Forensify
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
Threat-model and find vulnerabilities, with practical remediation.
$ npx skills add antonbabenko/deliberation --skill security-analyst -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install antonbabenko/deliberation security-analyst --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/antonbabenko/deliberation.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-analyst .claude/skills/security-analyst && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-analyst" agent skill from https://github.com/antonbabenko/deliberation/tree/master/.agents/skills/security-analyst into .claude/skills/security-analyst/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-analyst", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/antonbabenko/deliberation/tree/master/.agents/skills/security-analystType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add antonbabenko/deliberation --skill security-analyst -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install antonbabenko/deliberation security-analyst --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/antonbabenko/deliberation.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/security-analyst .agents/skills/security-analyst && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-analyst" agent skill from https://github.com/antonbabenko/deliberation/tree/master/.agents/skills/security-analyst into .agents/skills/security-analyst/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-analyst", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add antonbabenko/deliberation --skill security-analyst -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install antonbabenko/deliberation security-analyst --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/antonbabenko/deliberation.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/security-analyst .cursor/skills/security-analyst && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-analyst" agent skill from https://github.com/antonbabenko/deliberation/tree/master/.agents/skills/security-analyst into .cursor/skills/security-analyst/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-analyst", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/antonbabenko/deliberation.git --path .agents/skills/security-analyst--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add antonbabenko/deliberation --skill security-analyst -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install antonbabenko/deliberation security-analyst --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/antonbabenko/deliberation.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/security-analyst .gemini/skills/security-analyst && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-analyst" agent skill from https://github.com/antonbabenko/deliberation/tree/master/.agents/skills/security-analyst into .gemini/skills/security-analyst/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-analyst", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install antonbabenko/deliberation security-analystInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add antonbabenko/deliberation --skill security-analyst -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/antonbabenko/deliberation.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/security-analyst .github/skills/security-analyst && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-analyst" agent skill from https://github.com/antonbabenko/deliberation/tree/master/.agents/skills/security-analyst into .github/skills/security-analyst/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-analyst", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add antonbabenko/deliberation --skill security-analyst -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install antonbabenko/deliberation security-analyst --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/antonbabenko/deliberation.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/security-analyst .opencode/skills/security-analyst && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-analyst" agent skill from https://github.com/antonbabenko/deliberation/tree/master/.agents/skills/security-analyst into .opencode/skills/security-analyst/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-analyst", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-analystThreat-model and find vulnerabilities, with practical remediation.
Security Analyst is an agent skill from antonbabenko/deliberation. Threat-model and find vulnerabilities, with practical remediation.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Threat modeling. It works with Model Context Protocol. The repository describes itself as: Ask Codex, Gemini, Grok, and 400+ OpenRouter models (Qwen, Kimi, DeepSeek) for second opinions or arbiter-mediated consensus. One MCP server for Claude Code, Codex, Cursor, Kiro… The licence is MIT.
Read from SKILL.md and the folder at commit e5fe399. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Analyst loads about 1.1k tokens when it runs. Until then it costs about 21 tokens; SKILL.md has 477 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from antonbabenko/deliberation at commit e5fe399, republished under its MIT licence (© antonbabenko). 477 words, ~1,080 tokens.
.claude/skills/security-analyst/SKILL.md (or your agent's skills folder).<!-- GENERATED by scripts/sync-hosts.js - edit the source under prompts/, AGENTS.md, or examples/, then regenerate. -->
You are a security engineer specializing in application security, threat modeling, and vulnerability assessment.
You analyze code and systems with an attacker's mindset. Your job is to find vulnerabilities before attackers do, and to provide practical remediation - not theoretical concerns.
For any system or feature, identify:
Assets: What's valuable? (User data, credentials, business logic)
Threat Actors: Who might attack? (External attackers, malicious insiders, automated bots)
Attack Surface: What's exposed? (APIs, inputs, authentication boundaries)
Attack Vectors: How could they get in? (Injection, broken auth, misconfig)
| Category | What to Look For |
|---|---|
| Injection | SQL, NoSQL, OS command, LDAP injection |
| Broken Auth | Weak passwords, session issues, credential exposure |
| Sensitive Data | Unencrypted storage/transit, excessive data exposure |
| XXE | XML external entity processing |
| Broken Access Control | Missing authz checks, IDOR, privilege escalation |
| Misconfig | Default creds, verbose errors, unnecessary features |
| XSS | Reflected, stored, DOM-based cross-site scripting |
| Insecure Deserialization | Untrusted data deserialization |
| Vulnerable Components | Known CVEs in dependencies |
| Logging Failures | Missing audit logs, log injection |
For each category, report a status: Vulnerable / Secure / Not applicable / Insufficient context - report clean areas as clean rather than skipping them silently.
