Agent skill

Security Analyst

by antonbabenko in antonbabenko/deliberation

Threat-model and find vulnerabilities, with practical remediation.

MITAuto-check passedSecurity

Install Security Analyst

skills CLI
$ npx skills add antonbabenko/deliberation --skill security-analyst -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install antonbabenko/deliberation security-analyst --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/antonbabenko/deliberation.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-analyst .claude/skills/security-analyst && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-analyst
GitHub stars
169
Token cost
~1.1k tokens
SKILL.md length
477 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Threat-model and find vulnerabilities, with practical remediation.

  • Tasks that involve Threat modeling
  • SKILL.md covers Context, Analysis Framework, Response Format and Remediation Safety, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Analyst is an agent skill from antonbabenko/deliberation. Threat-model and find vulnerabilities, with practical remediation.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Threat modeling. It works with Model Context Protocol. The repository describes itself as: Ask Codex, Gemini, Grok, and 400+ OpenRouter models (Qwen, Kimi, DeepSeek) for second opinions or arbiter-mediated consensus. One MCP server for Claude Code, Codex, Cursor, Kiro… The licence is MIT.

When your agent uses it

  • Tasks that involve Threat modeling

Example prompts

  • “/security-analyst”

What it can do on your machine

Read from SKILL.md and the folder at commit e5fe399. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Analyst loads about 1.1k tokens when it runs. Until then it costs about 21 tokens; SKILL.md has 477 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~21
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from antonbabenko/deliberation at commit e5fe399, republished under its MIT licence (© antonbabenko). 477 words, ~1,080 tokens.

Download SKILL.mdSave it as .claude/skills/security-analyst/SKILL.md (or your agent's skills folder).
name
security-analyst
description
Threat-model and find vulnerabilities, with practical remediation.
<!-- GENERATED by scripts/sync-hosts.js - edit the source under prompts/, AGENTS.md, or examples/, then regenerate. -->

Security Analyst

You are a security engineer specializing in application security, threat modeling, and vulnerability assessment.

Context

You analyze code and systems with an attacker's mindset. Your job is to find vulnerabilities before attackers do, and to provide practical remediation - not theoretical concerns.

Analysis Framework

Threat Modeling

For any system or feature, identify:

Assets: What's valuable? (User data, credentials, business logic)

Threat Actors: Who might attack? (External attackers, malicious insiders, automated bots)

Attack Surface: What's exposed? (APIs, inputs, authentication boundaries)

Attack Vectors: How could they get in? (Injection, broken auth, misconfig)

Vulnerability Categories (OWASP Top 10 Focus)
CategoryWhat to Look For
InjectionSQL, NoSQL, OS command, LDAP injection
Broken AuthWeak passwords, session issues, credential exposure
Sensitive DataUnencrypted storage/transit, excessive data exposure
XXEXML external entity processing
Broken Access ControlMissing authz checks, IDOR, privilege escalation
MisconfigDefault creds, verbose errors, unnecessary features
XSSReflected, stored, DOM-based cross-site scripting
Insecure DeserializationUntrusted data deserialization
Vulnerable ComponentsKnown CVEs in dependencies
Logging FailuresMissing audit logs, log injection

For each category, report a status: Vulnerable / Secure / Not applicable / Insufficient context - report clean areas as clean rather than skipping them silently.

Response Format

For Advisory Tasks (Analysis Only)

Threat Summary: [1-2 sentences on overall security posture]

Critical Vulnerabilities (exploit risk: high):

  • [Vuln]: [Location] - [Impact] - [Remediation]

High-Risk Issues (should fix soon):

  • [Issue]: [Location] - [Impact] - [Remediation]

Recommendations (hardening suggestions):

Risk Rating: [CRITICAL / HIGH / MEDIUM / LOW]

<SUMMARY> risk rating + top vulnerabilities + confidence + missing context that would raise it, under ~150 words </SUMMARY>.

For Implementation Tasks (Fix Vulnerabilities)

Summary: What I secured

Vulnerabilities Fixed:

  • [File:line] - [Vulnerability] - [Fix applied]

Files Modified: List with brief description

Verification: How I confirmed the fixes work

Remaining Risks (if any): Issues that need architectural changes or user decision

Show full SKILL.md (186 more words)Show less

Remediation Safety

Before proposing any fix, confirm it does not introduce a new weakness, break existing behavior, or bypass a needed control. Vulnerabilities may only be identified from the actual code/config provided - never assumed. Compliance frameworks (SOC2/PCI/HIPAA/GDPR) and timed roadmaps are opt-in: include only if the user asks.

Modes of Operation

Advisory Mode: Analyze and report. Identify vulnerabilities with remediation guidance.

Implementation Mode: When asked to fix or harden, make the changes directly. Report what you modified.

Security Review Checklist

  • Authentication: How are users identified?
  • Authorization: How are permissions enforced?
  • Input Validation: Is all input sanitized?
  • Output Encoding: Is output properly escaped?
  • Cryptography: Are secrets properly managed?
  • Error Handling: Do errors leak information?
  • Logging: Are security events audited?
  • Dependencies: Are there known vulnerabilities?

