Agent skill

Senior Secops

by alirezarezvani in alirezarezvani/claude-skills

Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices.

MITAuto-check passedSecurity

Install Senior Secops

skills CLI
$ npx skills add alirezarezvani/claude-skills --skill senior-secops -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-skills senior-secops --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engineering-team/skills/senior-secops .claude/skills/senior-secops && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
senior-secops
GitHub stars
28k
Used in
1 other repo
Token cost
~4k tokens
SKILL.md length
878 words
Files
7 (incl. scripts, references)
Skills in repo
342
Repo updated
First seen
Licence
MIT

At a glance

Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices.

  • Works in 3 steps: Security Scanner → Vulnerability Assessor → Compliance Checker
  • Conducting a security review
  • SKILL.md covers Table of Contents, Core Capabilities, Workflows and Tool Reference, plus 5 more sections
  • Runs Python scripts from its folder; calls python; reaches github.com and token.actions.githubusercontent.com; needs API_KEY

What it does

Senior Secops is an agent skill from alirezarezvani/claude-skills. Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST scans, generates CVE remediation plans, checks dependency vulnerabilities, creates security policies, enforces secure coding patterns, and automates compliance checks against SOC2, PCI-DSS, HIPAA, and GDPR. Use when conducting a security review or audit, responding to a CVE or security incident, hardening infrastructure, implementing authentication or secrets…

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/compliance_requirements.md`, `references/security_standards.md` and `references/vulnerability_management_guide.md`).

It sits in Security, covering Vulnerability scanning, Healthcare and finance regulation and SOC 2 and security compliance. It works with npm. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.

When your agent uses it

  • Conducting a security review
  • Responding to a CVE
  • Security incident
  • Hardening infrastructure

Example prompts

  • “/senior-secops”

Requirements

  • Python 3
  • A credential in API_KEY

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Security Scanner
  2. Vulnerability Assessor
  3. Compliance Checker

What it can do on your machine

Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • token.actions.githubusercontent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Senior Secops loads about 4k tokens when it runs, and up to ~18k if it reads all its reference files. Until then it costs about 164 tokens; SKILL.md has 878 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~164
When it runs · the whole SKILL.md, loaded when a task matches
~4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~18k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 878 words, ~4,010 tokens.

Download SKILL.mdSave it as .claude/skills/senior-secops/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
senior-secops
description
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST scans, generates CVE remediation plans, checks dependency vulnerabilities, creates security policies, enforces secure coding patterns, and automates compliance checks against SOC2, PCI-DSS, HIPAA, and GDPR. Use when conducting a security review or audit, responding to a CVE or security incident, hardening infrastructure, implementing authentication or secrets management, running penetration test prep, checking OWASP Top 10 exposure, or enforcing security controls in CI/CD pipelines.

Senior SecOps Engineer

Complete toolkit for Security Operations including vulnerability management, compliance verification, secure coding practices, and security automation.


Table of Contents


Core Capabilities

1. Security Scanner

Scan source code for security vulnerabilities including hardcoded secrets, SQL injection, XSS, command injection, and path traversal.

bash
# Scan project for security issues
python scripts/security_scanner.py /path/to/project

# Filter by severity
python scripts/security_scanner.py /path/to/project --severity high

# JSON output for CI/CD
python scripts/security_scanner.py /path/to/project --json --output report.json

Detects:

  • Hardcoded secrets (API keys, passwords, AWS credentials, GitHub tokens, private keys)
  • SQL injection patterns (string concatenation, f-strings, template literals)
  • XSS vulnerabilities (innerHTML assignment, unsafe DOM manipulation, React unsafe patterns)
  • Command injection (shell=True, exec, eval with user input)
  • Path traversal (file operations with user input)
2. Vulnerability Assessor

Scan dependencies for known CVEs across npm, Python, and Go ecosystems.

bash
# Assess project dependencies
python scripts/vulnerability_assessor.py /path/to/project

# Critical/high only
python scripts/vulnerability_assessor.py /path/to/project --severity high

# Export vulnerability report
python scripts/vulnerability_assessor.py /path/to/project --json --output vulns.json

Scans:

  • package.json and package-lock.json (npm)
  • requirements.txt and pyproject.toml (Python)
  • go.mod (Go)

Output:

