CI Pipeline Synthesizer
kajisho5/ffmpeg-skill
Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.
PreToolUse security-anti-pattern hook for Claude Code. An agent skill from alirezarezvani/claude-skills.
$ npx skills add alirezarezvani/claude-skills --skill security-guidance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install alirezarezvani/claude-skills security-guidance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engineering/security-guidance/skills/security-guidance .claude/skills/security-guidance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-guidance" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering/security-guidance/skills/security-guidance into .claude/skills/security-guidance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-guidance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/alirezarezvani/claude-skills/tree/main/engineering/security-guidance/skills/security-guidanceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add alirezarezvani/claude-skills --skill security-guidance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install alirezarezvani/claude-skills security-guidance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/engineering/security-guidance/skills/security-guidance .agents/skills/security-guidance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-guidance" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering/security-guidance/skills/security-guidance into .agents/skills/security-guidance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-guidance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add alirezarezvani/claude-skills --skill security-guidance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install alirezarezvani/claude-skills security-guidance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/engineering/security-guidance/skills/security-guidance .cursor/skills/security-guidance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-guidance" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering/security-guidance/skills/security-guidance into .cursor/skills/security-guidance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-guidance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/alirezarezvani/claude-skills.git --path engineering/security-guidance/skills/security-guidance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add alirezarezvani/claude-skills --skill security-guidance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install alirezarezvani/claude-skills security-guidance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/engineering/security-guidance/skills/security-guidance .gemini/skills/security-guidance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-guidance" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering/security-guidance/skills/security-guidance into .gemini/skills/security-guidance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-guidance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install alirezarezvani/claude-skills security-guidanceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add alirezarezvani/claude-skills --skill security-guidance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/engineering/security-guidance/skills/security-guidance .github/skills/security-guidance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-guidance" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering/security-guidance/skills/security-guidance into .github/skills/security-guidance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-guidance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add alirezarezvani/claude-skills --skill security-guidance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install alirezarezvani/claude-skills security-guidance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/engineering/security-guidance/skills/security-guidance .opencode/skills/security-guidance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-guidance" agent skill from https://github.com/alirezarezvani/claude-skills/tree/main/engineering/security-guidance/skills/security-guidance into .opencode/skills/security-guidance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-guidance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-guidancePreToolUse security-anti-pattern hook for Claude Code. An agent skill from alirezarezvani/claude-skills.
Security Guidance is an agent skill from alirezarezvani/claude-skills. PreToolUse security-anti-pattern hook for Claude Code. Catches 12 common security risks (command injection, XSS, SQL injection, unsafe deserialization, GitHub Actions workflow injection, eval/new Function code injection) BEFORE the Edit/Write/MultiEdit operation completes. Session-state caching prevents duplicate warnings on the same file+rule combo. Stdlib only — no dependencies. Use when you want a safety net during Claude Code sessions that touch security-sensitive code (auth, payments, user input handling…
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/pretooluse_hook_canon.md`).
It sits in Security, covering Web application vulnerabilities, Session handoff and CI/CD. It works with GitHub Actions and Python. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
claudeFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Guidance loads about 1.9k tokens when it runs, and up to ~4k if it reads all its reference files. Until then it costs about 205 tokens; SKILL.md has 770 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 770 words, ~1,945 tokens.
.claude/skills/security-guidance/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.A PreToolUse hook that blocks 12 common security anti-patterns before Claude Code writes them.
This skill is a hook, not a slash command. Once installed, it runs automatically before every Edit, Write, or MultiEdit operation and warns + blocks if it detects a known dangerous pattern.
The hook scans both:
${{ }} patterns| Pattern | Category | Risk |
|---|---|---|
| GitHub Actions workflow expressions | Path-based | Workflow command injection via untrusted inputs |
child_process.exec, exec(, execSync( | Substring | Node.js command injection |
new Function | Substring | JS code injection |
eval( | Substring | JS code injection |
dangerouslySetInnerHTML | Substring | React XSS |
document.write | Substring | DOM XSS |
.innerHTML = | Substring | DOM XSS |
pickle | Substring | Python deserialization RCE |
os.system, from os import system | Substring | Python command injection |
shell=True (subprocess) | Substring | Python command injection |
f-string SQL or .format SQL | Substring | SQL injection |
yaml.load(, yaml.unsafe_load | Substring | YAML deserialization RCE |
Edit, Write, or MultiEditsecurity_reminder_hook.py with the tool input as JSON on stdin~/.claude/security_warnings_state_<session>.jsonThis plugin ships as a Claude Code plugin with hooks.json wiring:
# In Claude Code:
/plugin marketplace add alirezarezvani/claude-skills
/plugin install security-guidance@claude-code-skillsOnce installed, no further configuration needed — the hook runs automatically.
Disable per-session via environment variable:
ENABLE_SECURITY_REMINDER=0 claude
# Hook is bypassed for this sessionUse sparingly — the hook is most useful exactly when you're tempted to disable it (because you're under deadline pressure to ship something you know is sketchy).
If a specific file legitimately needs eval() or pickle (e.g., a sandboxed REPL, a deliberately unsafe parser for a fuzzer), document it in the file with a comment:
# SAFETY: pickle is the required serialization format for this internal tool.
# This file does NOT accept untrusted input. See SECURITY.md for boundary analysis.
import pickleThe hook will still warn on first edit per session. After acknowledging, subsequent edits in the same session are allowed (session-state caching).