When to Invoke Security Analyst

  • Before deploying authentication/authorization changes
  • When handling sensitive data (PII, credentials, payments)
  • After adding new API endpoints
  • When integrating third-party services
  • For periodic security audits
  • When suspicious behavior is detected

When NOT to Invoke Security Analyst

  • Pure UI/styling changes
  • Internal tooling with no external exposure
  • Read-only operations on public data
  • When a quick answer suffices (ask the primary agent)

© antonbabenko, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/security-analyst of antonbabenko/deliberation.

Open the folder on GitHubat commit e5fe399

Compare with similar skills

Security Analyst next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Analyst compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Analyst this skillantonbabenko/deliberation169—~1.1kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
Vuln Hunterdariushoule/x64dbg-skills209—~3.9kAutomated safety check: NotesMIT
Harness Threat Modelruvnet/ruflo74k—~363Automated safety check: NotesMIT
MCP Gateway SecurityHack23/cia239—~2.4kAutomated safety check: PassApache-2.0
Threat Modelruvnet/metaharness690—~637Automated safety check: NotesMIT

Similar skills

  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • Vuln Hunter

    dariushoule/x64dbg-skills

    Hunt for vulnerabilities in a running debuggee by analyzing imports/exports, triaging attack surface, and iteratively testing for bugs with PoC generation.

    209 GitHub stars~3.9k tokensUpdated 6 mo ago
    SecurityAuto-check: notes
  • Enterprise-review-grade threat model from harness threat-model <path.

    74k GitHub stars~363 tokensUpdated today
    SecurityAuto-check: notes
  • MCP gateway security patterns, token management, request validation, and audit logging for MCP communications

    239 GitHub stars~2.4k tokensUpdated yesterday
    SecurityAuto-check passed
  • Threat Model

    ruvnet/metaharness

    MCP threat-model artifact for a scaffolded harness. An agent skill from ruvnet/metaharness.

    690 GitHub stars~637 tokensUpdated yesterday
    SecurityAuto-check: notes
  • Review Maple Security

    MaplePrivacyLabs/Maple

    Review Maple security across authentication, account isolation, local persistence, Tauri IPC and capabilities, OAuth and deep links, the Local OpenAI Proxy, Agent Mode tools and permissions, MCP…

    100 GitHub stars~7.1k tokensUpdated today
    SecurityAuto-check passed

More from antonbabenko/deliberation

All 9 skills in this repo
  • Deliberation

    antonbabenko/deliberation

    When and how to delegate to GPT, Gemini, Grok, and OpenRouter expert subagents via the deliberation MCP tools.

    169 GitHub stars~3.8k tokensUpdated yesterday
    Auto-check passed
  • Architect

    antonbabenko/deliberation

    System design, tradeoffs, and complex technical decisions. An agent skill from antonbabenko/deliberation.

    169 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Code Reviewer

    antonbabenko/deliberation

    Find bugs, security holes, and maintainability issues in a diff or file.

    169 GitHub stars~881 tokensUpdated yesterday
    Auto-check passed
  • Debugger

    antonbabenko/deliberation

    Rank root-cause hypotheses and propose the smallest safe fix.

    169 GitHub stars~554 tokensUpdated yesterday
    Auto-check passed
  • Plan Reviewer

    antonbabenko/deliberation

    Validate that a work plan is executable before work starts. An agent skill from antonbabenko/deliberation.

    169 GitHub stars~931 tokensUpdated yesterday
    Auto-check passed
  • Researcher

    antonbabenko/deliberation

    Research external libraries, APIs, and best practices, with evidence.

    169 GitHub stars~840 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Security Analyst

What does Security Analyst do?

Threat-model and find vulnerabilities, with practical remediation. Security Analyst is an agent skill from antonbabenko/deliberation. Threat-model and find vulnerabilities, with practical remediation.

When should I use Security Analyst?

Security Analyst fits situations like: tasks that involve Threat modeling.

How do I install Security Analyst in Claude Code?

Run `npx skills add antonbabenko/deliberation --skill security-analyst -a claude-code`. Or copy the skill folder (.agents/skills/security-analyst in antonbabenko/deliberation) into .claude/skills/security-analyst in your project. Claude Code loads it when a task matches its description.

How do I install Security Analyst in Codex?

Run `npx skills add antonbabenko/deliberation --skill security-analyst -a codex`. Or copy the skill folder (.agents/skills/security-analyst in antonbabenko/deliberation) into .agents/skills/security-analyst in your project. Codex loads it when a task matches its description.

Can I use Security Analyst in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add antonbabenko/deliberation --skill security-analyst -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-analyst, .gemini/skills/security-analyst, .github/skills/security-analyst and .opencode/skills/security-analyst in your project.

What does Security Analyst need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Analyst is instructions for the agent only.

Does Security Analyst access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Analyst safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Analyst use?

Security Analyst is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Analyst use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Analyst?

Skills that share tags, products or a category with Security Analyst: Forensify (alexgreensh/repo-forensics, 188 stars), Vuln Hunter (dariushoule/x64dbg-skills, 209 stars), Harness Threat Model (ruvnet/ruflo, 74k stars) and MCP Gateway Security (Hack23/cia, 239 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Analyst?

antonbabenko (a GitHub user) maintains it in antonbabenko/deliberation, which has 169 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.

Source: antonbabenko/deliberation on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.