5 min read

Fabric: A Library of AI Prompts for the Terminal (GitHub, Scanned)

A CLI and about 260 ready-made AI prompts for summarizing, extracting and rewriting any text.

Fabric logo
✅
Scan: safe. Nothing to warn about. The installer downloads the release binary to your home folder and only prints, never runs, the sudo and PATH advice it gives. Scanned Oct 3, 2026; the full report is below.

Fabric treats prompts as tools. Each pattern is a Markdown prompt written for one job, such as summarize, extract_wisdom, analyze_claims or writing an essay, and the fabric command pipes any text through one: paste an article into it, point it at a web page with -u, or give it a YouTube URL with -y and it fetches the transcript first. The repository carries about 260 patterns, and your own sit in a folder beside them.

Fabric is a single Go binary that works with nearly every model provider: OpenAI, Anthropic, Gemini, Ollama, LM Studio, Azure, Bedrock and Vertex natively, plus OpenAI-compatible services such as Groq, DeepSeek, Mistral and OpenRouter. It can also use an existing ChatGPT or Claude subscription through the Codex and Claude Code CLIs, map different models to different patterns, and run as a REST server, including an Ollama-compatible mode that presents patterns as models to other apps.

It was created by security researcher Daniel Miessler in early 2024, is MIT-licensed, and has about 44,200 stars. His posts on X and a steady stream of YouTube tutorials spread it, and the original demo, running extract_wisdom on a YouTube video, is still the quickest way to see what it does.

Who it is for

Terminal users who want repeatable AI tasks without retyping prompts, researchers and writers working through long articles, videos and podcasts, and anyone who wants a curated prompt library they can read and edit.

Getting started

1. Install on macOS or Linux (Windows: winget install danielmiessler.Fabric)

curl -fsSL https://raw.githubusercontent.com/danielmiessler/fabric/main/scripts/installer/install.sh | bash

2. Pick a provider, add its API key and download the patterns

fabric --setup

3. Summarize whatever is on the clipboard (macOS)

pbpaste | fabric --pattern summarize

4. Pull the key ideas out of a YouTube video

fabric -y "https://youtube.com/watch?v=uXs-zPc63kM" --stream --pattern extract_wisdom

The one-line installer is a script piped to bash. Homebrew (brew install fabric-ai) is an alternative but installs the command as fabric-ai, so add alias fabric='fabric-ai'. The -y option uses yt-dlp, which must be installed, and pages fetched with -u go through Jina AI's reader service.

