Agent skill

Senior Secops

by borghei in borghei/Claude-Skills

SecOps for application security, vulnerability management, compliance, and secure development.

MITAuto-check passedSecurity

Install Senior Secops

skills CLI
$ npx skills add borghei/Claude-Skills --skill senior-secops -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills senior-secops --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engineering/senior-secops .claude/skills/senior-secops && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
senior-secops
GitHub stars
881
Token cost
~1.7k tokens
SKILL.md length
706 words
Files
9 (incl. scripts, references)
Skills in repo
349
Repo updated
First seen
Licence
MIT

At a glance

SecOps for application security, vulnerability management, compliance, and secure development.

  • Implementing security controls
  • SKILL.md covers Core Capabilities, When to Use, Clarify First and Tools, plus 3 more sections
  • Runs Python scripts from its folder; calls python
  • Conducting security audits

What it does

Senior Secops is an agent skill from borghei/Claude-Skills. SecOps for application security, vulnerability management, compliance, and secure development. Use when implementing security controls, conducting security audits, responding to vulnerabilities, or meeting compliance requirements.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `references/compliance_requirements.md`, `references/security_standards.md` and `references/standards-and-playbook.md`).

It sits in Security, covering Vulnerability scanning, Security review and Web application vulnerabilities. It works with Python. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • Implementing security controls
  • Conducting security audits
  • Responding to vulnerabilities
  • Meeting compliance requirements

Example prompts

  • “Use the senior-secops skill to secop for application security, vulnerability management, compliance, and secure development”
  • “/senior-secops”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Senior Secops loads about 1.7k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 61 tokens; SKILL.md has 706 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~22k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 706 words, ~1,672 tokens.

Download SKILL.mdSave it as .claude/skills/senior-secops/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
senior-secops
description
SecOps for application security, vulnerability management, compliance, and secure development. Use when implementing security controls, conducting security audits, responding to vulnerabilities, or meeting compliance requirements.
license
MIT + Commons Clause
metadata.version
1.1.0
metadata.author
borghei
metadata.category
engineering
metadata.domain
security-operations
metadata.updated
2026-06-17
metadata.tags
security-operations, vulnerability-management, incident-response, siem

Senior SecOps Engineer

The agent scans source code for security vulnerabilities (hardcoded secrets, SQL injection, XSS, command injection), assesses dependency CVEs across npm/Python/Go ecosystems, and verifies compliance against SOC 2, PCI-DSS, HIPAA, and GDPR frameworks.

Core Capabilities

  • Security scanner — detect hardcoded secrets, SQL injection, XSS, command injection, and path traversal in source code.
  • Vulnerability assessor — scan npm / Python / Go dependency manifests for known CVEs with CVSS scores, fixed versions, and a 0-100 risk score.
  • Compliance checker — verify SOC 2, PCI-DSS, HIPAA, and GDPR controls (access control, encryption, audit logging, auth strength).
  • Security workflows — audit, CI/CD security gate, CVE triage (with SLA tiers), and 5-phase incident response.
  • Standards & secure coding — OWASP Top 10 prevention, secure-coding checklist, and language-specific BAD/GOOD patterns.

When to Use

  • Implementing security controls or hardening a codebase.
  • Conducting a security audit or pre-release security pass.
  • Responding to or triaging a newly disclosed CVE.
  • Meeting SOC 2, PCI-DSS, HIPAA, or GDPR compliance requirements.
  • Wiring SAST/dependency/compliance gates into CI/CD.

Clarify First

Before the security pass, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Target path — the codebase or dependency manifest to scan (the subject of every scanner)
  • Compliance framework — SOC 2 / PCI-DSS / HIPAA / GDPR (--framework; changes which controls are verified)
  • Severity threshold — the minimum severity to report or gate on (--severity; changes the report and CI pass/fail)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.

Tools

ToolPurposeCommand
security_scanner.pyScan source for secrets, injection, XSS, command injection, path traversalpython scripts/security_scanner.py <target> --severity high --json --output report.json
vulnerability_assessor.pyScan dependency manifests for known CVEs and compute risk scorepython scripts/vulnerability_assessor.py <target> --severity critical
compliance_checker.pyVerify SOC 2 / PCI-DSS / HIPAA / GDPR controlspython scripts/compliance_checker.py <target> --framework soc2 --json --output soc2.json

References

Load the reference that matches the task — keep this file lean and pull detail on demand:

  • references/workflows-and-tooling.md — capability command reference, the 4 workflows (audit, CI/CD gate, CVE triage, incident response), full per-script flag/output/exit-code tables, and the tech stack. Read when running a workflow or invoking a script with specific flags.
  • references/standards-and-playbook.md — OWASP Top 10 prevention table, secure-coding checklist, SOC 2 / PCI-DSS / HIPAA / GDPR control tables, secure-coding BAD/GOOD code patterns, anti-patterns, troubleshooting table, and success criteria. Read when applying standards or diagnosing scanner behavior.
  • references/security_standards.md — deep OWASP Top 10 with code, secure coding practices, authentication standards, API security, and secrets management. Read for in-depth secure-coding guidance.
  • references/vulnerability_management_guide.md — vulnerability lifecycle, CVE triage process, CVSS scoring, remediation workflows, and dependency scanning. Read when managing CVEs end to end.
  • references/compliance_requirements.md — full SOC 2 / PCI-DSS / HIPAA / GDPR control detail, evidence collection, compliance automation, and audit preparation. Read when preparing for an audit.
Show full SKILL.md (252 more words)Show less

Scope & Limitations

This skill covers:

  • Static analysis of source code for common vulnerability classes (secrets, injection, XSS, command injection, path traversal).
  • Dependency vulnerability assessment against a built-in CVE database for npm, Python, and Go ecosystems.
  • Compliance verification for SOC 2 Type II, PCI-DSS v4.0, HIPAA Security Rule, and GDPR.
  • Security workflow orchestration including CI/CD gating, CVE triage, and incident response procedures.

