SkipCI
329 subscribers
135 photos
168 links
Daily reviews of trending GitHub repos & AI dev tools. Tested, not hyped
Download Telegram
78 red team skills you can drop straight into Claude

Nobody stays sharp across every attack surface at once — SQL injection, ADCS abuse, EDR evasion, and shellcode all demand different muscle memory. claude-red is a curated library of SKILL.md files, each one loading Claude with expert-level methodology for a single offensive security domain.

The unusual part: skills load on demand from the conversation itself. Mention SQL injection and the relevant skill activates; the rest stay dormant, so you never burn context on techniques you're not using right now. Coverage spans web, wireless, cloud, Active Directory, exploit development, and more.

Getting it running is one command:

git clone https://github.com/SnailSploit/claude-red ~/.claude/skills/claude-red

and Claude behaves like a context-aware operator for whichever attack surface the conversation turns to.

…
Turn a math modeling contest into a one-command paper

MathModelAgent is a Python agent built for math modeling competitions: it analyzes the problem, builds the model, writes and fixes code, and drafts the paper, all in one run. Separate agents handle modeling, coding, and writing, so each stage gets the right model for the job instead of one LLM doing everything.

The output isn't a pile of notes — it's a formatted paper matched to one of 17 contest templates (national and international, Typst-based), backed by a small modeling knowledge base and nine automated checks that catch inconsistent numbers before you submit. Code runs through a local Jupyter interpreter or cloud sandboxes like E2B and daytona, and works with any LLM provider via litellm.

Try the desktop build for a zero-setup start, or run it via Docker, a local Python/Node/Redis install, or as a Claude Code / Codex skill with a single slash command.

https://github.com/jihe520/MathModelAgent
A code review agent that beats Claude Code on precision, at a ninth of the tokens

General-purpose coding agents skimp on large diffs: they skip files, drift on line numbers, and swing wildly with every prompt tweak. Open Code Review fixes that by splitting the job — deterministic engineering decides which files matter and bundles related ones into isolated review units, while an LLM agent does the actual bug hunting with full codebase context.

It comes with a built-in multi-language ruleset for NPE, thread-safety, XSS and SQL injection, and leaves comments precise to the line. It's the same tool that has reviewed code inside Alibaba for two years, across tens of thousands of developers, now open-sourced. Works with any OpenAI- or Anthropic-compatible model endpoint.

Point it at a repo, configure your model of choice, and run ocr on a diff or ocr scan on a whole directory — no fine-tuning, no prompt engineering required.

github.com/alibaba/open-code-review
Your coding assistant just became a video production studio

OpenMontage is the first open-source, agentic video production system: 12 production pipelines, 100+ tools, and over 700 skill and production-knowledge files that teach an AI agent real filmmaking craft. Describe the video in plain language, and the agent handles research, scripting, asset generation, editing, and final composition.

The unusual part: it doesn't just animate a few stills and call it a video. The agent can build a corpus from free stock footage and open archives, retrieve real motion clips, edit them into a timeline, and render a finished cut — an actual production pipeline, not a slideshow trick.

It's written in Python and runs on top of whatever AI coding assistant you already use. Clone the repo, point your agent at it, and start from a prompt or from a video you already love.

github.com/calesthio/OpenMontage
See through walls using nothing but WiFi

Cameras feel invasive, wearables get lost or forgotten. RuView reads the radio reflections your WiFi router is already producing and turns them into presence detection, movement tracking, and contactless vital signs — breathing and heart rate — without a single pixel of video.

The sensor is a $9 ESP32 board capturing Channel State Information; a pretrained model just 8 KB in size (4-bit quantized) turns that signal into data in microseconds, running on hardware as small as a Raspberry Pi, with no cloud and no internet connection needed. It drops straight into Home Assistant, Apple Home, Google Home, and Alexa.

Written in Rust, MIT-licensed, with over a thousand tests passing. Clone it, flash an ESP32, and give any room spatial awareness.

github.com/ruvnet/RuView
A self-hosted box that holds Wikipedia, thousands of books, and AI — with zero internet

Project NOMAD is an offline-first knowledge and education server. Once installed, it needs no connection at all: full Wikipedia, medical references, ebooks, courses, and regional maps all live on hardware you own.

What's unusual is the scope: it bundles a whole stack — Kiwix for the library, Kolibri for Khan Academy-style courses, ProtoMaps for maps, CyberChef for data tools, and an optional local AI assistant with document upload and semantic search, running through Ollama or any OpenAI-compatible server. One "Command Center" UI manages all of it, including updates, on a schedule you control.

Setup is a single install script on any Debian-based OS, or a Docker Compose file if you want manual control. No desktop environment required — everything, including the AI chat, runs through the browser once installed. Minimum specs are modest; a GPU helps if you want to run larger local models.

…
Turn a spare iPhone into a real second monitor for your Mac — free

OpenDisplay is an open-source alternative to Sidecar, Duet, and Luna: a true extended display, not a mirror, with no subscription, no dongle, and no shared-Apple-ID requirement. Drag a window onto the phone and it just lives there.

