All authors

Claude Skills by mstfknn
github.com/mstfknn68 skills2 installs139 views
- sast-analysisPerform codebase analysis and architecture mapping as the first phase of a security assessment. Explores the tech stack, frameworks, entry points, data flows, and trust boundaries. Outputs sast/architecture.md. Run this before any vulnerability detection skill. Use when asked to analyze a codebase for security or when sast/architecture.md does not yet exist.Votes: 0GitHub stars: 12
- Sast AgentidentityDetect over-privileged non-human agent identities — service accounts, API tokens, IAM roles, and CI credentials used by automated pipelines that carry broader permissions than the agent's task requires, violating least privilege for non-human identities. Applies LLM-driven scope-vs-need analysis to distinguish genuine over-permission from permissions constrained by boundary controls or OIDC short-lived issuance. Outputs findings to sast/agentidentity-results.md and the canonical sast/agentide...Votes: 0GitHub stars: 12
- Sast BusinesslogicDetect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel subagents, 3 scenarios each), and merge (consolidate batch results). Covers price manipulation, workflow bypass, limit violations, race conditions, reward abuse, etc. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/businesslogic-results.md. Use when asked to find business l...Votes: 0GitHub stars: 12
- Sast CloudsdkDetect Cloud SDK misuse — public bucket ACLs, hardcoded access keys/secrets in SDK client constructors, and overly broad IAM policies/roles — across AWS (boto3, SDK JS/Java), Azure SDK, GCP google-cloud SDK, and IaC tools (Terraform, CDK, Pulumi). Uses a three-phase approach: recon (inventory SDK call sites and IaC blocks), batched verify (parallel subagents, 3 candidates each, taint and policy analysis), and merge (consolidate into sast/cloudsdk-results.md and sast/cloudsdk-results.json). Ma...Votes: 0GitHub stars: 12
- Sast ConfigrceDetect repository-configuration files that become an arbitrary-code-execution surface when a developer opens the project or a CI runner clones the repo, matching the real CVE class of config-file RCE (e.g. CVE-2025-59536, CVSS 8.7). Covers CLAUDE.md/AGENTS.md/cursor-rules files with embedded shell directives, .mcp.json entries that auto-launch processes, .github/workflows steps triggered at checkout, .vscode/tasks.json and devcontainer lifecycle hooks, and Makefile targets invoked automatical...Votes: 0GitHub stars: 12
- Sast CookieflagsDetect session and authentication cookies set without the HttpOnly, Secure, or SameSite flags across Flask, Django, Express, Spring Boot, PHP, Rails, and .NET. Uses a three-phase approach: recon (find cookie-setting sinks and framework config that omits or negates required flags), batched verify (confirm the cookie carries auth/session state and the missing flag is exploitable, 3 sinks per subagent, in parallel), and merge (consolidate batch results into sast/cookieflags-results.md and sast/c...Votes: 0GitHub stars: 12
- Sast CorsDetect CORS misconfiguration vulnerabilities in a codebase using a three-phase approach: recon (find CORS middleware, header setters, and preflight handlers), batched verify (analyze each configuration in parallel batches of 3), and merge (consolidate batch results). Flags wildcard-with-credentials, reflected Origin, unescaped regex origin checks, null-origin acceptance, and missing `Vary: Origin`. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/cors-results....Votes: 0GitHub stars: 12
- Sast CrlfDetect CRLF injection and HTTP response splitting vulnerabilities using a three-phase approach: recon (find header-write, redirect, and log sinks that accept unsanitized input), batched verify (trace user-controlled values to those sinks in parallel subagents, 3 sites each, checking for CR/LF stripping gaps), and merge (consolidate batch results). Covers all major web frameworks and languages. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/crlf-results.md an...Votes: 0GitHub stars: 12
