By bgultekin
Security audit skill for evaluating whether a repository is safe to clone and run locally.
AI agents are now deeply involved in software development, and code generation velocity has gone up tremendously. The volume of new repos, libraries, and tools being published is hard to keep up with — and star, fork, contributor counts no longer mean what they used to.
Even a polished repo with thousands of stars can have bad intentions baked in: a malicious postinstall script, a dependency that was quietly hijacked, or telemetry that phones home on startup.
I run this skill before installing anything open source, and I recommend you do the same. A quick audit takes seconds and can catch something you'd never notice by skimming a README.
npx skills add bgultekin/safe-to-run
MIT
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimnpx claudepluginhub bgultekin/safe-to-run --plugin safe-to-runHarness-native ECC operator layer - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
Binary reverse engineering, malware analysis, firmware security, and software protection research for authorized security research, CTF competitions, and defensive security
v9.44.1 — Patch release for Gemini environment/version detection and qwen auth gating. Run /octo:setup.
Next.js development expertise with skills for App Router, Server Components, Route Handlers, Server Actions, and authentication patterns
Comprehensive .NET development skills for modern C#, ASP.NET, MAUI, Blazor, Aspire, EF Core, Native AOT, testing, security, performance optimization, CI/CD, and cloud-native applications