Agent skill

Secskills

by Arenbai in Arenbai/SecSkills

渗透测试实战技能 v1.3.0。覆盖信息收集、全类漏洞发现(注入全家桶/SSRF/文件类/反序列化/SSTI/越权逻辑/CSRF)、漏洞利用、后渗透、免杀全流程。

MITAuto-check: notesSecurity

Install Secskills

skills CLI
$ npx skills add Arenbai/SecSkills --skill secskills -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Arenbai/SecSkills secskills --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secskills
GitHub stars
253
Token cost
~1.8k tokens
SKILL.md length
469 words
Files
43 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

渗透测试实战技能 v1.3.0。覆盖信息收集、全类漏洞发现(注入全家桶/SSRF/文件类/反序列化/SSTI/越权逻辑/CSRF)、漏洞利用、后渗透、免杀全流程。

  • Works in 7 steps: ❗ 授权优先 — 利用步骤输出前确认: 授权渗透 | 本人环境。无授权 →… → ❗ 引用强制 — CVE/Payload 必须引用 references/… → ❗ 风险标注 — 🔴致命/🔴高危/🟡中危/🟢低危 + 利用条件 → …
  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers 触发条件, 行为准则(全程有效), ⚔️ 漏洞过滤体系(输出前逐条过审,任一关卡未过 → 丢弃) and 幻觉防护, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Secskills is an agent skill from Arenbai/SecSkills. 渗透测试实战技能 v1.3.0。覆盖信息收集、全类漏洞发现(注入全家桶/SSRF/文件类/反序列化/SSTI/越权逻辑/CSRF)、漏洞利用、后渗透、免杀全流程。 已剔除无危害噪音项(明文传输/CORS/响应头缺失等),只报告有实际危害证据的漏洞。 当用户给出具体目标 (IP/域名/URL) 且意图是攻击/利用/拿权限时触发。 不触发: 概念讨论、蓝队防御、代码审计、CVE文档查询。

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 43 other files, including reference files (for example `README.md`, `_user_meta.json` and `references/evasion-shellcode.md`).

It sits in Security, covering Web application vulnerabilities and Vulnerability scanning. It works with SQL. The repository describes itself as: 面向 Claude Code 的专业渗透测试技能模块。严格遵循 PTES 标准,覆盖信息收集、漏洞利用、后渗透与免杀规避全阶段。后续不在更新skill,如需使用建议二开。 The licence is MIT.

When your agent uses it

  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Vulnerability scanning

Example prompts

  • “/secskills”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Write, Bash, Grep, WebSearch, WebFetch, Glob, AskUserQuestion

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. ❗ 授权优先 — 利用步骤输出前确认: 授权渗透 | 本人环境。无授权 → 只出分析,不出武器化Payload
  2. ❗ 引用强制 — CVE/Payload 必须引用 references/ 章节或 WebSearch 验证。未覆盖 → ⚠️ UNABLE TO CITE
  3. ❗ 风险标注 — 🔴致命/🔴高危/🟡中危/🟢低危 + 利用条件
  4. ❗ 链式思维 — 优先输出利用链 (A→B→C),非孤立漏洞
  5. ❗ 命令可执行 — 完整可复制,IP/端口用 占位
  6. ❗ 宁可漏报不可误报 — 每条漏洞必须过下方四道关卡,任一不过 → 直接丢弃
  7. ❗ 禁用破坏性操作 — 验证一律用无害语句(SELECT/延时/版本探测/写测试文件),严禁修改、删除数据或删表等写操作;危害证明靠"读到数据",不靠"改掉数据"

What it can do on your machine

Read from SKILL.md and the folder at commit 42b7035. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash
    • Grep
    • WebSearch
    • WebFetch
    • Glob
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secskills loads about 1.8k tokens when it runs, and up to ~65k if it reads all its reference files. Until then it costs about 51 tokens; SKILL.md has 469 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~65k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash, Grep, WebSearch, WebFetch, Glob, AskUserQuestion

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Arenbai/SecSkills at commit 42b7035, republished under its MIT licence (© Arenbai). 469 words, ~1,847 tokens.