- Sast CryptoDetect insecure cryptography in a codebase — weak hashes (MD5/SHA-1 for security), weak ciphers (DES/3DES/RC4), bad modes (ECB), IV reuse, short keys, and weak PRNGs (Math.random, rand()) used for security-sensitive values. Uses a three-phase approach: recon (find crypto primitive calls), batched verify (analyze purpose and usage in parallel subagents, 3 sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/crypto...Votes: 0GitHub stars: 12
- Sast CsrfDetect Cross-Site Request Forgery (CSRF) vulnerabilities in a codebase using a three-phase approach: recon (find state-changing cookie-authenticated endpoints), batched verify (check CSRF protections in parallel subagents, 3 endpoints each), and merge (consolidate batch results). Covers classic form/JSON CSRF, login CSRF, GraphQL mutation CSRF, and GET-based state changes. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/csrf-results.md. Use when asked to find...Votes: 0GitHub stars: 12
- Sast CsvinjDetect CSV / spreadsheet formula injection vulnerabilities where user-controlled cell values starting with =, +, -, or @ are written to a CSV or spreadsheet export (XLSX, ODS) without leading-character sanitisation, enabling arbitrary formula execution when the file is opened in Excel, LibreOffice, or Google Sheets. Uses a three-phase approach: recon (find CSV/spreadsheet write sinks), batched verify (trace user input to those sinks in parallel subagents, 3 sites each), and merge (consolidate...Votes: 0GitHub stars: 12
- Sast DangerousapiInventory inherently dangerous API sinks — dynamic code evaluation (eval, Function, exec, compile), reflective class/method invocation, native-code bridges (JNI, ctypes, cffi), and process-spawning functions — regardless of proven taint, because every occurrence requires explicit human review. Covers JavaScript/Node, Python, Java, PHP, Ruby, .NET, and Go. Uses a three-phase approach: recon (find every dangerous sink), batched verify (taint analysis + severity calibration in parallel, 3 sinks ...Votes: 0GitHub stars: 12
- Sast DepconfusionDetect dependency confusion vulnerabilities where internal package names are resolvable from public registries (npm, PyPI, RubyGems, Maven/Gradle, NuGet) due to absent registry scoping or allowlisting, and lifecycle scripts (postinstall, prepare, preinstall, setup.py) in dependencies that execute arbitrary code at install time. Uses a three-phase approach: recon (find all manifest files and registry configuration, identify unscoped internal-looking package names and lifecycle scripts), batche...Votes: 0GitHub stars: 12
- Sast DepsSurvey a codebase for known-vulnerable dependencies (direct and transitive) using a three-phase approach: recon (inventory all ecosystem manifests and lockfiles), batched verify (match package@version pairs against CVE/GHSA/OSV advisories in parallel subagents, 3 ecosystem files each), and merge (consolidate batch results). Also flags end-of-life runtimes, risky ecosystem defaults, and supply-chain markers. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/deps...Votes: 0GitHub stars: 12
- Sast DeserDetect insecure deserialization vulnerabilities (CWE-502, OWASP Web25 A05) where untrusted bytes from HTTP bodies, uploads, cookies, queues, or caches reach a deserializer capable of instantiating arbitrary types or invoking gadget-chain code (Java ObjectInputStream/XStream/SnakeYAML, Python pickle/yaml/jsonpickle/dill, PHP unserialize, .NET BinaryFormatter/Json.NET TypeNameHandling, Ruby Marshal/YAML, Node node-serialize/funcster/cryo). Uses a three-phase approach: recon (locate dangerous de...Votes: 0GitHub stars: 12
- Sast ElinjDetect Expression Language / OGNL / SpEL Injection vulnerabilities (CWE-917) in a codebase using a three-phase approach: recon (find programmatic expression-evaluator API calls that accept dynamic strings), batched verify (trace user input to those evaluation sinks in parallel subagents, 3 candidates each), and merge (consolidate batch results). Targets Java Spring SpEL, Struts OGNL, MVEL, JEXL, JSP EL, and Python simpleeval/asteval programmatic APIs. Distinct from sast-ssti (CWE-94): sast-ss...Votes: 0GitHub stars: 12
- Sast ErrorhandlingDetect security error-handling vulnerabilities using a three-phase approach: recon (find fail-open handlers, stack-trace leaks, debug flags, and swallowed security exceptions), batched verify (taint-trace each candidate in parallel subagents, 3 sites each — confirm untrusted-caller reachability, apply FP-killers, set exploitability / confidence), and merge (consolidate batch reports into sast/errorhandling-results.md and sast/errorhandling-results.json). Covers CWE-209 (Information Exposure T...Votes: 0GitHub stars: 12
