Agent skill

Security

by boshu2 in boshu2/agentops

Review code for security problems; scan for vulnerabilities, secrets, dependency and prompt risks.

Apache-2.0Auto-check passedDevelopment

Install Security

skills CLI
$ npx skills add boshu2/agentops --skill security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install boshu2/agentops security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/boshu2/agentops.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security .claude/skills/security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security
GitHub stars
447
Used in
1 other repo
Token cost
~2.6k tokens
SKILL.md length
1,085 words
Files
10 (incl. scripts, references)
Skills in repo
31
Repo updated
First seen
Licence
Apache-2.0

At a glance

Review code for security problems; scan for vulnerabilities, secrets, dependency and prompt risks.

  • Works in 4 steps: Fail-open paths. For every guard, check,… → Borrowed identity. Trace the effective… → Per-class coverage ledger. Walk every… → …
  • : asked whether code is safe to ship
  • SKILL.md covers Critical Constraints, What every review reports, Manual hunt and Scripted scans, plus 5 more sections
  • Runs Python and Shell scripts from its folder; calls bash and jq

What it does

Security is an agent skill from boshu2/agentops. Review code for security problems; scan for vulnerabilities, secrets, dependency and prompt risks. Use when: asked whether code is safe to ship, even one small handler.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts and reference files (for example `references/agentops-redteam-pack.json`, `references/owasp-checklist.md` and `references/policy-example.json`).

It sits in Development, covering Code review. The repository describes itself as: DevOps discipline for AI coding agents: shape the work, track it as a graph, and get each change judged by a context that didn't write it. The licence is Apache-2.0.

When your agent uses it

  • : asked whether code is safe to ship
  • Even one small handler

Example prompts

  • “/security”

Requirements

  • Python 3
  • A Bash shell

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Fail-open paths. For every guard, check, timeout, and exception handler
  2. Borrowed identity. Trace the effective identity at each hop (user,
  3. Per-class coverage ledger. Walk every applicable class in
  4. Proven versus suspected. A finding is proven only when you ran a

What it can do on your machine

Read from SKILL.md and the folder at commit 8cc4a11. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security loads about 2.6k tokens when it runs, and up to ~6.8k if it reads all its reference files. Until then it costs about 44 tokens; SKILL.md has 1,085 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from boshu2/agentops at commit 8cc4a11, republished under its Apache-2.0 licence (© boshu2). 1,085 words, ~2,580 tokens.

Download SKILL.mdSave it as .claude/skills/security/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
security
description
Review code for security problems; scan for vulnerabilities, secrets, dependency and prompt risks. Use when: asked whether code is safe to ship, even one small handler.
practices
supply-chain-integrity, design-by-contract, sre
hexagonal_role
driven-adapter
consumes
repo-context
produces
security-gate-summary.json, suite-summary.json, redteam-results.json
skill_api_version
1
user-invocable
true
context.window
fork
metadata.capabilities
security
metadata.effects
write_scan_artifacts
metadata.canonical_status
canonical

Security Skill

Purpose: Find and report security weaknesses in code, scripts, authorized binaries, and repo-managed prompt surfaces, with honest coverage.

Use this skill for a caller-requested security review of code, a repository scan, authorized binary assurance, dependency risk, secrets, or offline prompt-surface redteam.

Critical Constraints

  • Scan only repositories, binaries, and prompt surfaces the operator owns or is explicitly authorized to assess. Why: a security review does not grant access to third-party systems or proprietary material.
  • Keep collection read-only by default; do not exfiltrate secrets, execute destructive payloads, or mutate policy/baselines to manufacture green. Why: the assessment must not become the incident or erase its evidence.
  • Treat missing/error scanners as a coverage gap, never a clean finding; use --require-tools when complete tool coverage is required. Why: absent evidence is not evidence of absence.
  • Use the current agent and local shell; do not start another runtime or orchestration substrate unless explicitly requested. Why: repository scanning is a bounded operation, not permission to fan out.
  • Report findings and coverage gaps, then stop. Remediation, risk acceptance, reruns, promotion, and any ship or merge call are caller decisions. Name each finding's remediation class in a few words; do not write the patch, a plan, an owner, or a priority.