Download SKILL.mdSave it as .claude/skills/secskills/SKILL.md (or your agent's skills folder). This skill also uses 42 other files; get the full folder from GitHub.
name
secskills
description
渗透测试实战技能 v1.3.0。覆盖信息收集、全类漏洞发现(注入全家桶/SSRF/文件类/反序列化/SSTI/越权逻辑/CSRF)、漏洞利用、后渗透、免杀全流程。 已剔除无危害噪音项(明文传输/CORS/响应头缺失等),只报告有实际危害证据的漏洞。 当用户给出具体目标 (IP/域名/URL) 且意图是攻击/利用/拿权限时触发。 不触发: 概念讨论、蓝队防御、代码审计、CVE文档查询。
allowed-tools
Read, Write, Bash, Grep, WebSearch, WebFetch, Glob, AskUserQuestion
argument-hint
<target_url_or_ip>

渗透测试实战技能

架构: SKILL.md (本文件) → references/ (按需加载) | 覆盖: 信息收集 → Web漏洞 → 主机 → 后渗透 → 免杀

触发条件

触发(全部满足): ① 意图是攻击/利用/拿权限 ② 给出具体目标 (IP/域名/URL) ③ 涉及漏洞测试/提权/横向/免杀

不触发(任一命中): 概念问答("什么是XSS")| 蓝队/应急/日志分析 | 业务bug修复 | 查CVE(→WebSearch)| AI Prompt注入(→secknowledge-skill)| 白盒审计(→code-audit-skill)

行为: 用户给出具体目标后 → 先弹 AskUserQuestion 选择面板(见「测试确认」),再进入流程。

行为准则(全程有效)

  1. ❗ 授权优先 — 利用步骤输出前确认: 授权渗透 | 本人环境。无授权 → 只出分析,不出武器化Payload
  2. ❗ 引用强制 — CVE/Payload 必须引用 references/ 章节或 WebSearch 验证。未覆盖 → ⚠️ UNABLE TO CITE
  3. ❗ 风险标注 — 🔴致命/🔴高危/🟡中危/🟢低危 + 利用条件
  4. ❗ 链式思维 — 优先输出利用链 (A→B→C),非孤立漏洞
  5. ❗ 命令可执行 — 完整可复制,IP/端口用 <target> 占位
  6. ❗ 宁可漏报不可误报 — 每条漏洞必须过下方四道关卡,任一不过 → 直接丢弃
  7. ❗ 禁用破坏性操作 — 验证一律用无害语句(SELECT/延时/版本探测/写测试文件),严禁修改、删除数据或删表等写操作;危害证明靠"读到数据",不靠"改掉数据"

⚔️ 漏洞过滤体系(输出前逐条过审,任一关卡未过 → 丢弃)

第零关:快速预筛(任意命中 → 丢弃)
判定典型场景
⓪ 扫描器原始告警Burp/AWVS/Nessus 自动报告,未手动验证
① 凭经验推测"可能存在SSRF" — 未实际发请求
② 信息收集中间产物端口开放、版本号、子域名列表 — 是素材不是漏洞
③ 安全加固建议"建议开CSP"、"建议升级TLS" — 不算漏洞
④ 纯静态分析读代码推断,从未请求验证
第一关:自检门(逐项 YES/NO,任一 NO → 丢弃)
[ ] ① 实际发出了验证请求?(命令: ___)
[ ] ② 拿到了真实响应数据?(响应关键内容: ___)
[ ] ③ 造成了实际危害?(读了什么/执行了什么/越权了什么: ___)
    ⚠️ "触发报错"≠"造成危害";"能访问"≠"拿到敏感数据"。③为NO无条件丢弃
[ ] ④ 利用链完整可复现?(入口→___→危害,任一步为推测→NO)
[ ] ⑤ 对照黑名单通过?  [ ] ⑥ 满足对应等级最低准入?
第二关:黑名单(命中即丢弃)
类别永远不报为漏洞
响应头缺 CSP/HSTS/X-Frame-Options 等;Cookie 缺 HttpOnly/Secure/SameSite
信息泄露版本号 Banner;JS/HTML 中的路由/注释;无敏感文件的目录列表;robots.txt;phpinfo(无凭据);错误堆栈(不含密码/Token/密钥)
认证会话用户名枚举(响应/时间差异);密码策略不严格(无爆破成功);autocomplete 开启;默认凭据尝试失败;无验证码(无爆破成功);401/403 响应
SSL/网络明文传输/HTTP未跳转HTTPS;自签名证书;弱加密套件/TLS版本低;OPTIONS/TRACE 开启;后台存在但进不去
版本问题组件版本过旧/EOL 但无对应可验证漏洞(版本老 ≠ 有漏洞,必须落到具体 PoC 并实际打出危害)
未验证利用SQL报错但提取不到数据;上传成功但服务器不解析;无回显反射XSS;SSRF内网可达但没拿到数据;任意文件读只读到公开文件
其他纯功能bug;短信轰炸(无资费损失证明);同系统同类型>3个(降级合并);API无频率限制;利用条件极苛刻(物理接触/猜64位随机数)