- Sast ExcessiveagencyDetect Excessive Agency vulnerabilities (OWASP LLM Top 10 #6 / ASI Top 10 ASI02) in LLM/agent codebases using a three-phase approach: recon (find tool registrations and agent configurations with state-changing authority), batched verify (LLM-driven analysis of whether a human-in-the-loop approval gate exists between the model decision and the destructive action, in parallel subagents of 3 candidates each), and merge (consolidate batch results). Covers write/delete/spend/send tool schemas regi...Votes: 0GitHub stars: 12
- Sast ExcessivedataDetect Excessive Data Exposure vulnerabilities (API3:2023, CWE-213) where API responses serialize entire ORM objects — including password hashes, tokens, internal flags, and PII — instead of an explicit field allow-list. Covers Django REST Framework, Rails, Spring Boot, Express/Node.js, Laravel, and FastAPI serialization paths. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/excessivedata-results.md. Use when asked to find over-exposure, mass data leakage, or...Votes: 0GitHub stars: 12
- Sast FileuploadDetect insecure file upload vulnerabilities in a codebase using a three-phase approach: discovery (find all upload sites), batched verify (check extension bypass and related issues in parallel subagents, 3 sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/fileupload-results.md. Use when asked to find file upload, unrestricted upload, or extension bypass bugs.Votes: 0GitHub stars: 12
- Sast GraphqlDetect GraphQL injection vulnerabilities in a codebase using a three-phase approach: recon (confirm GraphQL usage and find unsafe operation document assembly sites), batched verify (trace user input to those sites in parallel subagents, up to 3 candidate sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/graphql-results.md. If no GraphQL technology is found in Phase 1, later phases are skipped. Use when asked t...Votes: 0GitHub stars: 12
- Sast HardcodedsecretsDetect hardcoded sensitive data (API keys, access tokens, private keys, passwords, etc.) in publicly accessible code — frontend JavaScript, mobile apps, client-side bundles, and HTML templates. Uses a three-phase approach: recon (find secret candidates), batched verify (confirm real secrets in public code paths, 3 candidates each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/hardcodedsecrets-results.md. Use when aske...Votes: 0GitHub stars: 12
- Sast IacDetect insecure Infrastructure-as-Code (IaC) configurations in a codebase using a three-phase approach: recon (inventory IaC files — Dockerfile, Terraform, Kubernetes manifests, GitHub Actions workflows, docker-compose), batched verify (apply rule-set against 3 files in parallel), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/iac-results.md plus canonical sast/iac-results.json. Use when asked to find insecure IaC, cont...Votes: 0GitHub stars: 12
- Sast IdorDetect Insecure Direct Object Reference (IDOR) vulnerabilities in a codebase using a three-phase approach: recon (find candidates), batched verify (check authorization in parallel subagents, 3 candidates each), and merge (consolidate batch results). Checks endpoints for missing ownership or authorization checks on user-supplied identifiers. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/idor-results.md. Use when asked to find IDOR or authorization bypass bugs.Votes: 0GitHub stars: 12
- Sast JwtDetect insecure JWT (JSON Web Token) implementations in a codebase using a two-phase approach: first map all JWT issuance and verification sites to understand the token lifecycle and signing configuration, then check each verification site for exploitable weaknesses such as algorithm confusion, missing signature verification, weak secrets, header injection, and missing claim validation. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/jwt-results.md. If no JWT...Votes: 0GitHub stars: 12