  • CVE IDs with CVSS scores
  • Affected package versions
  • Fixed versions for remediation
  • Overall risk score (0-100)
3. Compliance Checker

Verify security compliance against SOC 2, PCI-DSS, HIPAA, and GDPR frameworks.

bash
# Check all frameworks
python scripts/compliance_checker.py /path/to/project

# Specific framework
python scripts/compliance_checker.py /path/to/project --framework soc2
python scripts/compliance_checker.py /path/to/project --framework pci-dss
python scripts/compliance_checker.py /path/to/project --framework hipaa
python scripts/compliance_checker.py /path/to/project --framework gdpr

# Export compliance report
python scripts/compliance_checker.py /path/to/project --json --output compliance.json

Verifies:

  • Access control implementation
  • Encryption at rest and in transit
  • Audit logging
  • Authentication strength (MFA, password hashing)
  • Security documentation
  • CI/CD security controls

Workflows

Workflow 1: Security Audit

Complete security assessment of a codebase.

bash
# Step 1: Scan for code vulnerabilities
python scripts/security_scanner.py . --severity medium
# STOP if exit code 2 — resolve critical findings before continuing
bash
# Step 2: Check dependency vulnerabilities
python scripts/vulnerability_assessor.py . --severity high
# STOP if exit code 2 — patch critical CVEs before continuing
bash
# Step 3: Verify compliance controls
python scripts/compliance_checker.py . --framework all
# STOP if exit code 2 — address critical gaps before proceeding
bash
# Step 4: Generate combined reports
python scripts/security_scanner.py . --json --output security.json
python scripts/vulnerability_assessor.py . --json --output vulns.json
python scripts/compliance_checker.py . --json --output compliance.json
Workflow 2: CI/CD Security Gate

Integrate security checks into deployment pipeline.

yaml
# .github/workflows/security.yml
name: "security-scan"

on:
  pull_request:
    branches: [main, develop]

jobs:
  security-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: "set-up-python"
        uses: actions/setup-python@v5
        with:
          python-version: '3.11'

      - name: "security-scanner"
        run: python scripts/security_scanner.py . --severity high

      - name: "vulnerability-assessment"
        run: python scripts/vulnerability_assessor.py . --severity critical

      - name: "compliance-check"
        run: python scripts/compliance_checker.py . --framework soc2

Each step fails the pipeline on its respective exit code — no deployment proceeds past a critical finding.

Workflow 3: CVE Triage

Respond to a new CVE affecting your application.

1. ASSESS (0-2 hours)
   - Identify affected systems using vulnerability_assessor.py
   - Check if CVE is being actively exploited
   - Determine CVSS environmental score for your context
   - STOP if CVSS 9.0+ on internet-facing system — escalate immediately

2. PRIORITIZE
   - Critical (CVSS 9.0+, internet-facing): 24 hours
   - High (CVSS 7.0-8.9): 7 days
   - Medium (CVSS 4.0-6.9): 30 days
   - Low (CVSS < 4.0): 90 days

3. REMEDIATE
   - Update affected dependency to fixed version
   - Run security_scanner.py to verify fix (must return exit code 0)
   - STOP if scanner still flags the CVE — do not deploy
   - Test for regressions
   - Deploy with enhanced monitoring

4. VERIFY
   - Re-run vulnerability_assessor.py
   - Confirm CVE no longer reported
   - Document remediation actions
Workflow 4: Incident Response

Security incident handling procedure.

PHASE 1: DETECT & IDENTIFY (0-15 min)
- Alert received and acknowledged
- Initial severity assessment (SEV-1 to SEV-4)
- Incident commander assigned
- Communication channel established

PHASE 2: CONTAIN (15-60 min)
- Affected systems identified
- Network isolation if needed
- Credentials rotated if compromised
- Preserve evidence (logs, memory dumps)

PHASE 3: ERADICATE (1-4 hours)
- Root cause identified
- Malware/backdoors removed
- Vulnerabilities patched (run security_scanner.py; must return exit code 0)
- Systems hardened

PHASE 4: RECOVER (4-24 hours)
- Systems restored from clean backup
- Services brought back online
- Enhanced monitoring enabled
- User access restored

PHASE 5: POST-INCIDENT (24-72 hours)
- Incident timeline documented
- Root cause analysis complete
- Lessons learned documented
- Preventive measures implemented
- Stakeholder report delivered