Trade-off: AST-based detection would be more precise (no false positives on string literals containing "eval("). Substring-based is:
For 90%+ of cases, substring detection is sufficient. If you need stricter detection, layer in a proper SAST tool (semgrep, CodeQL) as a CI step.
The hook caches "warning shown" state in ~/.claude/security_warnings_state_<session_id>.json. These files:
<file_path>-<rule_name> keysYou can safely delete ~/.claude/security_warnings_state_*.json files at any time — the hook regenerates them on next run.
The hook writes to ~/.claude/security-warnings-log.txt for debugging hook misfires:
tail -f ~/.claude/security-warnings-log.txt
# Shows JSON decode errors, state-file save failures, etc.(Upstream version wrote to /tmp/security-warnings-log.txt — we moved it to ~/.claude/ for persistence across reboots.)
This plugin is ported from David Dworken's MIT-licensed implementation in alirezarezvani/aeo-box.
Verbatim: the original 9 patterns (GitHub Actions, child_process.exec, new Function, eval, dangerouslySetInnerHTML, document.write, innerHTML, pickle, os.system) are preserved with their exact warning text.
Modifications:
subprocess shell=True, SQL injection via f-string or .format, yaml.unsafe_load/tmp/security-warnings-log.txt → ~/.claude/security-warnings-log.txtattribution block in .claude-plugin/authoring-notes.json (originally in plugin.json; relocated when issue #954 showed Claude Code rejects manifests carrying extension keys)Defeats the purpose. If ENABLE_SECURITY_REMINDER=0 becomes your default, you've trained yourself to ignore the safety net. Use it only for specific verified-safe operations.
Anyone can add a pattern. Removing one requires a security review — patterns exist because they map to real CVE classes.
The cache prevents nag-spam but is per-session. Don't rely on "I dismissed this once" as long-term policy — use the per-file documentation pattern instead (comment justifying the use).
engineering-team/skills/red-team — adversarial pen-testingengineering-team/skills/threat-detection — threat modeling + detection designengineering-team/skills/ai-security — AI-specific security (prompt injection, etc.)engineering/ship-gate — pre-production audit (8-category, ~89 checks)engineering/skill-security-auditor — security scan for skill packagesVersion: 2.7.3
Source: Ported from alirezarezvani/aeo-box .claude/plugins/security-guidance/ (originally by David Dworken at Anthropic, MIT)
License: MIT
© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in engineering/security-guidance/skills/security-guidance of alirezarezvani/claude-skills.
Open the folder on GitHubat commit 19392f7
Security Guidance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Guidance this skillalirezarezvani/claude-skills | 28k | — | ~1.9k | Automated safety check: Pass | MIT | |
| CI Pipeline Synthesizerkajisho5/ffmpeg-skill | 1.9k | 1 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Code Securitysemgrep/skills | 322 | — | ~1.2k | Automated safety check: Pass | Custom licence | |
| Sast BanditAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~2.6k | Automated safety check: Pass | Custom licence | |
| Integrating Dast With Owasp Zap In Pipelinemukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Reproduce macOS Python FlavorsNuitka/Nuitka | 15k | — | ~1.7k | Automated safety check: Pass | AGPL-3.0 |
kajisho5/ffmpeg-skill
Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.
semgrep/skills
Security guidelines for writing secure code. An agent skill from semgrep/skills.
AgentSecOps/SecOpsAgentKit
Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping.
mukul975/Anthropic-Cybersecurity-Skills
Integrates OWASP ZAP (Zed Attack Proxy) into GitHub Actions and GitLab CI pipelines, covering baseline, full, and API scan configuration against running applications, ZAP finding interpretation…
Nuitka/Nuitka
Reproduce macOS Nuitka issues across Python distributions and GitHub Actions Python packaging.
bubbuild/bub
GitHub CLI skill for interacting with GitHub via the gh command line tool.
alirezarezvani/claude-skills
Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.
alirezarezvani/claude-skills
OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.
alirezarezvani/claude-skills
App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.
alirezarezvani/claude-skills
Design AWS architectures for startups using serverless patterns and IaC templates.
alirezarezvani/claude-skills
Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.
alirezarezvani/claude-skills
Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.
Works with
Categories
PreToolUse security-anti-pattern hook for Claude Code. An agent skill from alirezarezvani/claude-skills. Security Guidance is an agent skill from alirezarezvani/claude-skills. PreToolUse security-anti-pattern hook for Claude Code.
Security Guidance fits situations like: you want a safety net during Claude Code sessions that touch security-sensitive code (auth; user input handling; — add security hook; block unsafe code.
Run `npx skills add alirezarezvani/claude-skills --skill security-guidance -a claude-code`. Or copy the skill folder (engineering/security-guidance/skills/security-guidance in alirezarezvani/claude-skills) into .claude/skills/security-guidance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add alirezarezvani/claude-skills --skill security-guidance -a codex`. Or copy the skill folder (engineering/security-guidance/skills/security-guidance in alirezarezvani/claude-skills) into .agents/skills/security-guidance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill security-guidance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-guidance, .gemini/skills/security-guidance, .github/skills/security-guidance and .opencode/skills/security-guidance in your project.
Going by SKILL.md and its folder, Security Guidance needs the command-line tools its instructions call (claude). Our summary lists: Python 3; Node.js.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Guidance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Security Guidance: CI Pipeline Synthesizer (kajisho5/ffmpeg-skill, 1.9k stars), Code Security (semgrep/skills, 322 stars), Sast Bandit (AgentSecOps/SecOpsAgentKit, 220 stars) and Integrating Dast With Owasp Zap In Pipeline (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,891 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.
Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.