Safety scan

We cloned danielmiessler/Fabric at commit ddf1aab on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets and no bare-IP URLs across 868 files and about 109,000 lines, mostly Go and the Markdown patterns. The single pattern hit is the usage comment at the top of scripts/installer/install.sh showing the curl | bash one-liner.
  • We read the installers. install.sh and install.ps1 download the release archive for your platform from GitHub into ~/.local/bin by default; the sudo and shell-profile flags come from messages suggesting sudo for system folders and a PATH line to add yourself. It does not check the SHA-256 the release page publishes, so the manual download is the stricter route. completions/setup-completions.sh is the same kind of script for shell completions.
  • 12 known advisories (1 high, 11 of unknown severity). Nine name github.com/ollama/ollama, which Fabric imports for its client types; they concern the Ollama server, not the client code. The others are golang.org/x/crypto's deprecated openpgp package, a gRPC server panic, and braces in the web UI's build tooling.
  • No telemetry. Network access is the model provider you configure, YouTube transcripts through yt-dlp, and Jina AI's reader when you use -u on a URL.
  • Four workflows, none using pull_request_target; the 3 third-party actions are pinned to tags. Security policy and licence present; no contributing guide, Dependabot or CodeQL.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious code1 pattern hit found and read; every one is listed under the raw findings.
Install-time code1 npm lifecycle script. 3 installer scripts (one edits your shell profile; one can call sudo)
Committed binariesNone.
CI workflows4 workflows. None use pull_request_target. 3 of 3 third-party actions pinned to a tag rather than a commit.
Network hosts40 distinct hosts referenced from source; most often github.com, gw.example.com, raw.githubusercontent.com, open.spotify.com. No URLs to bare IP addresses.
Known vulnerabilities12 advisories across 630 pinned packages: 0 critical, 1 high, 0 moderate, 0 low, 11 unrated. go.mod: 157 packages, 11 advisories; web/package-lock.json: 487 packages, 1 advisories; web/pnpm-lock.yaml: 460 packages, 1 advisories.
Project hygieneHas security policy, licence file. Missing automated dependency updates, CodeQL, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Pattern hits (1)
WhereRuleMatch
scripts/installer/install.sh:3download-piped-to-shell# Usage: curl -fsSL https://raw.githubusercontent.com/danielmiessler/fabric/main/scripts/installer/install.sh | bash
npm lifecycle scripts (1)
  • web/package.json postinstall: svelte-kit sync
Installer scripts (3)
Worst known vulnerabilities (12 of 12)
AdvisorySeverityPackageSummary
GHSA-vfj7-8cjw-p6xmhighbraces@3.0.3braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
GHSA-fccc-8m69-8r78unknowngithub.com/ollama/ollama@0.34.4Ollama Allocation of Resources Without Limits or Throttling vulnerability in github.com/ollama/ollama
GHSA-89qx-m49c-8crfunknowngithub.com/ollama/ollama@0.34.4Ollama Allows Out-of-Bounds Read in github.com/ollama/ollama
GHSA-9gcr-28rp-cc24unknowngithub.com/ollama/ollama@0.34.4Ollama Divide By Zero vulnerability in github.com/ollama/ollama
GHSA-p2wh-w96x-w232unknowngithub.com/ollama/ollama@0.34.4Ollama Denial of Service (DoS) via Null Pointer Dereference in github.com/ollama/ollama
GHSA-2xf2-gjm6-g2c6unknowngithub.com/ollama/ollama@0.34.4Ollama Divide by Zero Vulnerability in github.com/ollama/ollama
GHSA-wrh5-cmwx-q2qrunknowngithub.com/ollama/ollama@0.34.4Ollama Server Vulnerable to Denial of Service (DoS) Attack in github.com/ollama/ollama
GHSA-x9hg-5q6g-q3jrunknowngithub.com/ollama/ollama@0.34.4Ollama vulnerable to Cross-Domain Token Exposure in github.com/ollama/ollama
GHSA-f6mr-38g8-39rgunknowngithub.com/ollama/ollama@0.34.4Ollama has missing authentication enabling attackers to perform model management operations in github.com/ollama/ollama
GHSA-x99g-8v8j-25j2unknowngithub.com/ollama/ollama@0.34.4Ollama is Vulnerable to Path Traversal in github.com/ollama/ollama
GO-2026-5932unknowngolang.org/x/crypto@0.57.0The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
GHSA-2v4p-qf9q-27wjunknowngoogle.golang.org/grpc@1.84.0Server panic via missing authority or Host headers in google.golang.org/grpc

By the numbers

Stars44.2K
Forks4,293
Contributors271
Commits4,153
Open issues26
Open pull requests17
Releases460
Latest releasev1.4.507
LicenceMIT
Main languageGo
Project age2 years
Last pushOct 3, 2026
Tracked files868
Lines of code109.2K
Checkout size28 MB

Lines by language: Markdown 41.9K, Go 39.4K, JSON 13.8K, Svelte 4,915, TypeScript 3,029, Python 2,422.

Questions

Is Fabric free?

Yes. Fabric is MIT-licensed and free, patterns included. You pay your model provider per token, or nothing with a local model through Ollama or LM Studio, and it can also run on an existing ChatGPT or Claude subscription through the Codex and Claude Code integrations.

What is a Fabric pattern?

A folder holding a system.md prompt written for one task in a consistent Markdown structure: identity and purpose, the steps to take, and output instructions. You can read and edit any of them, and custom patterns in your own folder are picked up alongside the built-in ones.

Can other apps use Fabric's patterns?

Yes. fabric --serve starts a REST API, and fabric --serve --serveOllama adds Ollama-compatible endpoints that list patterns as models, so apps that talk to Ollama can call a pattern directly. The patterns are also plain Markdown you can paste into any chat.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.