All skills
vincentkoc avatar

/technical-skill-finder

@e0b7247
by Vincent Kocvincentkoc/dotskills108 stars
9

Mine coding agent logs (Codex/Cursor/session histories and similar telemetry) to discover high-value candidate skills, then draft structured skill creation/reuse recommendations.

Use this Skill: https://skilld.dev/gh/vincentkoc/dotskills/technical-skill-finder

This session only. Nothing lands on disk.

referencessources.md

≈137 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Source Inputs

Use this order unless user overrides:

  1. ~/.codex/history.jsonl
  2. ~/.codex/archived_sessions/*.jsonl
  3. ~/.codex/sessions/*.jsonl
  4. ~/.codex/log/*
  5. Repository-local telemetry and instructions (AGENTS.md, existing skills)
  6. MCP-exposed resources (only when explicitly authorized)

For opt-in personal extension:

  • Messaging MCP resources or local logs should only be read when user explicitly approves.
  • Do not join personal communication patterns into coding-skill candidates unless user asks for a merged scope.

Source: SKILL.md on GitHub

1 alert6mo4 checks · Risk HIGH
  • Gen Agent Trust Hub7mo

    This skill mines sensitive local agent interaction histories and telemetry to suggest new automation. It lacks safeguards against Indirect Prompt Injection, meaning malicious instructions embedded in historical logs could trick the agent into recommending harmful commands or exposing private conversation data. Additionally, it reads dotfiles and log directories that often contain sensitive credentials and proprietary code.

  • Socket6mo

    No alerts

  • Snyk7mo

    Risk: LOW · No issues

  • Runlayer7mo

    4/4 files flagged

Signed by skilld at e0b7247. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last week.

Activeupdated 2 weeks ago
metadata
{
  "source": "https://github.com/vincentkoc/dotskills"
}

README badge

README badge for vincentkoc/dotskills/technical-skill-finder