Tool Reference

security_scanner.py
OptionDescription
targetDirectory or file to scan
--severity, -sMinimum severity: critical, high, medium, low
--verbose, -vShow files as they're scanned
--jsonOutput results as JSON
--output, -oWrite results to file

Exit Codes: 0 = no critical/high findings · 1 = high severity findings · 2 = critical severity findings

vulnerability_assessor.py
OptionDescription
targetDirectory containing dependency files
--severity, -sMinimum severity: critical, high, medium, low
--verbose, -vShow files as they're scanned
--jsonOutput results as JSON
--output, -oWrite results to file

Exit Codes: 0 = no critical/high vulnerabilities · 1 = high severity vulnerabilities · 2 = critical severity vulnerabilities

compliance_checker.py
OptionDescription
targetDirectory to check
--framework, -fFramework: soc2, pci-dss, hipaa, gdpr, all
--verbose, -vShow checks as they run
--jsonOutput results as JSON
--output, -oWrite results to file

Exit Codes: 0 = compliant (90%+ score) · 1 = non-compliant (50-69% score) · 2 = critical gaps (<50% score)


Security Standards

See references/security_standards.md for OWASP Top 10 full guidance, secure coding standards, authentication requirements, and API security controls.

Secure Coding Checklist
markdown
## Input Validation
- [ ] Validate all input on server side
- [ ] Use allowlists over denylists
- [ ] Sanitize for specific context (HTML, SQL, shell)

## Output Encoding
- [ ] HTML encode for browser output
- [ ] URL encode for URLs
- [ ] JavaScript encode for script contexts

## Authentication
- [ ] Use bcrypt/argon2 for passwords
- [ ] Implement MFA for sensitive operations
- [ ] Enforce strong password policy

## Session Management
- [ ] Generate secure random session IDs
- [ ] Set HttpOnly, Secure, SameSite flags
- [ ] Implement session timeout (15 min idle)

## Error Handling
- [ ] Log errors with context (no secrets)
- [ ] Return generic messages to users
- [ ] Never expose stack traces in production

## Secrets Management
- [ ] Use environment variables or secrets manager
- [ ] Never commit secrets to version control
- [ ] Rotate credentials regularly

Compliance Frameworks

See references/compliance_requirements.md for full control mappings. Run compliance_checker.py to verify the controls below:

SOC 2 Type II
  • CC6 Logical Access: authentication, authorization, MFA
  • CC7 System Operations: monitoring, logging, incident response
  • CC8 Change Management: CI/CD, code review, deployment controls
PCI-DSS v4.0
  • Req 3/4: Encryption at rest and in transit (TLS 1.2+)
  • Req 6: Secure development (input validation, secure coding)
  • Req 8: Strong authentication (MFA, password policy)
  • Req 10/11: Audit logging, SAST/DAST/penetration testing
HIPAA Security Rule
  • Unique user IDs and audit trails for PHI access (164.312(a)(1), 164.312(b))
  • MFA for person/entity authentication (164.312(d))
  • Transmission encryption via TLS (164.312(e)(1))
GDPR
  • Art 25/32: Privacy by design, encryption, pseudonymization
  • Art 33: Breach notification within 72 hours
  • Art 17/20: Right to erasure and data portability

Show full SKILL.md (352 more words)Show less

Best Practices

Secrets Management
python
# BAD: Hardcoded secret
API_KEY = "sk-1234567890abcdef"

# GOOD: Environment variable
import os
API_KEY = os.environ.get("API_KEY")

# BETTER: Secrets manager
from your_vault_client import get_secret
API_KEY = get_secret("api/key")
SQL Injection Prevention
python
# BAD: String concatenation
query = f"SELECT * FROM users WHERE id = {user_id}"

# GOOD: Parameterized query
cursor.execute("SELECT * FROM users WHERE id = %s", (user_id,))
XSS Prevention
javascript
// BAD: Direct innerHTML assignment is vulnerable
// GOOD: Use textContent (auto-escaped)
element.textContent = userInput;

// GOOD: Use sanitization library for HTML
import DOMPurify from 'dompurify';
const safeHTML = DOMPurify.sanitize(userInput);
Authentication
javascript
// Password hashing
const bcrypt = require('bcrypt');
const SALT_ROUNDS = 12;

