with one click
opencode-agents
opencode-agents contains 16 collected skills from lousix, with repository-level occupation coverage and site-owned skill detail pages.
Skills in this repository
Feature-centric deep incremental security review harness for Git-backed code changes, with autonomous, agents, and hybrid execution modes.
Optional graph-context enrichment for feature-centric incremental security review using CodeGraph or code-review-graph when available.
Pre-report finding verification contract. Re-checks whether each vulnerability has a real external Source, reachable Sink, bypassable or missing sanitization, and practical exploitability before final reporting.
Sink chain deep tracing methodology with graded code output templates (Critical full-chain / High-Medium key-nodes), reverse tracking rules, and per-hop Read verification.
Agent contract templates for R1 and R2+ rounds, including output format, token budget management, truncation defense, and auto-injection prompt templates.
Jalor internal Spring framework audit extension for endpoint operation authorization and service audit logging coverage.
Two-layer checklist architecture with D1-D10 security coverage matrix and language-specific semantic prompts for gap verification after free audit.
Structured security audit report template focused on exploit narrative, root cause, verified source-to-sink data flow, key code analysis, PoC, and minimal remediation notes.
OpenCode-native audit harness protocol for target-project context negotiation, mixed-language profiling, extension skill activation, and stable HARNESS_PROFILE injection.
Anti-confirmation-bias rules for code audit. Ensures methodology-driven audit approach instead of case-driven, preventing skipping of checklist items or prioritizing familiar patterns.
Anti-hallucination rules for code security audit. Prevents false positive vulnerability reports by enforcing file verification, code authenticity, and tech stack matching. Must be loaded by all audit agents.
Attack chain construction methodology for code audit. Provides chain reasoning method, common chain patterns, and automatic chain building rules. Load when evaluating cross-vulnerability impact.
Five-phase audit model with effort allocation, semantic-driven Phase 2A, coverage verification Phase 2B, validation Phase 3, and aggressive scanning principles.
Vulnerability severity rating framework with CVSS-based 4-tier system, 3-dimensional assessment model, decision tree, and attack chain impact rules.
Taint analysis methodology for code audit. Provides sink identification, backward tracing, source location, sanitization checking, and report generation. Load when analyzing data flow vulnerabilities.
Tech stack to security module routing table, tech stack identification methods, functional module discovery, and boundary interaction matrix.