What every review reports

Apply these to every review, scripted or manual. They are the rules most often skipped:

  1. Fail-open paths. For every guard, check, timeout, and exception handler on the surface, ask what happens when it errors or hangs. A control that grants access, skips a check, or continues as success on error is a finding even when its happy path is correct.
  2. Borrowed identity. Trace the effective identity at each hop (user, service, token, default, hook). A hop where identity is assumed, defaulted, or inherited instead of verified is the borrowed identity failure mode and a finding.
  3. Per-class coverage ledger. Walk every applicable class in the OWASP checklist (the attack pack for prompt surfaces), plus fail-open and identity, and give each a result: finding, clean, or not assessed. An unvisited class is a gap, never a clean. Chasing one lead to the exclusion of the taxonomy is the first-scent fixation failure mode.
  4. Proven versus suspected. A finding is proven only when you ran a concrete input, request, or command and observed the behavior; capture it. A finding reasoned from the code is suspected, even with a candidate input; give that input and rank it below proven findings.
text
target:   <paths, endpoints, or binary>; authorization: <boundary>
findings: <id> <severity> <file:line> <class>: <what>
          proven: <input run> | suspected: <candidate input, why not run>
          fix class: <a few words>
coverage: <class> -> finding <ids> | clean | not assessed (<why>)
tools:    <scanner or command> -> ran | missing | error
hunt:     converged after <n> passes | unconverged | not run

Manual hunt

Code-level review and redteam passes work in any repository, with or without AgentOps tooling. Walk the ledger against the full surface and probe fail-open behavior where that is safe. Repeat full passes until one complete pass adds no new finding and no new coverage gap; that quiet round is the stop condition. If the budget ends first, report the hunt as unconverged. The quiet-round rule applies only to the manual hunt.

Scripted scans

Each selected scan runs once per request; a rerun is a new caller decision.

SurfaceEntry pointLocation
Repository gate (quick or full)scripts/security-gate.shAgentOps repository root only
Composable suite for authorized binariesskills/security/scripts/security_suite.pythis skill's scripts/
Offline prompt-surface redteamskills/security/scripts/prompt_redteam.pythis skill's scripts/
  • No gate script (any other repository): run the scanners the project already uses, such as a dependency audit, secret scan, or static analyzer, record each one that is absent as a coverage gap, and do the manual hunt.
  • Redteam pack: the bundled attack pack targets AgentOps control surfaces. In another repository its cases fail with "no files matched target globs"; that is a pack mismatch, not a finding.
  • Read the suite runbook before binary, policy, baseline, or redteam work.

This is the canonical security runbook. Suite policy gating produces machine-consumable outputs, including policy/policy-verdict.json when a policy file is supplied.

Show full SKILL.md (460 more words)Show less
Repository gate
bash
scripts/security-gate.sh --mode quick   # changed scope
scripts/security-gate.sh --mode full    # repository-wide

Add --require-tools when skipped scanners would invalidate the assurance claim. Checkpoint: preserve the exit code and verify the reported security-gate-summary.json exists and parses before triage; report the result as incomplete unless the selected artifact validator and process both succeed.

Scheduled automation runs the full gate against the intended branch and retains its artifact directory. A failing scheduled run creates actionable tracked work; AgentOps itself does not supply the scheduler.

Triage
  1. Open the latest artifact and identify scanner, severity, file, and coverage gaps.
  2. Reproduce the finding with the narrowest safe command; an unreproduced hit stays suspected.
  3. Rank concrete findings and preserve coverage gaps.
  4. Stop. Remediation, risk acceptance, and any later scan are new caller decisions. Do not downgrade, suppress, or update a baseline merely to pass.

Output Specification

Artifact directory: repository gates write ${SECURITY_GATE_OUTPUT_DIR:-${TMPDIR:-/tmp}/agentops-security}/<run-id>/; composable-suite and redteam runs use their explicit --out-dir.

Filename convention: repository gates require security-gate-summary.json (and raw summary.json); suite runs require suite-summary.json; redteam runs require redteam/redteam-results.json.

Serialization/schema format: security-gate-summary.json is JSON with nonempty mode, run_id, output_dir, and gate_status, numeric missing_tool_count, boolean require_tools, and object toolchain.

Validator command: with OUT=<security-gate-run-dir>, run jq -e '(.mode|type)=="string" and (.mode|length)>0 and (.run_id|type)=="string" and (.run_id|length)>0 and (.output_dir|type)=="string" and (.output_dir|length)>0 and .gate_status=="PASS" and (.missing_tool_count|type)=="number" and (.require_tools|type)=="boolean" and (.toolchain|type)=="object"' "$OUT/security-gate-summary.json" >/dev/null.

Output: the review report above; for scripted scans also the artifact path, command/exit code, mode, and gate status. Do not add an owner, next action, approval, release, ship, or retry decision.

