← ClaudeAtlas

using-omvlisted

Bootstrap discipline for oh-my-vul research. Use at the start of any vulnerability research conversation, when the user asks to audit/find/report a package, dig for CVEs, or run omv skills — and before claiming a finding is confirmed, ready to submit, or “done”. Establishes mandatory process, hard gates, and evidence-before-claims rules. Prefer this over improvising a research workflow.
bx33661/oh-my-vul · ★ 3 · AI & Automation · score 69
Install: claude install-skill bx33661/oh-my-vul
# using-omv High-quality growth rule for this project: **deepen discipline, do not inflate skill count.** This skill is the session bootstrap. Domain work still lives in the `omv-find`, `omv-audit`, `omv-repro`, and `omv-report` skills. You use those skills **inside** the process below — you do not invent parallel workflows. ## Platform Invocation Use the invocation form provided by the active agent: | Platform | Project manager | Focused skill example | |---|---|---| | Pi | `/skill:omv` | `/skill:omv-audit <id>` | | Codex | `$omv` | `$omv-audit <id>` | | Claude Code | `/omv` | `/omv-audit <id>` | In the workflow below, `/omv-*` is shorthand for the matching focused skill on the active platform. ## Iron Laws ```text 1. EVIDENCE BEFORE CLAIMS 2. CLI TRUTH BEFORE PROSE 3. PROCESS BEFORE IMPROVISATION 4. PASSIVE RESEARCH ONLY ``` <HARD-GATE> Before any research claim or lifecycle transition, you must satisfy the matching gate. Rationalizing past a gate is a failure mode, not speed. </HARD-GATE> ## When This Applies Invoke **before** substantive research action if the user is: - looking for packages to audit, ranking targets, or running `/omv-find` - auditing source → sink → guard, or running `/omv-audit` - reproducing, reporting, disclosing, or asking “what next” - about to say a finding is confirmed, report-ready, non-duplicate, or complete If you are a subagent doing one delegated slice (e.g. only CVSS math), stay in that slice and still refuse to invent evidence.