// Hash password
const hash = await bcrypt.hash(password, SALT_ROUNDS);

// Verify password
const match = await bcrypt.compare(password, hash);
Security Headers
javascript
// Express.js security headers
const helmet = require('helmet');
app.use(helmet());

// Or manually set headers:
app.use((req, res, next) => {
  res.setHeader('X-Content-Type-Options', 'nosniff');
  res.setHeader('X-Frame-Options', 'DENY');
  res.setHeader('X-XSS-Protection', '1; mode=block');
  res.setHeader('Strict-Transport-Security', 'max-age=31536000; includeSubDomains');
  res.setHeader('Content-Security-Policy', "default-src 'self'");
  next();
});

OWASP Top 10 Quick-Check

Rapid 15-minute assessment — run through each category and note pass/fail. For deep-dive testing, hand off to the security-pen-testing skill.

#CategoryOne-Line Check
A01Broken Access ControlVerify role checks on every endpoint; test horizontal privilege escalation
A02Cryptographic FailuresConfirm TLS 1.2+ everywhere; no secrets in logs or source
A03InjectionRun parameterized query audit; check ORM raw-query usage
A04Insecure DesignReview threat model exists for critical flows
A05Security MisconfigurationCheck default credentials removed; error pages generic
A06Vulnerable ComponentsRun vulnerability_assessor.py; zero critical/high CVEs
A07Auth FailuresVerify MFA on admin; brute-force protection active
A08Software & Data IntegrityConfirm CI/CD pipeline signs artifacts; no unsigned deps
A09Logging & MonitoringValidate audit logs capture auth events; alerts configured
A10SSRFTest internal URL filters; block metadata endpoints (169.254.169.254)

Deep dive needed? Hand off to security-pen-testing for full OWASP Testing Guide coverage.


Secret Scanning Tools

Choose the right scanner for each stage of your workflow:

ToolBest ForLanguagePre-commitCI/CDCustom Rules
gitleaksCI pipelines, full-repo scansGoYesYesTOML regexes
detect-secretsPre-commit hooks, incrementalPythonYesPartialPlugin-based
truffleHogDeep history scans, entropyGoNoYesRegex + entropy

Recommended setup: Use detect-secrets as a pre-commit hook (catches secrets before they enter history) and gitleaks in CI (catches anything that slips through).

bash
# detect-secrets pre-commit hook (.pre-commit-config.yaml)
- repo: https://github.com/Yelp/detect-secrets
  rev: v1.4.0
  hooks:
    - id: detect-secrets
      args: ['--baseline', '.secrets.baseline']

# gitleaks in GitHub Actions
- name: gitleaks
  uses: gitleaks/gitleaks-action@v2
  env:
    GITLEAKS_LICENSE: ${{ secrets.GITLEAKS_LICENSE }}

Supply Chain Security

Protect against dependency and artifact tampering with SBOM generation, artifact signing, and SLSA compliance.

SBOM Generation:

  • syft — generates SBOMs from container images or source dirs (SPDX, CycloneDX formats)
  • cyclonedx-cli — CycloneDX-native tooling; merge multiple SBOMs for mono-repos
bash
# Generate SBOM from container image
syft packages ghcr.io/org/app:latest -o cyclonedx-json > sbom.json

Artifact Signing (Sigstore/cosign):

bash
# Sign a container image (keyless via OIDC)
cosign sign ghcr.io/org/app:latest
# Verify signature
cosign verify ghcr.io/org/app:latest --certificate-identity=ci@org.com --certificate-oidc-issuer=https://token.actions.githubusercontent.com

SLSA Levels Overview:

LevelRequirementWhat It Proves
1Build process documentedProvenance exists
2Hosted build service, signed provenanceTamper-resistant provenance
3Hardened build platform, non-falsifiable provenanceTamper-proof build
4Two-party review, hermetic buildsMaximum supply-chain assurance

Cross-references: security-pen-testing (vulnerability exploitation testing), dependency-auditor (license and CVE audit for dependencies).


Reference Documentation

DocumentDescription
references/security_standards.mdOWASP Top 10, secure coding, authentication, API security
references/vulnerability_management_guide.mdCVE triage, CVSS scoring, remediation workflows
references/compliance_requirements.mdSOC 2, PCI-DSS, HIPAA, GDPR full control mappings

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in engineering-team/skills/senior-secops of alirezarezvani/claude-skills.