Threat Summary: [1-2 sentences on overall security posture]
Critical Vulnerabilities (exploit risk: high):
High-Risk Issues (should fix soon):
Recommendations (hardening suggestions):
Risk Rating: [CRITICAL / HIGH / MEDIUM / LOW]
<SUMMARY> risk rating + top vulnerabilities + confidence + missing context that would raise it, under ~150 words </SUMMARY>.
Summary: What I secured
Vulnerabilities Fixed:
Files Modified: List with brief description
Verification: How I confirmed the fixes work
Remaining Risks (if any): Issues that need architectural changes or user decision
Before proposing any fix, confirm it does not introduce a new weakness, break existing behavior, or bypass a needed control. Vulnerabilities may only be identified from the actual code/config provided - never assumed. Compliance frameworks (SOC2/PCI/HIPAA/GDPR) and timed roadmaps are opt-in: include only if the user asks.
Advisory Mode: Analyze and report. Identify vulnerabilities with remediation guidance.
Implementation Mode: When asked to fix or harden, make the changes directly. Report what you modified.
© antonbabenko, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/security-analyst of antonbabenko/deliberation.
Open the folder on GitHubat commit e5fe399
Security Analyst next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Analyst this skillantonbabenko/deliberation | 169 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Forensifyalexgreensh/repo-forensics | 188 | — | ~2.5k | Automated safety check: Notes | Custom licence | |
| Vuln Hunterdariushoule/x64dbg-skills | 209 | — | ~3.9k | Automated safety check: Notes | MIT | |
| Harness Threat Modelruvnet/ruflo | 74k | — | ~363 | Automated safety check: Notes | MIT | |
| MCP Gateway SecurityHack23/cia | 239 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Threat Modelruvnet/metaharness | 690 | — | ~637 | Automated safety check: Notes | MIT |
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
dariushoule/x64dbg-skills
Hunt for vulnerabilities in a running debuggee by analyzing imports/exports, triaging attack surface, and iteratively testing for bugs with PoC generation.
ruvnet/ruflo
Enterprise-review-grade threat model from harness threat-model <path.
Hack23/cia
MCP gateway security patterns, token management, request validation, and audit logging for MCP communications
ruvnet/metaharness
MCP threat-model artifact for a scaffolded harness. An agent skill from ruvnet/metaharness.
MaplePrivacyLabs/Maple
Review Maple security across authentication, account isolation, local persistence, Tauri IPC and capabilities, OAuth and deep links, the Local OpenAI Proxy, Agent Mode tools and permissions, MCP…
antonbabenko/deliberation
When and how to delegate to GPT, Gemini, Grok, and OpenRouter expert subagents via the deliberation MCP tools.
antonbabenko/deliberation
System design, tradeoffs, and complex technical decisions. An agent skill from antonbabenko/deliberation.
antonbabenko/deliberation
Find bugs, security holes, and maintainability issues in a diff or file.
antonbabenko/deliberation
Rank root-cause hypotheses and propose the smallest safe fix.
antonbabenko/deliberation
Validate that a work plan is executable before work starts. An agent skill from antonbabenko/deliberation.
antonbabenko/deliberation
Research external libraries, APIs, and best practices, with evidence.
Works with
Categories
Threat-model and find vulnerabilities, with practical remediation. Security Analyst is an agent skill from antonbabenko/deliberation. Threat-model and find vulnerabilities, with practical remediation.
Security Analyst fits situations like: tasks that involve Threat modeling.
Run `npx skills add antonbabenko/deliberation --skill security-analyst -a claude-code`. Or copy the skill folder (.agents/skills/security-analyst in antonbabenko/deliberation) into .claude/skills/security-analyst in your project. Claude Code loads it when a task matches its description.
Run `npx skills add antonbabenko/deliberation --skill security-analyst -a codex`. Or copy the skill folder (.agents/skills/security-analyst in antonbabenko/deliberation) into .agents/skills/security-analyst in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add antonbabenko/deliberation --skill security-analyst -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-analyst, .gemini/skills/security-analyst, .github/skills/security-analyst and .opencode/skills/security-analyst in your project.
SKILL.md names no scripts, command-line tools or credentials: Security Analyst is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Analyst is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Analyst: Forensify (alexgreensh/repo-forensics, 188 stars), Vuln Hunter (dariushoule/x64dbg-skills, 209 stars), Harness Threat Model (ruvnet/ruflo, 74k stars) and MCP Gateway Security (Hack23/cia, 239 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
antonbabenko (a GitHub user) maintains it in antonbabenko/deliberation, which has 169 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.
Source: antonbabenko/deliberation on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.