- Sast LdapDetect LDAP injection vulnerabilities in a codebase using a three-phase approach: recon (find LDAP query construction sites — search filters, DN assembly, bind operations), batched verify (trace user input to those sites in parallel subagents, 3 sites each), and merge (consolidate batch results). Covers auth-bypass filter tampering, wildcard enumeration, unescaped DN components, dynamic attribute names, and StartTLS/ldaps context issues. Requires sast/architecture.md (run sast-analysis first)...Votes: 0GitHub stars: 12
- Sast LlmdosDetect unbounded LLM API calls and agent loops in LLM/agent codebases that lack hard token caps or iteration limits on user-reachable paths, enabling denial-of-wallet attacks and compute exhaustion (CWE-770, LLM10, LLM25). Covers Python (OpenAI, Anthropic, LangChain, LlamaIndex), TypeScript (Vercel AI SDK), and any recursive agent-spawning pattern. Skip this skill on repos with no LLM API calls or agent orchestration — the stack router will mark it out-of-scope if no LLM framework is detected.Votes: 0GitHub stars: 12
- Sast LlmoutputDetect Insecure Handling of LLM Output (OWASP LLM Top 10 #2) in a codebase using a three-phase approach: recon (find LLM response sinks), batched verify (check trust boundary, schema validation, sanitization, and allowlisting in parallel subagents, 3 sinks each), and merge (consolidate batch results). Covers innerHTML/v-html/dangerouslySetInnerHTML injection from model output, eval/exec/child_process of model text, raw SQL from model, model-generated redirects and fetch URLs (SSRF/open redire...Votes: 0GitHub stars: 12
- Sast LockfileSurvey a codebase for missing, incomplete, or bypassed lockfile integrity controls — the mechanism that guarantees each install gets byte-identical packages pinned to a verified content hash. Applies a three-phase approach: recon (enumerate all ecosystem manifests, lockfiles, Dockerfiles, and CI install steps), batched verify (parallel subagents, 3 artefacts each, confirm whether a pinned hash or digest is provably absent), and merge (consolidate into sast/lockfile-results.md and sast/lockfil...Votes: 0GitHub stars: 12
- Sast MassassignDetect mass assignment vulnerabilities where user-supplied request data is bound directly to ORM model instances without an explicit field allow-list, enabling privilege escalation via overposting of sensitive fields such as is_admin, role, or balance. Covers Rails, Django, Spring, Express, Laravel, and ASP.NET. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/massassign-results.md and sast/massassign-results.json. Use when asked to find mass assignment, overp...Votes: 0GitHub stars: 12
- Sast McpsecDetect MCP (Model Context Protocol) server security vulnerabilities using a three-phase approach: recon (find MCP server definitions, tool registrations, and transport configuration), batched verify (check for missing auth on every tool handler and analyse tool descriptions for hidden behavioral directives in parallel subagents, 3 candidates each), and merge (consolidate batch results). Covers two distinct attack classes: (1) unauthenticated or under-authorised tool handlers that let any call...Votes: 0GitHub stars: 12
- Sast MemorypoisonDetect agent memory poisoning vulnerabilities (OWASP LLM Top 10 / ASI26 ASI06, CWE-349) in LLM/agent codebases using a three-phase approach: recon (find memory write sites where untrusted content is persisted), batched verify (trace the write-then-retrieve trust path in parallel subagents, 3 sites each, with LLM-driven taint analysis), and merge (consolidate batch results). Targets LangChain, LlamaIndex, Mem0, vector DB upsert paths, and any custom session or key-value memory store where user...Votes: 0GitHub stars: 12
- Sast MissingauthDetect missing authentication and broken function-level authorization vulnerabilities in a codebase using a three-phase approach: recon (map endpoints and the role/permission system), batched verify (check auth/authz in parallel subagents, 3 endpoints each), and merge (consolidate batch results). Covers unauthenticated access and vertical privilege escalation (e.g., regular user accessing admin-only functions). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/...Votes: 0GitHub stars: 12
