finding-template
Copy this block per finding. Keep it to one anchor, one exploit sentence, one fix. Delete the guidance comments before shipping.
$ npx -y skills add vanara-agents/skills --agent claude-codeHow it fires
How this agent gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
Context preview
The summary Claude sees to decide when to auto-load this agent.
Copy this block per finding. Keep it to one anchor, one exploit sentence, one fix. Delete the guidance comments before shipping.
Agent definition
finding-template.mdSingle-Finding Template
Copy this block per finding. Keep it to one anchor, one exploit sentence, one fix. Delete the guidance comments before shipping.
### <CRITICAL | HIGH | MEDIUM | LOW>
- `<path>:<line>` — **<Vulnerability name> (<OWASP category, e.g. A03>)**. <One sentence: which
attacker-controlled input reaches which dangerous sink, and the concrete impact. Include the exploit
string if it makes it real.> **Fix:** <the corrected code or precise action — a real control
(parameterize / encode / allow-list / rotate), never a blocklist.>
Filled example
### CRITICAL
- `orders/repo.js:88` — **SQL injection (A03)**. The `sort` query param is interpolated into the SQL
text (`ORDER BY ${req.query.sort}`); `?sort=id;DROP TABLE orders--` executes arbitrary SQL.
**Fix:** allow-list sortable columns (`{ created_at, total }`) and map the param through it; bind
all values as parameters. Identifiers can't be bound, so the allow-list is mandatory.Checklist before you ship a finding
- [ ] Anchored to a real `file:line` that contains the quoted code.
- [ ] Names the source (input), the sink, and the impact.
- [ ] Has an OWASP category.
- [ ] Severity matches the rubric in `../references/severity-and-reporting.md`.
- [ ] Fix is a real control, not a blocklist; includes rotation if a secret was exposed.
- [ ] You could defend it to the author without hand-waving.
Read more
Single-Finding Template
Copy this block per finding. Keep it to one anchor, one exploit sentence, one fix. Delete the guidance comments before shipping.
### <CRITICAL | HIGH | MEDIUM | LOW> - `<path>:<line>` — **<Vulnerability name> (<OWASP category, e.g. A03>)**. <One sentence: which attacker-controlled input reaches which dangerous sink, and the concrete impact. Include the exploit string if it makes it real.> **Fix:** <the corrected code or precise action — a real control (parameterize / encode / allow-list / rotate), never a blocklist.>
Filled example
### CRITICAL
- `orders/repo.js:88` — **SQL injection (A03)**. The `sort` query param is interpolated into the SQL
text (`ORDER BY ${req.query.sort}`); `?sort=id;DROP TABLE orders--` executes arbitrary SQL.
**Fix:** allow-list sortable columns (`{ created_at, total }`) and map the param through it; bind
all values as parameters. Identifiers can't be bound, so the allow-list is mandatory.Checklist before you ship a finding
- [ ] Anchored to a real `file:line` that contains the quoted code.
- [ ] Names the source (input), the sink, and the impact.
- [ ] Has an OWASP category.
- [ ] Severity matches the rubric in `../references/severity-and-reporting.md`.
- [ ] Fix is a real control, not a blocklist; includes rotation if a secret was exposed.
- [ ] You could defend it to the author without hand-waving.
🐒 Free agents, skills & packs for Claude Code One subscription. An army of Claude Code agents. 30 production-grade agents, skills, and packs for Claude Code — free, Apache-2.0, install with one command.
Repo: vanara-agents/skills
Other agents on vanara-agents-skills.
- AGENT
Use when designing a new HTTP/GraphQL API or changing an existing one — modeling resources, defining endpoint contracts, choosing status codes, pagination, filtering, error envelopes, versioning, and idempotency. Produces a reviewable API contract plus an OpenAPI snippet, not
Open agent - review-notes
This shows how the api-designer agent reviews a flawed draft. Findings are severity-ranked so the implementer fixes the contract-breakers first. Severity legend: **CRITICAL** (breaks clients / data risk), **HIGH** (real bug or inconsistency), **MEDIUM** (maintainability),
Open agent - contract-and-openapi
The contract is the deliverable. Express it as an **OpenAPI 3.1** document so it is human-readable *and* machine-checkable. This reference covers how to structure that document and what `scripts/lint-openapi.mjs` enforces.
Open agent - design-checklist
Run through this before declaring an API contract done. It is ordered the way you should *design*: resources first, cross-cutting rules last. Every box is a place real APIs go wrong in production.
Open agent - versioning-and-evolution
APIs are forever once published: a consumer you've never met may depend on any field you expose. Design so you can **add without breaking**, and version explicitly when you must break.
Open agent - pr-comment-template
Copy-paste templates for leaving review comments. Keep each comment to one finding: an anchor, the problem, and the fix.
Open agent

