Agent skill

Openfdd Mt Security

by bbartling in bbartling/open-fdd

Multi-tenant authz, pre-auth disclosure hardening, and Kali disposition.

Custom licenceAuto-check passedBackend & APIs

Install Openfdd Mt Security

skills CLI
$ npx skills add bbartling/open-fdd --skill openfdd-mt-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bbartling/open-fdd openfdd-mt-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bbartling/open-fdd.git skills-src && mkdir -p .claude/skills && cp -r skills-src/openfdd_agent_spec/skills/openfdd-mt-security .claude/skills/openfdd-mt-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
openfdd-mt-security
GitHub stars
172
Token cost
~2.2k tokens
SKILL.md length
866 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
Custom licence

At a glance

Multi-tenant authz, pre-auth disclosure hardening, and Kali disposition.

  • : /api/tenants leak
  • SKILL.md covers Verified Kali findings…, Endpoint → authz (quick matrix), Tests to run (Mint) and MQTT (staging / Kali next), plus 4 more sections
  • Calls cargo, pytest and python3; needs OPENFDD_JWT_SECRET
  • Capabilities public

What it does

Openfdd Mt Security is an agent skill from bbartling/open-fdd. Multi-tenant authz, pre-auth disclosure hardening, and Kali disposition. Triggers on: /api/tenants leak, capabilities public, CSP, security.txt, IDOR, Tenant A/B, hub admin, agent token, MQTT ACL, ZAP findings, O2c, P2c.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Penetration testing, Authorization and RBAC and Multi-tenancy. The repository describes itself as: Fault Detection Diagnostics (FDD) for HVAC datasets.

When your agent uses it

  • : /api/tenants leak
  • Capabilities public

Example prompts

  • “/openfdd-mt-security”

Requirements

  • Python 3
  • A credential in OPENFDD_JWT_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit b5c4e9c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo
    • pytest
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENFDD_JWT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Openfdd Mt Security loads about 2.2k tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 866 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 866 words (~2,230 tokens).

“Kali owns live ZAP/PEN. Mint implements product fixes + automated tests. Never ActiveScan production OT from Mint.”

— opening of SKILL.md by bbartling, Custom licence
name
openfdd-mt-security

Read the full SKILL.md on GitHub

Files

Just SKILL.md in openfdd_agent_spec/skills/openfdd-mt-security of bbartling/open-fdd.

Open the folder on GitHubat commit b5c4e9c

Compare with similar skills

Openfdd Mt Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Openfdd Mt Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Openfdd Mt Security this skillbbartling/open-fdd172—~2.2kAutomated safety check: PassCustom licence
Django Access Reviewgetsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.0
Auth BypassNeoTheCapt/RedteamAgent142—~1.3kAutomated safety check: PassNone
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0
Security Reviewlangfuse/langfuse36k—~1.4kAutomated safety check: PassCustom licence
Security Reviewtrycompai/comp2k—~853Automated safety check: PassAGPL-3.0

Similar skills

  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Backend & APIsAuto-check: notes
  • Auth Bypass

    NeoTheCapt/RedteamAgent

    Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses

    142 GitHub stars~1.3k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Security Review

    langfuse/langfuse

    Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy.

    36k GitHub stars~1.4k tokensUpdated today
    SecurityAuto-check passed
  • Security Review

    trycompai/comp

    Check code for the most common, high-risk security vulnerabilities (broken access control, tenant isolation, injection, secrets, SSRF, auth/session, unsafe file handling, mass assignment) before it…

    2k GitHub stars~853 tokensUpdated today
    SecurityAuto-check passed
  • Idor Testing

    zebbern/claude-code-guide

    This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…

    4.7k GitHub starsUsed in 8 repos~3.1k tokens
    SecurityAuto-check passed

More from bbartling/open-fdd

All 23 skills in this repo
  • Architecture Design Review

    bbartling/open-fdd

    A skill your agent uses to evaluate architecture, design proposals, refactors, module boundaries, dependency direction, data flow, concurrency model, and maintainability tradeoffs across any codebase.

    172 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Codebase Research Pass

    bbartling/open-fdd

    A skill your agent uses for structured research on an unfamiliar or complex codebase before planning, reviewing, or editing.

    172 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • External Source Research

    bbartling/open-fdd

    A skill your agent uses when implementation or review depends on external documentation, standards, protocols, APIs, SDKs, changelogs, or version-specific behavior.

    172 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Multi Agent PR Review

    bbartling/open-fdd

    A skill your agent uses for rigorous pull request, branch, patch, or diff review.

    172 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • A skill your agent uses to design, run, or review performance work with reproducible A/B baselines.

    172 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • A skill your agent uses to compare any codebase against a specification, API contract, protocol, policy, RFC, security baseline, or product requirements document.

    172 GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Questions about Openfdd Mt Security

What does Openfdd Mt Security do?

Multi-tenant authz, pre-auth disclosure hardening, and Kali disposition. Openfdd Mt Security is an agent skill from bbartling/open-fdd. Multi-tenant authz, pre-auth disclosure hardening, and Kali disposition.

When should I use Openfdd Mt Security?

Openfdd Mt Security fits situations like: : /api/tenants leak; capabilities public.

How do I install Openfdd Mt Security in Claude Code?

Run `npx skills add bbartling/open-fdd --skill openfdd-mt-security -a claude-code`. Or copy the skill folder (openfdd_agent_spec/skills/openfdd-mt-security in bbartling/open-fdd) into .claude/skills/openfdd-mt-security in your project. Claude Code loads it when a task matches its description.

How do I install Openfdd Mt Security in Codex?

Run `npx skills add bbartling/open-fdd --skill openfdd-mt-security -a codex`. Or copy the skill folder (openfdd_agent_spec/skills/openfdd-mt-security in bbartling/open-fdd) into .agents/skills/openfdd-mt-security in your project. Codex loads it when a task matches its description.

Can I use Openfdd Mt Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bbartling/open-fdd --skill openfdd-mt-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openfdd-mt-security, .gemini/skills/openfdd-mt-security, .github/skills/openfdd-mt-security and .opencode/skills/openfdd-mt-security in your project.

What does Openfdd Mt Security need to run?

Going by SKILL.md and its folder, Openfdd Mt Security needs the command-line tools its instructions call (cargo, pytest and python3) and credentials named OPENFDD_JWT_SECRET. Our summary lists: Python 3; A credential in OPENFDD_JWT_SECRET.

Does Openfdd Mt Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Openfdd Mt Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Openfdd Mt Security use?

Openfdd Mt Security has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Openfdd Mt Security use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Openfdd Mt Security?

Skills that share tags, products or a category with Openfdd Mt Security: Django Access Review (getsentry/skills, 1k stars), Auth Bypass (NeoTheCapt/RedteamAgent, 142 stars), Supercheck Security Auth (supercheck-io/supercheck, 215 stars) and Security Review (langfuse/langfuse, 36k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Openfdd Mt Security?

bbartling (a GitHub user) maintains it in bbartling/open-fdd, which has 172 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 7, 2026.

Source: bbartling/open-fdd on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.