- Sast NosqlDetect NoSQL injection vulnerabilities in a codebase using a three-phase approach: recon (find query construction sites on MongoDB, Firestore, DynamoDB, CouchDB, etc.), batched verify (trace user input and operator shape validation in parallel subagents, 3 sites each), and merge (consolidate batch results). Covers operator injection ($gt, $ne, $where, $regex, $expr), Mongoose schema bypass, Firestore path injection, and DynamoDB expression concatenation. Requires sast/architecture.md (run sas...Votes: 0GitHub stars: 12
- Sast OauthDetect OAuth 2.0 and OIDC implementation flaws in a codebase using a three-phase approach: recon (find authorization flows, redirect_uri handling, state parameter usage, PKCE configuration, and grant type selection), batched verify (check each candidate for exploitable misconfigurations in parallel subagents, 3 candidates each), and merge (consolidate batch results). Covers unvalidated redirect_uri (open redirect / authorization-code interception), missing or unverified state parameter (CSRF ...Votes: 0GitHub stars: 12
- Sast OpenredirectDetect Open Redirect vulnerabilities in a codebase using a three-phase approach: recon (find redirect sinks in Location headers, client-side window.location, meta-refresh tags, and href attributes), batched verify (trace user input to redirect destinations in parallel subagents, 3 sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/openredirect-results.md and sast/openredirect-results.json. Use when asked to fin...Votes: 0GitHub stars: 12
- Sast PathtraversalDetect path traversal vulnerabilities in a codebase using a three-phase approach: recon (find file-loading sinks with dynamic paths), batched verify (trace user input and mitigations in parallel subagents, 3 sinks each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/pathtraversal-results.md. Use when asked to find path traversal, directory traversal, or file disclosure bugs.Votes: 0GitHub stars: 12
- Sast PaymentlogicDetect payment and monetary business-logic vulnerabilities using a three-phase approach: recon (locate checkout, refund, coupon, balance, and pricing handlers), batched verify (parallel subagents, 3 candidates each, semantic taint analysis from client input to monetary outcome), and merge (consolidate into sast/paymentlogic-results.md and sast/paymentlogic-results.json). Scope boundary: monetary/payment abuse only — price and quantity manipulation, coupon and wallet stacking, refund fraud, ne...Votes: 0GitHub stars: 12
- Sast PiiDetect PII and credential leakage into logs, error messages, telemetry, and crash reporters (Sentry, Rollbar, APM breadcrumbs). Uses a three-phase approach: recon (find log/print sinks), batched verify (check sensitivity of what is logged, 3 sinks each), and merge (consolidate batch results). Covers passwords, tokens, session IDs, Authorization headers, and PII (emails, phone, SSN, DOB, credit card). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/pii-results...Votes: 0GitHub stars: 12
- Sast PipelineinjDetect CI/CD pipeline injection vulnerabilities where untrusted event payload values (pull request titles, issue bodies, comment bodies, branch names) are interpolated directly into a `run:` shell step or `actions/github-script` via `${{ ... }}` expression syntax, letting an external contributor inject arbitrary shell commands into the CI runner. Uses a three-phase approach: recon (find all injection sinks across GitHub Actions, GitLab CI, and CircleCI configs), batched verify (parallel subag...Votes: 0GitHub stars: 12
- Sast PostmessageDetect origin-trust failures in browser and WebSocket contexts using a three-phase approach: recon (find postMessage handlers, WebSocket upgrade points, and target="_blank" links), batched verify (trace whether event.data flows to a sink without an origin check, whether WebSocket connections are exploitable via cross-site request, and whether reverse-tabnabbing is possible, in parallel subagents of 3 candidates each), and merge (consolidate into sast/postmessage-results.md and sast/postmessag...Votes: 0GitHub stars: 12
- Sast PromptinjectionDetect LLM prompt injection vulnerabilities (OWASP LLM Top 10 #1) in a codebase using a three-phase approach: recon (find LLM API call sites), batched verify (trace untrusted input into prompt construction in parallel subagents, 3 call sites each), and merge (consolidate batch results). Covers direct injection (user chat), indirect injection (RAG, email, web pages, file uploads, tool output), and multi-agent prompt poisoning. Requires sast/architecture.md (run sast-analysis first). Outputs fi...Votes: 0GitHub stars: 12