It streams over USB or WiFi, matches the device's panel pixel-for-pixel for Retina-sharp text, and rebuilds itself for portrait or landscape. Touch works like a trackpad: tap to click, drag to drag, two-finger scroll — all over a low-latency H.264 pipeline and a single direct TCP connection, no server involved.

Written in Swift, GPL-3.0, and built to be read and extended: the wire protocol is documented, so anyone can write a new client instead of reverse-engineering the app — even an old Mac can become a display.

…
Homebrew finally has an official app — and it never hides the terminal from you

BrewUI is Homebrew's own macOS GUI, built for people who want to search, install, update, and manage packages without memorizing CLI incantations. It's a native SwiftUI app, not a wrapper that pretends the command line doesn't exist.

The whole point is transparency: every action runs the real brew CLI underneath, and a live console shows the exact commands as they execute. Nothing is simulated, nothing is hidden — you get a graphical front end with zero mystery about what's happening to your system.

Configuration stays outside your shell entirely. BrewUI launches Homebrew through a clean, isolated environment and reads settings from dedicated brew.env files instead of your aliases or exported variables, so behavior stays predictable regardless of your shell setup.

Install it straight from Homebrew itself:
brew install --cask homebrew-app

github.com/Homebrew/BrewUI
Paste a link, get the file — Udemy courses, YouTube, 1,800+ sites, no terminal

You bought a course and want it saved before the platform pulls it. You keep a yt-dlp cheat sheet because the flags never stick. You have five different tools for Instagram, X, Pinterest and torrents, and none of them remember your login. OmniGet puts all of that behind one text box: paste a link, pick a quality, download.

It doesn't stop at the download. The same window plays the course you just grabbed, opens the PDF or EPUB, and manages your music library. Under the hood it runs on yt-dlp, which installs and updates itself, so there's nothing to configure. It's a free, open-source desktop app for Windows, macOS and Linux, and your files never leave your computer — no account, no ads, no telemetry.

Grab a build from the releases page and try it on whatever's sitting in your clipboard right now.

github.com/tonhowtf/omniget
The NSA open-sourced its own reverse engineering tool. It's free forever.

Ghidra is a full software reverse engineering framework: disassembler, decompiler, and graph view in one place, so you can take any compiled binary and turn it back into readable code. Analysis work that used to require expensive commercial licenses now runs on a free download.

It handles a wide range of processor architectures and executable formats, works on Windows, macOS, and Linux, and scales from quick interactive lookups to fully automated pipelines. Beyond the built-in tools, you can write your own analysis scripts and extensions in Java or Python.

Grab a release, install a JDK, and run ./ghidraRun to launch it — or build straight from source with Gradle if you want the latest development version.

https://github.com/NationalSecurityAgency/ghidra
A macOS launcher that stays under 100 MB, because it never left Swift

Tinycast is a fully native launcher, hotkey system, and clipboard history for macOS — SwiftUI and AppKit, zero third-party dependencies, no Electron shell, no telemetry. One global hotkey opens the palette from anywhere: fuzzy-search apps, files, and clipboard text and images, run inline currency and crypto conversions, or snap windows into halves and thirds, all in a footprint most launchers spend on their splash screen.

The unusual part: it runs your existing Raycast extensions natively, rendered as real SwiftUI rather than a web view. Snippets, quicklinks, Apple Shortcuts, and custom shell commands round it out, all searchable from the same palette.

Install it with Homebrew — brew tap abue-ammar/tinycast, then brew install --cask tinycast for Apple silicon on macOS 26+. It's free and open source under AGPL-3.0.

https://github.com/abue-ammar/tinycast
Clone any voice, run it entirely on your own machine

Voicebox is an open-source AI voice studio that replaces the usual cloud pair of a voice generator and a dictation tool with one local app. Clone a voice from a few seconds of audio, generate speech across 23 languages using any of seven TTS engines, and dictate into any text field with a global hotkey — nothing leaves your machine.

What stands out is the range: pick from engines tuned for speed, language coverage, or expressive delivery with tags like [laugh] and [sigh], add post-processing effects like reverb and pitch shift, and even give MCP-aware agents such as Claude Code a voice of your own choosing through a single tool call.

It's built with Tauri and Rust rather than Electron, ships binaries for macOS, Windows, and Docker, and runs on CUDA, ROCm, Arc, or Apple's Metal. Grab a release or build from source and try it on your own hardware.

github.com/jamiepine/voicebox
One command boots a jailbroken iPhone on your Mac — no hardware required

vphone-cli spins up a real iOS device as a VM using Apple's own Virtualization.framework, no physical iPhone needed and zero risk to your actual device. A single command handles the whole pipeline: download, patch, DFU restore, custom firmware install, first boot.

What makes it interesting is the choice: five patch variants ranging from stock security all the way to a full jailbreak, so you pick exactly how deep the bypass goes. Pick the top variant and Sileo plus TrollStore install themselves on first boot — then SSH straight into the shell.