  • SKILL.md
  • references/compliance_requirements.md
  • references/security_standards.md
  • references/vulnerability_management_guide.md
  • scripts/compliance_checker.py
  • scripts/security_scanner.py
  • scripts/vulnerability_assessor.py

Open the folder on GitHubat commit 19392f7

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in alirezarezvani/claude-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Senior Secops next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Senior Secops compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Senior Secops this skillalirezarezvani/claude-skills28k1 repos~4kAutomated safety check: PassMIT
Security Auditorcuriositech/some_claude_skills243—~2.2kAutomated safety check: PassMIT
Senior Secopsborghei/Claude-Skills886—~1.7kAutomated safety check: PassMIT
Code Vuln Auditzebbern/claude-code-guide4.7k—~1.3kAutomated safety check: PassMIT
Security Auditoraiskillstore/marketplace4306 repos~2.6kAutomated safety check: PassNone
Security Analyzeraiskillstore/marketplace430—~1.2kAutomated safety check: NotesNone

Similar skills

  • Security Auditor

    curiositech/some_claude_skills

    Security vulnerability scanner and OWASP compliance auditor for codebases.

    243 GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Senior Secops

    borghei/Claude-Skills

    SecOps for application security, vulnerability management, compliance, and secure development.

    886 GitHub stars~1.7k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Code Vuln Audit

    zebbern/claude-code-guide

    Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

    4.7k GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check passed
  • Security Auditor

    aiskillstore/marketplace

    Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.

    430 GitHub starsUsed in 6 repos~2.6k tokens
    SecurityAuto-check passed
  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    430 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check: notes
  • Find Cybersecurity Firm

    jeremylongshore/tons-of-skills-marketplace

    A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed…

    2.8k GitHub stars~3.7k tokensUpdated today
    SecurityAuto-check: notes

More from alirezarezvani/claude-skills

All 342 skills in this repo
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Product Strategist

    alirezarezvani/claude-skills

    OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.

    28k GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • App Store Optimization

    alirezarezvani/claude-skills

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.

    28k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Campaign Analytics

    alirezarezvani/claude-skills

    Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Code to PRD

    alirezarezvani/claude-skills

    Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.

    28k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed

Works with

Questions about Senior Secops

What does Senior Secops do?

Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Senior Secops is an agent skill from alirezarezvani/claude-skills. Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices.

When should I use Senior Secops?

Senior Secops fits situations like: conducting a security review; responding to a CVE; security incident; hardening infrastructure.

How do I install Senior Secops in Claude Code?

Run `npx skills add alirezarezvani/claude-skills --skill senior-secops -a claude-code`. Or copy the skill folder (engineering-team/skills/senior-secops in alirezarezvani/claude-skills) into .claude/skills/senior-secops in your project. Claude Code loads it when a task matches its description.

How do I install Senior Secops in Codex?

Run `npx skills add alirezarezvani/claude-skills --skill senior-secops -a codex`. Or copy the skill folder (engineering-team/skills/senior-secops in alirezarezvani/claude-skills) into .agents/skills/senior-secops in your project. Codex loads it when a task matches its description.

Can I use Senior Secops in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill senior-secops -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/senior-secops, .gemini/skills/senior-secops, .github/skills/senior-secops and .opencode/skills/senior-secops in your project.

What does Senior Secops need to run?

Going by SKILL.md and its folder, Senior Secops needs Python for the scripts in its folder, the command-line tools its instructions call (python) and credentials named API_KEY. Our summary lists: Python 3; A credential in API_KEY.

Does Senior Secops access the network?

SKILL.md names 2 domains. In commands or code: github.com and token.actions.githubusercontent.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Senior Secops safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Senior Secops use?

Senior Secops is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Senior Secops use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 14k tokens, read only when the agent opens those files.

What are the alternatives to Senior Secops?

Skills that share tags, products or a category with Senior Secops: Security Auditor (curiositech/some_claude_skills, 243 stars), Senior Secops (borghei/Claude-Skills, 886 stars), Code Vuln Audit (zebbern/claude-code-guide, 4.7k stars) and Security Auditor (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Senior Secops?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,891 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.

Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.