Agent skill

Security Sensitive Path Instrumenter

by ArabelaTso in ArabelaTso/Skills-4-SE

Instruments authentication, authorization, and input-handling code paths to monitor security-relevant events and states at runtime.

Apache-2.0Auto-check passedBackend & APIs

Install Security Sensitive Path Instrumenter

skills CLI
$ npx skills add ArabelaTso/Skills-4-SE --skill security-sensitive-path-instrumenter -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArabelaTso/Skills-4-SE security-sensitive-path-instrumenter --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-sensitive-path-instrumenter .claude/skills/security-sensitive-path-instrumenter && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-sensitive-path-instrumenter
GitHub stars
253
Token cost
~1.1k tokens
SKILL.md length
292 words
Files
5 (incl. scripts, references)
Skills in repo
150
Repo updated
First seen
Licence
Apache-2.0

At a glance

Instruments authentication, authorization, and input-handling code paths to monitor security-relevant events and states at runtime.

  • Works in 7 steps: Identify security-sensitive code paths -… → Determine event types - Classify the… → Review best practices - Check… → …
  • Developers need to add security monitoring and logging to their code
  • SKILL.md covers Workflow, Quick Reference, Helper Script and Important Reminders
  • Runs Python scripts from its folder; calls python

What it does

Security Sensitive Path Instrumenter is an agent skill from ArabelaTso/Skills-4-SE. Instruments authentication, authorization, and input-handling code paths to monitor security-relevant events and states at runtime. Use this skill when developers need to add security monitoring and logging to their code, including tracking authentication attempts (login/logout), authorization decisions (access control checks), input validation failures, session management events, and other security-critical operations. Supports Python, JavaScript/TypeScript, and Java with structured logging patterns. Triggers…

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/best_practices.md`, `references/language_patterns.md` and `references/security_events.md`).

It sits in Backend & APIs, covering Authorization and RBAC, Observability and Authentication. It works with Java, JavaScript, Python and TypeScript. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.

When your agent uses it

  • Developers need to add security monitoring and logging to their code
  • Including tracking authentication attempts (login/logout)
  • Authorization decisions (access control checks)
  • Input validation failures

Example prompts

  • “Use the security-sensitive-path-instrumenter skill to instrument authentication, authorization, and input-handling code paths to monitor…”
  • “/security-sensitive-path-instrumenter”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Identify security-sensitive code paths - Locate authentication, authorization, input validation, or session management code that needs…
  2. Determine event types - Classify the security events to monitor (see security_events.md for taxonomy)
  3. Review best practices - Check best_practices.md for what to log and what to avoid (never log passwords, secrets, or sensitive PII)
  4. Select language patterns - Use language_patterns.md for language-specific instrumentation code (Python, JavaScript/TypeScript, Java)
  5. Add instrumentation - Insert structured logging calls at key decision points
  6. Include context - Log relevant data points
  7. Verify instrumentation - Ensure

What it can do on your machine

Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Sensitive Path Instrumenter loads about 1.1k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 186 tokens; SKILL.md has 292 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~186
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 292 words, ~1,102 tokens.

Download SKILL.mdSave it as .claude/skills/security-sensitive-path-instrumenter/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
security-sensitive-path-instrumenter
description
Instruments authentication, authorization, and input-handling code paths to monitor security-relevant events and states at runtime. Use this skill when developers need to add security monitoring and logging to their code, including tracking authentication attempts (login/logout), authorization decisions (access control checks), input validation failures, session management events, and other security-critical operations. Supports Python, JavaScript/TypeScript, and Java with structured logging patterns. Triggers when users ask to add security instrumentation, monitor security events, log authentication/authorization, track security-sensitive operations, or add security observability to their codebase.

Security-Sensitive Path Instrumenter

Add structured logging instrumentation to security-critical code paths for runtime monitoring of authentication, authorization, input validation, session management, and other security-relevant events.