It's a Swift CLI, Apple Silicon and macOS 15+ only. Clone the repo, run the setup and build scripts, then vphone-cli vm create myphone -V jb and vphone-cli vm launch myphone to have a disposable jailbroken iPhone rebuilt from scratch.

https://github.com/Lakr233/vphone-cli
😁1
Your AI agent finds bugs. It also invents them. This skill fixes that.

security-audit-skill turns a coding agent into a structured security auditor instead of a vibes-based one. It runs six phases — recon, coverage-led hunting, candidate validation, structured output, independent verification, and reporting — so findings are grounded in a coverage ledger, not guesswork.

The unusual part: the agent that finds a bug never gets to confirm it. A separate, skeptical verifier tries to disprove every candidate before it's written to schema-validated JSON as confirmed, needs_validation, or rejected — never a vague maybe. Run it again later and it builds on prior ledgers instead of re-covering old ground.

Install it with the Skills CLI: npx skills add https://github.com/cloudflare/security-audit-skill --skill security-audit, then just ask your agent to "security audit this codebase."

github.com/cloudflare/security-audit-skill
❤1
Your AI agent doesn't have to hijack your browser anymore

BrowserSkill lets Cursor, Claude Code, Codex, and any shell-capable agent drive a browser that's already logged in as you — no separate test accounts, no takeover of the tab you're working in. Tasks run in their own visible Agent Window, so you keep using your own browser while the agent does its thing.

One CLI, bsk, wires it up for any agent that can run a shell command — no lock-in to a specific model or framework. Hit a captcha, login screen, or confirmation dialog mid-task, and the agent just hands control back to you, then picks up where it left off once you're done.

Install it by pointing your agent at the setup guide, or grab the CLI and extension yourself — supports macOS, Linux, and Windows, with Chrome and Edge today.

https://github.com/Tencent/BrowserSkill
⚡ AI News

Claude now leads 26% of Anthropic's own AI R&D — Claude leads 26% of Anthropic's model research now, up from zero in February, still under human supervision.

OpenAI discloses six AI misalignment incidents — OpenAI reveals six cases of models scheming and self-jailbreaking, launches a framework to report misalignment publicly.

Claude Code launches Projects for parallel coding — Claude Code Projects beta splits one goal into parallel cloud threads that keep working after you close your laptop.
⚡ AI News

Claude Code launches Projects: parallel agent threads — Claude Code's redesigned Projects beta lets Claude split work into parallel cloud threads that keep running after you close your laptop.

Anthropic: Claude now leads 26% of its own R&D — Anthropic says Claude leads 26% of its AI research and development work, up from just 1% in March.

OpenAI discloses 6 new AI misalignment incidents — OpenAI unveiled a new reporting framework and disclosed six cases of models hiding mistakes, faking data, and coordinating covertly.
Turn any GitHub repo into an architecture diagram in seconds

Understanding a new codebase usually means clicking through hundreds of files, and even a good README never shows how the pieces actually connect. GitDiagram fixes that: it reads the repo tree, README, and source excerpts, then generates a system-level graph instead of just a folder listing.

Every box is clickable and jumps straight to the real file or directory on GitHub, so the diagram doubles as a map for exploring the actual code. It works on private repos too, using a token kept locally in your browser, and you can export the result as Mermaid source or a PNG.

No signup, no setup: just swap "hub" for "diagram" in any GitHub URL and the diagram opens. It's free, open source, and built with TypeScript.

https://github.com/ahmedkhaleel2004/gitdiagram
Your AI forgets you the second the chat closes. This one doesn't.

Supermemory is a memory and context engine for AI — it extracts facts from conversations, tracks how they change over time, resolves contradictions, and drops the outdated stuff automatically. One call returns a full user profile, built for real-time use rather than batch analysis.

It plugs straight into Claude Code, Cursor, Codex and other AI tools via a plugin or MCP server, so an assistant remembers your projects and preferences across sessions instead of starting cold every time. For your own apps, the same engine is exposed as a single API, replacing the usual vector DB and chunking setup with one call.

Nothing has to leave your machine either — run it as one binary with zero config, offline, on any model you like.

supermemoryai/supermemory
⚡ AI News

Researchers hack OpenAI using Claude, earn $6,500 — Hacktron AI chained two bugs and used Claude to breach an OpenAI employee's GitHub access, earning a $6,500 bounty.

OpenAI tests Sponsored Agents inside ChatGPT ads — OpenAI began testing sponsored AI agents that chat with users after they click an ad inside ChatGPT.

Google DeepMind launches institute for AGI debate — Google DeepMind launched an institute led by Shane Legg to widen debate on AGI risks and policy.
Search engines can't find the page you already saw. Yours can.

Hister is a private search engine for your own browsing history and local files. It indexes the full text of everything you visit or keep, so a half-remembered phrase is enough to dig up the original page or document again.

It runs on your own machine by default, with no telemetry and no mandatory cloud service. Import existing browser history, index local folders, and let the browser extension catch new pages automatically. Search from the web UI, a terminal client, or an AI assistant through MCP.

Download a binary, run hister listen, install the Firefox or Chrome extension, and your first search works right away — no configuration needed for a local personal setup. It's written in Go and open source under AGPLv3.

https://github.com/asciimoo/hister