attack-path-analysis
Use when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and…
Find all TODO/FIXME comments in codebase
$ npx -y skills add CoWork-OS/CoWork-OS --skill extract-todos --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/extract-todosContext preview
The summary Claude sees to decide when to auto-load this skill.
Find all TODO/FIXME comments in codebase
name: extract-todos description: "Find all TODO/FIXME comments in codebase" version: "1.0.0" metadata: author: CoWork OS Contributors <info@coworkosapp.com>
Find all TODO/FIXME comments in codebase
| Name | Type | Required | Description | |---|---|---|---| | path | string | Yes | Path to search |
Local-first personal agentic OS and everything app for coding, knowledge work, web design, automations, and artifacts.
Repo: CoWork-OS/CoWork-OS
Use when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and…
Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide Codex Security scan. Run repeated independent repository-wide…
Use when Codex is already in the finding-discovery phase of a security scan or the user explicitly asks to discover candidate security findings in a repository…
Use when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch,…
Use when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set.
Use when the user asks for a repository-wide or scoped-path security scan.