oma-academic-writing
Draft and revise academic prose against a rubric, evidence, and
Scan application source, agent skills, and MCP components; run
$ npx -y skills add first-fluke/oh-my-agent --skill oma-security --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/oma-securityContext preview
The summary Claude sees to decide when to auto-load this skill.
Scan application source, agent skills, and MCP components; run
name: oma-security description: Scan application source, agent skills, and MCP components; run penetration tests against scoped web test deployments, validate findings, and configure scan gates. Use oma-qa for broad quality reviews and domain skills for remediation.
Run the selected security checks, retain their native evidence, independently validate candidates, and report findings and coverage on the recorded source or deployment identity.
outputs:
- name: run
artifact: ".agents/results/security/*/run.json"
required: true
- name: findings
artifact: ".agents/results/security/*/findings.json"
required: true
- name: report
artifact: ".agents/results/security/*/report.md"
required: trueUse one unique `.agents/results/security/<run-id>/` per invocation and check that directory explicitly; old matching files do not establish completion. Keep raw outputs and logs under `raw/<engine>/`, verification evidence under `evidence/`, and stable references to native engine workspaces. When `web_runtime` is selected, also require `runtime.json`; for `ci`, require `gate.json`. Report confirmed findings, reviewed leads, unreviewed candidates, rejected claims, scope, skips, engine failures, budget stops, and evidence limits separately.
Load the chosen target/engine resource; load the findings contract when retaining or normalizing results. Only load validation for triage/reproduction and CI guidance for a gate request. Use an installed/pinned native interface; inspect its version and help before choosing flags. Deepsec `init` can configure models and start AI review; do not treat it as free scaffolding or run it before the selected scope/spend is authorized. Use native cost/duration controls verified against the installed engine; record when a hard bound cannot be enforced. ARTEX uses a verified snapshot-specific UI/API or manual/external integration; it has no assumed scanner command. Authorization, clarification, spend, build restrictions, and completion follow `../_shared/core/execution-policy.md`. Existing backend/scope/spend authorization persists. A key, login, or installed tool alone does not authorize paid calls or changed scope.
| Concrete target | Default engine | Alternative/additional operation | |---|---|---| | Application source or source diff | Deepsec | Cisco AI Deep SAST when explicitly selected or included in the authorized plan | | Agent skill directory/package | Cisco Skill Scanner | Independent validation of candidates | | MCP source/configuration/server | Cisco MCP Scanner | Only supported static/dynamic modes within scope | | Web test deployment (`web_runtime`, `pentest`) | ARTEX | Independent runtime replay of candidates | | Bounded source/local reproduction | Cloudflare validation method | No external network or deployment traffic |
A general repository scan selects source; do not add skill/MCP/runtime scans by implication. A full source-plus-runtime audit includes ARTEX when a concrete web test deployment is provided; absent deployment leaves that stage pending. Use the user-named engine within its supported target/mode. No failed or empty result automatically selects another engine, model, backend, or paid analyzer. Cloudflare is a validation procedure, not evidence of superior detection accuracy. Keep its local-only proof separate from ARTEX's network-scoped runtime proof and Deepsec's static-only worker.
Agents narrate success. oh-my-agent checks the artifacts. Spawning parallel agents is the easy part. The hard part is knowing whether they actually did the work.
Repo: first-fluke/oh-my-agent
Draft and revise academic prose against a rubric, evidence, and
Evaluate system boundaries and architectural tradeoffs. Use for
Implement server APIs, authentication, and application data access.
Coordinate assigned specialist tasks and handoffs manually. Use