- Sast PrototypeDetect JavaScript/TypeScript prototype pollution vulnerabilities in a codebase using a three-phase approach: recon (find merge/assign/set sites that walk user-supplied keys), batched verify (trace user input and check for safe-key filtering in parallel subagents, 3 sites each), and merge (consolidate batch results). Covers `__proto__` / `constructor.prototype` key injection through unsafe deep-merge, `_.set`, manual recursive copy, minimist <1.2.6, qs with `allowPrototypes`, and gadget chains...Votes: 0GitHub stars: 12
- Sast RaceDetect race condition vulnerabilities in a codebase using a three-phase approach: recon (find read-modify-write and TOCTOU sites), batched verify (check atomicity in parallel subagents, 3 sites each), and merge (consolidate batch results). Covers balance/coupon double-spend, file TOCTOU, auth time-of-check/time-of-use, duplicate webhook processing, missing optimistic concurrency, and Node.js async/await races. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/r...Votes: 0GitHub stars: 12
- Sast RagleakDetect RAG cross-tenant data leakage and indirect prompt injection via retrieval pipelines (OWASP LLM Top 10 LLM08 / LLM01, CWE-200) in codebases that use vector stores or document indexes with an LLM or agent framework. Skips repositories with no LLM/agent SDK (LangChain, LlamaIndex, Chroma, Pinecone, Weaviate, Qdrant, OpenAI, Anthropic, or similar). Uses a three-phase approach: recon (find every vector-store query and RAG retrieval site), batched verify (parallel subagents, 3 candidates eac...Votes: 0GitHub stars: 12
- Sast RatelimitDetect missing rate limits on authentication and resource-intensive endpoints (login, password-reset, token-refresh, OTP verify, search, bulk-export) that are reachable without a framework- or gateway-level request cap, enabling brute-force credential attacks and resource-exhaustion DoS (CWE-770, API4, API23). Uses a three-phase approach: recon (map sensitive endpoints and their middleware chains), batched verify (parallel subagents, 3 candidates each, confirm no per-IP or per-user rate cap e...Votes: 0GitHub stars: 12
- Sast RceDetect Remote Code Execution (RCE) vulnerabilities in a codebase using a three-phase approach: recon (find dangerous execution sinks), batched verify (trace user input to sinks in parallel subagents, 3 sinks each), and merge (consolidate batch results). Covers OS command injection, eval-like sinks, and unsafe deserialization. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/rce-results.md. Use when asked to find RCE, command injection, or unsafe deserializatio...Votes: 0GitHub stars: 12
- Sast RedosDetect Regular Expression Denial of Service (ReDoS) vulnerabilities caused by catastrophic backtracking in a codebase using a three-phase approach: recon (find suspicious regex literals and user-input sinks), batched verify (analyze regex ambiguity and exposure in parallel subagents, 3 candidates each), and merge (consolidate batch results). Covers nested quantifiers, overlapping alternation, and regex engines without linear-time guarantees. Requires sast/architecture.md (run sast-analysis fi...Votes: 0GitHub stars: 12
- Sast ReportConsolidate all SAST vulnerability results from the sast/ folder into a single final report ranked by severity and confidentiality impact. Reads all *-results.md files and produces sast/final-report.md. Run after all vulnerability detection skills complete. Use when asked to generate a final report, consolidate findings, or summarize security results.Votes: 0GitHub stars: 12
- Sast RouteinventoryDetect shadow, debug, and admin routes that are registered in the running application but absent from the published API specification, marked deprecated yet still active, or reachable without authentication from a public network. Uses a three-phase approach: recon (enumerate every registered route and its auth posture), batched verify (parallel subagents, 3 routes each, confirm reachability and spec coverage), and merge (consolidate into sast/routeinventory-results.md and sast/routeinventory-...Votes: 0GitHub stars: 12