This skill does NOT cover:

  • Dynamic application security testing (DAST) or runtime analysis -- use OWASP ZAP or Burp Suite for live scanning.
  • Infrastructure-as-code security (Terraform, CloudFormation misconfigurations) -- see the senior-devops skill for IaC hardening.
  • Container image scanning or Kubernetes admission control -- see the senior-devops skill or use Trivy directly.
  • Penetration testing execution or red-team operations -- these require specialized tooling and authorized human operators.

Integration Points

SkillIntegrationData Flow
senior-devopsInfrastructure hardening and CI/CD pipeline configurationSecurity scan results feed into deployment gates; DevOps provides container and IaC scanning
senior-backendSecure coding patterns and input validation in server-side codeSecOps scanner findings drive backend remediation; backend applies parameterized queries and output encoding
senior-qaSecurity test cases and regression verification after patchesVulnerability reports generate QA test cases; QA confirms fixes do not introduce regressions
senior-architectThreat modeling, defense-in-depth design, and zero-trust architectureCompliance gaps inform architecture decisions; architect provides security design patterns
code-reviewerSecurity-focused code review and pre-merge analysisScanner findings prioritize review focus areas; reviewer enforces secure coding standards
senior-fullstackEnd-to-end security across frontend and API layers (XSS, CSRF, auth)SecOps identifies frontend and API vulnerabilities; fullstack applies framework-level mitigations

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (scripts, references) in engineering/senior-secops of borghei/Claude-Skills.

  • SKILL.md
  • references/compliance_requirements.md
  • references/security_standards.md
  • references/standards-and-playbook.md
  • references/vulnerability_management_guide.md
  • references/workflows-and-tooling.md
  • scripts/compliance_checker.py
  • scripts/security_scanner.py
  • scripts/vulnerability_assessor.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Senior Secops next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Senior Secops compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Senior Secops this skillborghei/Claude-Skills881—~1.7kAutomated safety check: PassMIT
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Cyber NeoHainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT
Senior Secopsalirezarezvani/claude-skills28k1 repos~4kAutomated safety check: PassMIT
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Security Analyzeraiskillstore/marketplace430—~1.2kAutomated safety check: NotesNone

Similar skills

  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    281 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Senior Secops

    alirezarezvani/claude-skills

    Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices.

    28k GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    430 GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Auditor

    curiositech/some_claude_skills

    Security vulnerability scanner and OWASP compliance auditor for codebases.

    243 GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from borghei/Claude-Skills

All 349 skills in this repo
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    881 GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    881 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    881 GitHub stars~3.6k tokensUpdated yesterday
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    881 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    881 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Brainstorm Okrs

    borghei/Claude-Skills

    OKR brainstorming and validation using the Radical Focus framework — outcome objectives, measurable key results, counter-metrics.

    881 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Senior Secops

What does Senior Secops do?

SecOps for application security, vulnerability management, compliance, and secure development. Senior Secops is an agent skill from borghei/Claude-Skills. SecOps for application security, vulnerability management, compliance, and secure development.

When should I use Senior Secops?

Senior Secops fits situations like: implementing security controls; conducting security audits; responding to vulnerabilities; meeting compliance requirements.

How do I install Senior Secops in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill senior-secops -a claude-code`. Or copy the skill folder (engineering/senior-secops in borghei/Claude-Skills) into .claude/skills/senior-secops in your project. Claude Code loads it when a task matches its description.

How do I install Senior Secops in Codex?

Run `npx skills add borghei/Claude-Skills --skill senior-secops -a codex`. Or copy the skill folder (engineering/senior-secops in borghei/Claude-Skills) into .agents/skills/senior-secops in your project. Codex loads it when a task matches its description.

Can I use Senior Secops in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill senior-secops -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/senior-secops, .gemini/skills/senior-secops, .github/skills/senior-secops and .opencode/skills/senior-secops in your project.

What does Senior Secops need to run?

Going by SKILL.md and its folder, Senior Secops needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Senior Secops access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Senior Secops safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Senior Secops use?

Senior Secops is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Senior Secops use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 20k tokens, read only when the agent opens those files.

What are the alternatives to Senior Secops?

Skills that share tags, products or a category with Senior Secops: Security Auditor (eigent-ai/eigent, 15k stars), Cyber Neo (Hainrixz/cyber-neo, 281 stars), Senior Secops (alirezarezvani/claude-skills, 28k stars) and Security Review (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Senior Secops?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 881 GitHub stars. The repository holds 349 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.