Workflow

  1. Identify security-sensitive code paths - Locate authentication, authorization, input validation, or session management code that needs instrumentation

  2. Determine event types - Classify the security events to monitor (see security_events.md for taxonomy)

  3. Review best practices - Check best_practices.md for what to log and what to avoid (never log passwords, secrets, or sensitive PII)

  4. Select language patterns - Use language_patterns.md for language-specific instrumentation code (Python, JavaScript/TypeScript, Java)

  5. Add instrumentation - Insert structured logging calls at key decision points:

    • Before and after authentication attempts
    • At authorization check points
    • When validation fails
    • During session lifecycle events
  6. Include context - Log relevant data points:

    • User identifier
    • Timestamp (automatically added)
    • IP address
    • Resource accessed
    • Success/failure status
    • Failure reasons
  7. Verify instrumentation - Ensure:

    • No sensitive data (passwords, tokens, secrets) is logged
    • Structured format (JSON) is used for machine parsing
    • Appropriate log levels are set
    • Performance impact is minimal

Quick Reference

Event Categories
  • Authentication: Login attempts, logout, password changes, MFA, token validation
  • Authorization: Access control decisions, permission checks, RBAC evaluations
  • Input Validation: Validation failures, injection detection, format violations
  • Session Management: Session creation/expiration, IP changes, hijacking detection
  • Sensitive Data Access: PII access, financial data, encryption key usage
  • Configuration Changes: Permission changes, role assignments, security policy updates
Common Patterns

Authentication (Python/Flask):

python
log_security_event(
    event_type='authentication_attempt',
    username=username,
    ip_address=request.remote_addr
)

Authorization (JavaScript/Express):

typescript
logSecurityEvent('authorization_check', {
  user_id: user.id,
  resource: resourceId,
  permission: requiredPermission,
  decision: hasPermission ? 'granted' : 'denied'
});

Validation (Java/Spring):

java
Map<String, Object> data = new HashMap<>();
data.put("user_id", user.getId());
data.put("errors", validationErrors);
SecurityLogger.logSecurityEvent("validation_failure", data);

Helper Script

Use scripts/generate_instrumentation.py to generate code snippets:

bash
# Generate Python authentication instrumentation
python scripts/generate_instrumentation.py python authentication

# Generate JavaScript authorization instrumentation
python scripts/generate_instrumentation.py javascript authorization

# Generate Java validation instrumentation
python scripts/generate_instrumentation.py java validation

Important Reminders

Never log:

  • Passwords (plaintext or hashed)
  • API keys or secrets
  • Full session tokens
  • Credit card numbers
  • Social Security numbers
  • Encryption keys

Always log:

  • Event type and timestamp
  • User identifier (when available)
  • Success/failure status
  • IP address (consider GDPR)
  • Resource accessed
  • Action performed

Use structured logging (JSON format) for machine parsing and analysis.

© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/security-sensitive-path-instrumenter of ArabelaTso/Skills-4-SE.

  • SKILL.md
  • references/best_practices.md
  • references/language_patterns.md
  • references/security_events.md
  • scripts/generate_instrumentation.py

Open the folder on GitHubat commit 4f38503

Compare with similar skills

Security Sensitive Path Instrumenter next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Sensitive Path Instrumenter compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Sensitive Path Instrumenter this skillArabelaTso/Skills-4-SE253—~1.1kAutomated safety check: PassApache-2.0
Gemini Live API Devgoogle-gemini/gemini-skills4.3k—~4.6kAutomated safety check: PassApache-2.0
Gemini Live API DevJetBrains/skills364—~2.6kAutomated safety check: PassNone
Logfire Instrumentationbasicmachines-co/basic-memory4.1k—~2.3kAutomated safety check: PassAGPL-3.0
Logfire Instrumentationpydantic/skills140—~6.1kAutomated safety check: PassMIT
Copilot SDKintellectronica/agent-skills295—~3.2kAutomated safety check: PassCC0-1.0

Similar skills

  • Gemini Live API Dev

    google-gemini/gemini-skills

    Official

    A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.

    4.3k GitHub stars~4.6k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Gemini Live API Dev

    JetBrains/skills

    Official

    A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API.