CORS/CRLF/Host头/缓存投毒/请求走私/GraphQL内省/开放重定向 → 见 references/web-low-value.md,默认不报,除非满足该文件的报告门槛(完整利用链+实际危害)。

第三关:严重等级准入(不满足 → 降级重审,再降到底则丢弃)
等级最低准入(满足至少一项)
🔴致命获取系统权限(RCE/WebShell)|核心DB拖库(≥3类敏感字段)|核心认证绕过直进后台
🔴高危任意密码重置/登录|重要系统SQL注入(有回显)|SSRF拿到内网凭证/云元数据|任意文件读到配置/密钥|越权增删改查敏感信息|本地提权完整链
🟡中危存储XSS(能窃Cookie)|敏感操作CSRF|非核心SQL注入(有回显)|任意文件操作有实际影响|普通越权|弱口令(有登录成功证据)|子域名接管成功
🟢低危反射XSS(有弹窗证据)|有限越权|需特殊条件的信息泄露(SVN等)
高频误判速查(校准用)
你看到的实际判断
"用户名不存在"vs"密码错误"响应不同不是漏洞,UX设计
/admin 返回302跳登录已正确保护,不算未授权
上传.php返回200服务器必须实际解析执行才算
内网IP:端口有HTTP响应必须通过SSRF拿到敏感数据/云凭证才算
4位数字验证码可识别必须实际爆破成功才算

幻觉防护

内容正确做法禁止
CVE编号WebSearch → WebFetch PoC → 实际验证凭记忆编造编号/版本范围,看到版本号直接报CVE
Payload引用 references/ 或搜索验证凭记忆写
无匹配⚠️ UNABLE TO ASSESS: 未覆盖,建议[行动]凭经验断言
黑名单命中跳过包装成"低危"输出

标注: [引用:file:section] · ⚠️ 通用知识 · 💡 方法论推理

🎯 测试确认(用户给出目标时,先弹 AskUserQuestion)

一次性弹出 3 个问题,方向键选择、Enter 确认,完成后立即进入 Step 1:

  1. 授权级别: 🔴 授权渗透(完整利用链)/ 🟡 灰盒(有测试账号)/ 🟢 黑盒(无凭证)/ ⚪ 本人环境(靶场/CTF)
  2. 测试深度: 标准测试(推荐,全量检测+验证)/ 快速扫描 / 深度测试(含横向后渗透)/ 仅信息收集
  3. 测试范围: 仅主目标 / 含子域名 / 含关联资产(C段/同ASN)

有测试账号 → 用户通过"其他"填写。

工作流程

两阶段: [攻击] Step 1+2 → [利用] Step 3+4。利用阶段只能引用攻击阶段已加载的文件,禁止跨阶段新增 reference。

🔍 攻击阶段

Step 1: 信息收集 + 攻击面识别

  • 分类目标 (Web/主机/内网) → 匹配导航索引 → 攻击面: 端口/服务/Web入口/认证/API/子域名
  • 指纹组件+版本 → 标记为「历史漏洞候选」,Step 2a 优先处理
  • ✅ Step1: 类型={X}, 攻击面={N}项, 历史漏洞候选={P}个

Step 2a: 历史漏洞匹配(⭐ 最高投入产出比,优先于通用检测)

  1. 提取指纹组件(有/无版本号都要)→ 并行搜索: "[组件] [版本] CVE exploit" / "[组件] RCE 漏洞 PoC" / site:exploit-db.com [组件] / site:github.com [组件] exploit
  2. 有公开 PoC → WebFetch 加载 → 对目标实际验证;无 PoC → 跳过,不猜测
  3. 无版本号组件(Shiro/WebLogic 等)→ 用特征检测方法直接验证,不需精确版本
  4. 同样过全部自检门 — 版本匹配 ≠ 漏洞存在;验证失败记录原因,不进报告
  5. 命中致命/高危 → 立即停止深入,先确认记录