Quality Checklist

  • Target and authorization boundary are explicit; collection stayed within them.
  • Every applicable class has a result; unvisited classes are listed as not assessed.
  • Scanner availability and skipped/error coverage are visible in the report.
  • Findings include severity, location, proven-or-suspected evidence, and a remediation class, with no patch, plan, owner, or priority.
  • Artifacts contain no newly exposed secrets or unredacted sensitive payloads.
  • The report distinguishes a passing scan from permission to promote, ship, or release.
  • Suppressions, policy changes, baselines, and risk acceptance require explicit judgment.
  • The report stops after evidence and contains no continuation decision.

Validation

Run the skill and redteam validators:

bash
bash skills/security/scripts/validate.sh
bash tests/scripts/test-security-suite-redteam.sh

For a bounded suite smoke test, use an owned binary and a temporary output directory as shown in the suite runbook.

Troubleshooting

ProblemResponse
Scanner missing/errorRecord the coverage gap; install it or rerun with --require-tools when required
Local/CI mismatchCompare scanner versions, config, mode, and both artifact directories
Suspected false positiveReproduce narrowly; document any authorized suppression and its owner
Suite/baseline failureInspect the named compare/policy artifact; never refresh baseline reflexively
Redteam failure after wording changeDecide whether the control regressed or the attack-pack matcher needs intentional revision

Reference Documents

© boshu2, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (scripts, references) in skills/security of boshu2/agentops.

  • SKILL.md
  • references/agentops-redteam-pack.json
  • references/owasp-checklist.md
  • references/policy-example.json
  • references/security-suite-runbook.md
  • references/security-suite.feature
  • references/security.feature
  • scripts/prompt_redteam.py
  • scripts/security_suite.py
  • scripts/validate.sh

Open the folder on GitHubat commit 8cc4a11

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in boshu2/agentops, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security this skillboshu2/agentops4471 repos~2.6kAutomated safety check: PassApache-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Backend Code Reviewlangflow-ai/langflow156k—~3.5kAutomated safety check: NotesMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT
Mole Bug Patternstw93/Mole69k—~2kAutomated safety check: PassGPL-3.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Backend Code Review

    langflow-ai/langflow

    Review backend code for quality, security, maintainability, and best practices based on established checklist rules.

    156k GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

    69k GitHub stars~2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Backend Code Review

    langgenius/dify

    Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.

    158k GitHub stars~676 tokensUpdated today
    DevelopmentAuto-check passed

More from boshu2/agentops

All 31 skills in this repo
  • Agent Native

    boshu2/agentops

    Dispatch independent tasks to parallel workers or subagents without write collisions.

    447 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Council

    boshu2/agentops

    Compare independent opinions from several models or contexts without inflating agreement.

    447 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed
  • Craft Goal

    boshu2/agentops

    Draft or lint a bounded long-running goal prompt with a finish line and hard limits.

    447 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed
  • Doc

    boshu2/agentops

    Write or update READMEs, docs, repo instructions and handoff notes, checked against source.

    447 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Idea Genie

    boshu2/agentops

    Brainstorm evidence-backed options for what to build, or stress-test an idea.

    447 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Implement

    boshu2/agentops

    Change or repair code, config or services without weakening tests; report what ran and what did not.

    447 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Categories

Questions about Security

What does Security do?

Review code for security problems; scan for vulnerabilities, secrets, dependency and prompt risks. Security is an agent skill from boshu2/agentops. Review code for security problems; scan for vulnerabilities, secrets, dependency and prompt risks.

When should I use Security?

Security fits situations like: : asked whether code is safe to ship; even one small handler.

How do I install Security in Claude Code?

Run `npx skills add boshu2/agentops --skill security -a claude-code`. Or copy the skill folder (skills/security in boshu2/agentops) into .claude/skills/security in your project. Claude Code loads it when a task matches its description.

How do I install Security in Codex?

Run `npx skills add boshu2/agentops --skill security -a codex`. Or copy the skill folder (skills/security in boshu2/agentops) into .agents/skills/security in your project. Codex loads it when a task matches its description.

Can I use Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add boshu2/agentops --skill security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security, .gemini/skills/security, .github/skills/security and .opencode/skills/security in your project.

What does Security need to run?

Going by SKILL.md and its folder, Security needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (bash and jq). Our summary lists: Python 3; A Bash shell.

Does Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security use?

Security is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.3k tokens, read only when the agent opens those files.

What are the alternatives to Security?

Skills that share tags, products or a category with Security: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Backend Code Review (langflow-ai/langflow, 156k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security?

boshu2 (a GitHub user) maintains it in boshu2/agentops, which has 447 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 7, 2026.

Source: boshu2/agentops on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.