    364 GitHub stars~2.6k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Logfire Instrumentation

    basicmachines-co/basic-memory

    Adds Pydantic Logfire tracing, logging and metrics to Python, JavaScript or TypeScript and Rust projects, with the correct setup order and library extras.

    4.1k GitHub stars~2.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Add Pydantic Logfire observability to application code — traces, logs, metrics, and AI/agent spans.

    140 GitHub stars~6.1k tokensUpdated 7 days ago
    AI & LLM EngineeringAuto-check passed
  • Copilot SDK

    intellectronica/agent-skills

    This skill helps with GitHub Copilot SDK work across Node.js/TypeScript, Python, Go, .NET, and Java.

    295 GitHub stars~3.2k tokensUpdated 5 mo ago
    Agent WorkflowsAuto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated yesterday
    SecurityAuto-check: notes

More from ArabelaTso/Skills-4-SE

All 150 skills in this repo
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Metamorphic Test Generator

    ArabelaTso/Skills-4-SE

    Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.

    253 GitHub stars~798 tokensUpdated 1 mo ago
    Auto-check passed
  • Reproduction Trace Instrumenter

    ArabelaTso/Skills-4-SE

    Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.

    253 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spring Mvc To Boot Migrator

    ArabelaTso/Skills-4-SE

    Automatically migrate Spring MVC applications to Spring Boot.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • State Snapshot Instrumenter

    ArabelaTso/Skills-4-SE

    Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Security Sensitive Path Instrumenter

What does Security Sensitive Path Instrumenter do?

Instruments authentication, authorization, and input-handling code paths to monitor security-relevant events and states at runtime. Security Sensitive Path Instrumenter is an agent skill from ArabelaTso/Skills-4-SE. Instruments authentication, authorization, and input-handling code paths to monitor security-relevant events and states at runtime.

When should I use Security Sensitive Path Instrumenter?

Security Sensitive Path Instrumenter fits situations like: developers need to add security monitoring and logging to their code; including tracking authentication attempts (login/logout); authorization decisions (access control checks); input validation failures.

How do I install Security Sensitive Path Instrumenter in Claude Code?

Run `npx skills add ArabelaTso/Skills-4-SE --skill security-sensitive-path-instrumenter -a claude-code`. Or copy the skill folder (skills/security-sensitive-path-instrumenter in ArabelaTso/Skills-4-SE) into .claude/skills/security-sensitive-path-instrumenter in your project. Claude Code loads it when a task matches its description.

How do I install Security Sensitive Path Instrumenter in Codex?

Run `npx skills add ArabelaTso/Skills-4-SE --skill security-sensitive-path-instrumenter -a codex`. Or copy the skill folder (skills/security-sensitive-path-instrumenter in ArabelaTso/Skills-4-SE) into .agents/skills/security-sensitive-path-instrumenter in your project. Codex loads it when a task matches its description.

Can I use Security Sensitive Path Instrumenter in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill security-sensitive-path-instrumenter -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-sensitive-path-instrumenter, .gemini/skills/security-sensitive-path-instrumenter, .github/skills/security-sensitive-path-instrumenter and .opencode/skills/security-sensitive-path-instrumenter in your project.

What does Security Sensitive Path Instrumenter need to run?

Going by SKILL.md and its folder, Security Sensitive Path Instrumenter needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Security Sensitive Path Instrumenter access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Sensitive Path Instrumenter safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Sensitive Path Instrumenter use?

Security Sensitive Path Instrumenter is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Sensitive Path Instrumenter use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.1k tokens, read only when the agent opens those files.

What are the alternatives to Security Sensitive Path Instrumenter?

Skills that share tags, products or a category with Security Sensitive Path Instrumenter: Gemini Live API Dev (google-gemini/gemini-skills, 4.3k stars), Gemini Live API Dev (JetBrains/skills, 364 stars), Logfire Instrumentation (basicmachines-co/basic-memory, 4.1k stars) and Logfire Instrumentation (pydantic/skills, 140 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Sensitive Path Instrumenter?

ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on August 21, 2026.

Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.