Step 2b: 通用漏洞检测

  • 第一梯队必测 → 第二梯队验证后报 → 低价值类查 web-low-value.md 后默认跳过
  • 仅输出已过自检门的确认漏洞(等级+前提+检测命令+响应证据),禁止输出"漏洞假设"列表
  • ✅ Step2: 历史漏洞={X}条(验证{Y}/排除{Z}), 通用确认={K}条, 过滤噪音={N}条
Show full SKILL.md (175 more words)Show less
⚔️ 利用阶段

Step 3: 武器化 + 利用链 + 报告

  • 从已加载文件取利用 Payload → 优先组合利用链 (A→B→C→RCE),每条引用具体 section
  • 每条漏洞/链必须「能打出危害+有链+有证据」,否则跳过 → 按下方模板生成报告(含修复方案)

Step 4: 后渗透(按需) — 提权/横向/凭据窃取/域渗透/持久化/痕迹清理

报告输出格式(强制)

仅两部分。无确认漏洞时只输出:✅ 测试完成,未发现可利用漏洞。 禁止输出: "可能存在"/"疑似"/"建议检查"/安全配置建议/扫描器原始告警。

### 🔴/🟡/🟢 [漏洞名称] — [目标URL/端点]
**危害**: [一句话,实际造成的危害,非推测]
**证据**: 请求: [完整命令] | 响应: [脱敏关键内容]
**利用链**: [入口] → [步骤] → [危害]
**自检清单**: ①请求YES ②响应YES ③危害YES ④链完整YES ⑤黑名单通过YES ⑥等级准入YES
**修复方案**: [具体可操作,非泛泛而谈]

测试摘要: 目标/时间/确认漏洞N条(分级计数)/已排除噪音M条

场景导航索引

信息收集
场景reference
端口扫描+服务识别references/info-port-scan.md
子域名枚举+接管检测references/info-subdomain.md
目录/文件爆破references/info-dir-brute.md
Web指纹/OSINTreferences/info-fingerprint.md / references/info-osint.md
Web 漏洞 — 检测

🔴第一梯队必测必报 | 🟡第二梯队有实际危害才报 | ⚫低价值类默认不报

梯队场景reference关键检测
🔴SQL 注入references/web-sqli.md闭合/报错/延时/Union/读写文件
🔴NoSQL/LDAP/XPath/EL 注入references/web-injection-ext.md操作符绕过/盲注提取
🔴命令执行 RCEreferences/web-rce.md拼接符/回显/不出网
🔴SSRFreferences/web-ssrf.md内网探测/云元数据/Gopher
🔴文件上传references/web-upload.md后缀/内容/条件竞争
🔴文件包含/路径遍历references/web-lfi-path.md伪协议/日志投毒/截断
🔴XXEreferences/web-xxe.md文件读取/Blind/外带DTD
🔴反序列化references/web-deser.mdPHP/Java/Python gadget
🔴SSTI 模板注入references/web-ssti.mdJinja2/Twig/FreeMarker
🔴越权/逻辑/JWT/CSRFreferences/web-auth-logic.mdIDOR/支付/密码重置/JWT攻击/会话/CSRF
🟡XSSreferences/web-xss.md反射/存储/DOM(报告门槛见自检门)
🟡目录遍历/敏感文件references/web-dir-traversal.md仅读到非公开敏感文件才报
🟡竞争条件references/web-race-condition.md仅成功绕过业务限制才报
⚫CORS/CRLF/Host头/缓存投毒/走私/GraphQL/明文传输/开放重定向references/web-low-value.md默认跳过,门槛见文件
Web 漏洞 — 利用阶段
场景reference
WAF/IDS 绕过(利用阶段通用)references/web-waf-bypass.md

各漏洞利用 Payload 在对应 reference 的「利用」section 中。

主机与后渗透
场景reference
密码爆破references/host-brute.md
Linux 提权references/post-linux-privesc.md
Windows 提权references/post-win-privesc.md
凭据窃取+横向references/post-credentials.md
域渗透references/post-ad.md
免杀: Shellcode混淆+加载器references/evasion-shellcode.md

零结果处理

情况动作
目标不可达❌ UNABLE TO ASSESS: 目标无响应
Reference 未覆盖⚠️ UNABLE TO CITE: 建议 WebSearch [关键词]
无授权仅检测方法,不出武器化链
WAF拦截加载 web-waf-bypass.md
利用失败检查版本→防护→替代Payload

路由边界

诉求路由
渗透/红队/提权本 Skill
AI/LLM 安全测试secknowledge-skill
白盒代码审计code-audit-skill
查CVE/文档WebSearch

v1.3.0 | 26个reference | 变化: 6个低价值文件合并为 web-low-value.md;新增 web-injection-ext.md(NoSQL/LDAP/XPath/EL);子域名接管、JWT算法攻击入库;删除 tools- 工具速查(665行);补 CSRF/CSWSH、宽字节注入;WAF 绕过闭环(sqli/xss → web-waf-bypass.md 分层流程);SKILL.md 428→~230行*

© Arenbai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 42 other files (references) in the repository root of Arenbai/SecSkills.

  • SKILL.md
  • LICENSE
  • README.md
  • _user_meta.json
  • references/evasion-shellcode.md
  • references/host-brute.md
  • references/info-dir-brute.md
  • references/info-fingerprint.md
  • references/info-osint.md
  • references/info-port-scan.md
  • references/info-subdomain.md
  • references/post-ad.md
  • references/post-credentials.md
  • references/post-linux-privesc.md
  • references/post-win-privesc.md
  • references/tools-fuzz.md
  • references/tools-hydra.md
  • references/tools-impacket.md
  • references/tools-msf.md
  • references/tools-nmap.md
  • … and 23 more

Open the folder on GitHubat commit 42b7035

Compare with similar skills

Secskills next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secskills compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secskills this skillArenbai/SecSkills253—~1.8kAutomated safety check: NotesMIT
Secknowledge SkillPa55w0rd/secknowledge-skill425—~2.7kAutomated safety check: PassNone
Security AuditAedelon/claude-code-blueprint120—~1.6kAutomated safety check: NotesCustom licence
Security Auditstaruhub/ClaudeSkills728—~1.3kAutomated safety check: NotesMIT
Golang Securityunxed/f42432 repos~3.6kAutomated safety check: PassMIT
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0

Similar skills

  • Secknowledge Skill

    Pa55w0rd/secknowledge-skill

    Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

    425 GitHub stars~2.7k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Security Audit

    Aedelon/claude-code-blueprint

    Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults.

    120 GitHub stars~1.6k tokensUpdated 7 mo ago
    SecurityAuto-check: notes
  • Security Audit

    staruhub/ClaudeSkills

    全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -…

    728 GitHub stars~1.3k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

    243 GitHub starsUsed in 2 repos~3.6k tokens
    SecurityAuto-check passed
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed

Works with

Categories

Questions about Secskills

What does Secskills do?

渗透测试实战技能 v1.3.0。覆盖信息收集、全类漏洞发现(注入全家桶/SSRF/文件类/反序列化/SSTI/越权逻辑/CSRF)、漏洞利用、后渗透、免杀全流程。. Secskills is an agent skill from Arenbai/SecSkills.

When should I use Secskills?

Secskills fits situations like: tasks that involve Web application vulnerabilities; tasks that involve Vulnerability scanning.

How do I install Secskills in Claude Code?

Run `npx skills add Arenbai/SecSkills --skill secskills -a claude-code`. Or copy the skill folder (the Arenbai/SecSkills repository) into .claude/skills/secskills in your project. Claude Code loads it when a task matches its description.

How do I install Secskills in Codex?

Run `npx skills add Arenbai/SecSkills --skill secskills -a codex`. Or copy the skill folder (the Arenbai/SecSkills repository) into .agents/skills/secskills in your project. Codex loads it when a task matches its description.

Can I use Secskills in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Arenbai/SecSkills --skill secskills -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secskills, .gemini/skills/secskills, .github/skills/secskills and .opencode/skills/secskills in your project.

What does Secskills need to run?

SKILL.md names no scripts, command-line tools or credentials: Secskills is instructions for the agent only. Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Bash, Grep, WebSearch, WebFetch, Glob, AskUserQuestion.

Does Secskills access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Secskills safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Secskills use?

Secskills is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secskills use?

About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 63k tokens, read only when the agent opens those files.

What are the alternatives to Secskills?

Skills that share tags, products or a category with Secskills: Secknowledge Skill (Pa55w0rd/secknowledge-skill, 425 stars), Security Audit (Aedelon/claude-code-blueprint, 120 stars), Security Audit (staruhub/ClaudeSkills, 728 stars) and Golang Security (unxed/f4, 243 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secskills?

Arenbai (a GitHub user) maintains it in Arenbai/SecSkills, which has 253 GitHub stars. The repository was last updated on September 29, 2026.

Source: Arenbai/SecSkills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.