Agent skill

Post Dev Security Review

by Bald0Wang in Bald0Wang/DeepSeek-Oracle

Perform post-implementation security review on recent code changes and produce prioritized hardening recommendations with file evidence and fix guidance.

No licenceAuto-check passedSecurity

Install Post Dev Security Review

skills CLI
$ npx skills add Bald0Wang/DeepSeek-Oracle --skill post-dev-security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Bald0Wang/DeepSeek-Oracle post-dev-security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Bald0Wang/DeepSeek-Oracle.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/post-dev-security-review .claude/skills/post-dev-security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
post-dev-security-review
GitHub stars
187
Token cost
~694 tokens
SKILL.md length
293 words
Files
3 (incl. references)
Skills in repo
10
Repo updated
First seen
Licence
None found

At a glance

Perform post-implementation security review on recent code changes and produce prioritized hardening recommendations with file evidence and fix guidance.

  • A development task is completed
  • SKILL.md covers Overview, Review Workflow, Output Contract and Quality Rules, plus 1 more section
  • Calls git
  • Before merge/release

What it does

Post Dev Security Review is an agent skill from Bald0Wang/DeepSeek-Oracle. Perform post-implementation security review on recent code changes and produce prioritized hardening recommendations with file evidence and fix guidance. Use when a development task is completed, before merge/release, or when users ask for security checks, vulnerability analysis, or security optimization suggestions for backend/frontend/API/worker code.

Its SKILL.md is about 690 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `agents/openai.yaml` and `references/deepseek-oracle-security-checklist.md`).

It sits in Security, covering Security review. The repository describes itself as: 基于紫微斗数的命理分析系统,使用deepseek等大语言模型进行解读。目前是情人节版本,支持姻缘推算。 在线体验:http://deepseek-oracle.rebornai.cn/oracle.

When your agent uses it

  • A development task is completed
  • Before merge/release
  • Users ask for security checks
  • Vulnerability analysis

Example prompts

  • “/post-dev-security-review”

What it can do on your machine

Read from SKILL.md and the folder at commit b7199cf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Post Dev Security Review loads about 694 tokens when it runs, and up to ~1.5k if it reads all its reference files. Until then it costs about 95 tokens; SKILL.md has 293 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~694
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 293 words (~694 tokens).

“Review changed code after implementation and output actionable security improvements, not generic advice. Focus on real attack paths, impact, and concrete mitigation steps tied to specific files.”

— opening of SKILL.md by Bald0Wang
name
post-dev-security-review

Read the full SKILL.md on GitHub

Files

SKILL.md and 2 other files (references) in .codex/skills/post-dev-security-review of Bald0Wang/DeepSeek-Oracle.

  • SKILL.md
  • agents/openai.yaml
  • references/deepseek-oracle-security-checklist.md

Open the folder on GitHubat commit b7199cf

Compare with similar skills

Post Dev Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Post Dev Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Post Dev Security Review this skillBald0Wang/DeepSeek-Oracle187—~694Automated safety check: PassNone
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Agentlas Security Scanagentlas-ai/Agentlas-OS1.6k1 repos~822Automated safety check: PassApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Agentlas Security Scan

    agentlas-ai/Agentlas-OS

    A skill your agent uses when an agent folder must pass the Agentlas Cloud 2-stage security scan (static rules + BYOK LLM judgment) before private sync or public publish, or when asked to…

    1.6k GitHub starsUsed in 1 repo~822 tokens
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from Bald0Wang/DeepSeek-Oracle

All 10 skills in this repo
  • Oracle Agent Team Orchestrator

    Bald0Wang/DeepSeek-Oracle

    Orchestrate DeepSeek Oracle multi-agent workflows by routing user intents to specialist oracle skills, enforcing safety gates, and composing one unified answer with follow-up questions and action…

    187 GitHub stars~551 tokensUpdated 7 mo ago
    Auto-check passed
  • Oracle Consistency Auditor

    Bald0Wang/DeepSeek-Oracle

    Audit consistency of repeated long-line oracle outputs and diagnose drift causes across routing, retrieval, and generation settings.

    187 GitHub stars~337 tokensUpdated 7 mo ago
    Auto-check passed
  • Oracle Philosophy RAG Agent

    Bald0Wang/DeepSeek-Oracle

    Convert retrieved philosophy or classics snippets into concise modern mindset guidance and practical reflection methods.

    187 GitHub stars~281 tokensUpdated 7 mo ago
    Auto-check passed
  • Oracle Actionizer

    Bald0Wang/DeepSeek-Oracle

    Transform oracle guidance into concrete, calendar-ready tasks with suggested time windows, effort level, and practical notes.

    187 GitHub stars~246 tokensUpdated 7 mo ago
    Auto-check passed
  • Oracle Daily Card Composer

    Bald0Wang/DeepSeek-Oracle

    Compose daily oracle cards from profile, date context, and recent conversation themes using a fixed stable format.

    187 GitHub stars~247 tokensUpdated 7 mo ago
    Auto-check passed
  • Oracle Meihua Agent

    Bald0Wang/DeepSeek-Oracle

    Produce short-term MeiHua YiShu analysis for concrete near-term events, including reframed question, tendency, key variables, do/donot guidance, and contingency actions.

    187 GitHub stars~265 tokensUpdated 7 mo ago
    Auto-check passed

Categories

Questions about Post Dev Security Review

What does Post Dev Security Review do?

Perform post-implementation security review on recent code changes and produce prioritized hardening recommendations with file evidence and fix guidance. Post Dev Security Review is an agent skill from Bald0Wang/DeepSeek-Oracle. Perform post-implementation security review on recent code changes and produce prioritized hardening recommendations with file evidence and fix guidance.

When should I use Post Dev Security Review?

Post Dev Security Review fits situations like: A development task is completed; before merge/release; users ask for security checks; vulnerability analysis.

How do I install Post Dev Security Review in Claude Code?

Run `npx skills add Bald0Wang/DeepSeek-Oracle --skill post-dev-security-review -a claude-code`. Or copy the skill folder (.codex/skills/post-dev-security-review in Bald0Wang/DeepSeek-Oracle) into .claude/skills/post-dev-security-review in your project. Claude Code loads it when a task matches its description.

How do I install Post Dev Security Review in Codex?

Run `npx skills add Bald0Wang/DeepSeek-Oracle --skill post-dev-security-review -a codex`. Or copy the skill folder (.codex/skills/post-dev-security-review in Bald0Wang/DeepSeek-Oracle) into .agents/skills/post-dev-security-review in your project. Codex loads it when a task matches its description.

Can I use Post Dev Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Bald0Wang/DeepSeek-Oracle --skill post-dev-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/post-dev-security-review, .gemini/skills/post-dev-security-review, .github/skills/post-dev-security-review and .opencode/skills/post-dev-security-review in your project.

What does Post Dev Security Review need to run?

Going by SKILL.md and its folder, Post Dev Security Review needs the command-line tools its instructions call (git).

Does Post Dev Security Review access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Post Dev Security Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Post Dev Security Review use?

No licence was found for Post Dev Security Review or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Post Dev Security Review use?

About 694 tokens (SKILL.md is roughly 2.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 782 tokens, read only when the agent opens those files.

What are the alternatives to Post Dev Security Review?

Skills that share tags, products or a category with Post Dev Security Review: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Agentlas Security Scan (agentlas-ai/Agentlas-OS, 1.6k stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Post Dev Security Review?

Bald0Wang (a GitHub user) maintains it in Bald0Wang/DeepSeek-Oracle, which has 187 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on February 24, 2026.

Source: Bald0Wang/DeepSeek-Oracle on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.