_url=$(git remote get-url origin 2>/dev/null || pwd) && short_hash=$(printf '%s' "$remote_url" | git hash-object --stdin | cut -c1-8) && repo_id="${repo_name}-${short_hash}" && short_sha=$(git rev-parse --short HEAD 2>/dev/null || date +%Y%m%d) && ghost_repo_dir="$HOME/.ghost/repos/${repo_id}" && scans_dir="${ghost_repo_dir}/scans/${short_sha}" && cache_dir="${ghost_repo_dir}/cache" && skill_dir=$(find . -path '*/skills/report/SKILL.md' 2>/dev/null | head -1 | xargs dirname) && echo "scans_dir=$scans_dir cache_dir=$cache_dir skill_dir=$skill_dir" ```
Store `scans_dir` (commit-level scan directory), `cache_dir`, and `skill_dir`.
---
## Cache Check
If `<scans_dir>/report.md` already exists, show:
``` Combined security report is at: <scans_dir>/report.md ```
And stop. Do not regenerate it.
---
## Step 1: Read Repo Context
Read `<cache_dir>/repo.md` if it exists. Extract: - Business criticality - Sensitive data types - Component map
If it does not exist, continue without it โ this is not an error.
---
## Step 2: Discover Scan Results
List the contents of `<scans_dir>` to see which scan-type directories exist. Recognized types: - `deps/` โ SCA / dependency vulnerability scan - `secrets/` โ secrets and credentials scan - `code/` โ code security scan (SAST)
If none of these directories exist, report an error:
``` No scan results found in <scans_dir>. Run one or more scan skills first: /ghost-scan-deps /ghost-scan-secrets /ghost-scan-code ```
And stop.
---
## Step 3: Collect Findings
For each scan type that exists, glob `<scans_dir>/<type>/findings/*.md` and read each finding file **in full**. Retain the complete markdown body of every finding โ the report will inline this content directly so readers never need to open individual finding files.
From each finding, also extract these metadata fields for filtering and sorting:
- **ID** โ from `## Metadata` โ `ID` - **Type** โ the scan type (`deps`, `secrets`, or `code`) - **Severity** โ from `## Metadata` โ `Severity` (high, medium, low) - **Status** โ from `## Metadata` โ `Status` (e.g., confirmed-exploitable, unverified, verified, rejected, clean)
---
## Step 4: Filter and Sort
**Filter:** Keep only high-confidence findings: - For `deps` findings: status is `confirmed-exploitable` - For `secrets` findings: status is NOT `clean` and NOT `rejected` - For `code` findings: status is `verified` or `unverified` (NOT `rejected`)
**Exclude** any finding with status `clean`, `rejected`, or `false-positive`.
**Sort** the remaining findings: 1. By severity: high first, then medium, then low 2. Within same severity: deps before secrets before code
---
## Step 5: Read Per-Scan Reports
For `deps` and `secrets` scan types, read `<scans_dir>/<type>/report.md` if present. Extract: - Statistics (candidates scanned, confirmed findings, false positives filtered) - Executive summary highlights
Note: `code` does not produce a `report.md`. For code scan coverage, count the finding files in `<scans_dir>/code/findings/` directly. The "Candidates Scanned" count is the total number of finding files (all statuses). "Confirmed Findings" is the count with status `verified`, `confirmed`, or `unverified`. "False Positives Filtered" is the count with status `rejected`. Do NOT count clean file analyses from the nomination/analysis funnel โ those never became findings.
If a per-scan report does not exist for deps or secrets, note it as unavailable.
---
## Step 6: Generate Report
1. Read `<skill_dir>/report-template.md` 2. Populate the template with collected data: - Fill Scan Information with repository name, commit SHA, date, and which scans ran - Write Executive Summary using repo context and aggregated findings - For all writing elements in this security-focused, objective and fact based report, use a neutral, human tone that balances expertise with ease of reading. Do not use emojis, em-dashes, etc. - For Critical & High findings (severity = high): inline the substantive content from each finding file directly into the report โ include code snippets, assessment tables, remediation commands, and all relevant detail so the report is fully self-contained - For Medium findings: write a full subsection per finding with description, location, code context, and remediation (not a condensed table) - Omit low-severity findings (they remain in per-scan finding files only) - Fill Scan Coverage table from per-scan report statistics (for code, use finding file counts from Step 5) - Add a brief methodology note per scan type that ran (1-2 sentences drawn from per-scan reports) - Do NOT include links to per-scan reports or individual finding files โ all content is inlined 3. Write the report to `<scans_dir>/report.md`
---
## Step 7: Show Output
``` Combined security report is at: <scans_dir>/report.md ```
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for ghost-report, ready for a manual X post.
A practical pick for the next repo task: ghost-report: Ghost Security โ combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) in... 405 stars https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=x
Listing + install path for ghost-report: https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=x Install: npx skills add ghostsecurity/skills --skill ghost-report
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to ghostsecurity but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/ghostsecurity-ghost-report/audit)
[](https://www.openagentskill.com/skills/ghostsecurity-ghost-report?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)ghostsecurity
@ghostsecurity
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
๐ต๏ธโโ๏ธ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K StarsPermission surface
shell or command execution, filesystem or document access
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
shell or command execution, filesystem or document access
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
shell or command execution, filesystem or document access
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
Permission surface
shell or command execution, filesystem or document access
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness