Agent skill

Security

by BuilderIO in BuilderIO/agent-native

Secure coding practices for agent-native apps: input validation, SQL injection, XSS, secrets, data scoping, and auth.

No licenceAuto-check: notesSecurity

Install Security

skills CLI
$ npx skills add BuilderIO/agent-native --skill security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BuilderIO/agent-native security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BuilderIO/agent-native.git skills-src && mkdir -p .claude/skills && cp -r skills-src/community-templates/win-loss-memo/.agents/skills/security .claude/skills/security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security
GitHub stars
7.1k
Token cost
~5.2k tokens
SKILL.md length
2,251 words
Files
1
Skills in repo
102
Repo updated
First seen
Licence
None found

At a glance

Secure coding practices for agent-native apps: input validation, SQL injection, XSS, secrets, data scoping, and auth.

  • Works in 3 steps: Read the session: const session = await… → Run the work inside… → Inside fn, query through one of
  • Writing any action
  • SKILL.md covers Rule, Absolute Secrets Rule, Input Validation and Large Payloads, plus 13 more sections
  • Calls pnpm; needs BETTER_AUTH_SECRET and OPENAI_API_KEY

What it does

Security is an agent skill from BuilderIO/agent-native. Secure coding practices for agent-native apps: input validation, SQL injection, XSS, secrets, data scoping, and auth. Use when writing any action, route, or component that touches user data or external input.

Its SKILL.md is about 5.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities and Secure coding. The repository describes itself as: A framework for building agentic apps.

When your agent uses it

  • Writing any action
  • Component that touches user data

Example prompts

  • “/security”

Requirements

  • A credential in OPENAI_API_KEY
  • A credential in SECRETS_ENCRYPTION_KEY

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Read the session: const session = await getSession(event).catch(() => null).
  2. Run the work inside runWithRequestContext({ userEmail: session?.email, orgId: session?.orgId }, fn) from @agent-native/core/server.
  3. Inside fn, query through one of

What it can do on your machine

Read from SKILL.md and the folder at commit e16da0c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • BETTER_AUTH_SECRET
    • OPENAI_API_KEY
    • SECRETS_ENCRYPTION_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security loads about 5.2k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 2,251 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~5.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:343
    - [ ] New env vars in `.env` only, not committed

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 2,251 words (~5,181 tokens).

“Use the framework's security primitives everywhere. Never bypass them.”

— opening of SKILL.md by BuilderIO
name
security
scope
dev
metadata.internal
true

Read the full SKILL.md on GitHub

Files

Just SKILL.md in community-templates/win-loss-memo/.agents/skills/security of BuilderIO/agent-native.

Open the folder on GitHubat commit e16da0c

Compare with similar skills

Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security this skillBuilderIO/agent-native7.1k—~5.2kAutomated safety check: NotesNone
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
Fix Strix Security Findingsusestrix/strix67k—~1.5kAutomated safety check: PassApache-2.0
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Security Verification Gatefengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT
Security and Hardeningaddyosmani/agent-skills103k1 repos~4.4kAutomated safety check: NotesMIT

Similar skills

  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

    67k GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 23 days ago
    SecurityAuto-check: notes
  • Security and Hardening

    addyosmani/agent-skills

    Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

    103k GitHub starsUsed in 1 repo~4.4k tokens
    SecurityAuto-check: notes
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    322 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from BuilderIO/agent-native

All 102 skills in this repo
  • Actions

    BuilderIO/agent-native

    How to create and run agent actions. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Client Methods

    BuilderIO/agent-native

    Client method surface rules. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Adding A Feature

    BuilderIO/agent-native

    The four-area checklist every new feature must complete. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • Address Feedback

    BuilderIO/agent-native

    Triage feedback from docs, issues, Slack threads, or pasted notes into verified bugs, UX proposals, unclear questions, and skipped noise.

    7.1k GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Audit Log

    BuilderIO/agent-native

    Durable, access-scoped, append-only record of who changed what app data, when, and whether it was the agent or a human.

    7.1k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Automations

    BuilderIO/agent-native

    Event-triggered and schedule-triggered automations with natural-language conditions.

    7.1k GitHub stars~4.4k tokensUpdated today
    Auto-check passed

Categories

Questions about Security

What does Security do?

Secure coding practices for agent-native apps: input validation, SQL injection, XSS, secrets, data scoping, and auth. Security is an agent skill from BuilderIO/agent-native. Secure coding practices for agent-native apps: input validation, SQL injection, XSS, secrets, data scoping, and auth.

When should I use Security?

Security fits situations like: writing any action; component that touches user data.

How do I install Security in Claude Code?

Run `npx skills add BuilderIO/agent-native --skill security -a claude-code`. Or copy the skill folder (community-templates/win-loss-memo/.agents/skills/security in BuilderIO/agent-native) into .claude/skills/security in your project. Claude Code loads it when a task matches its description.

How do I install Security in Codex?

Run `npx skills add BuilderIO/agent-native --skill security -a codex`. Or copy the skill folder (community-templates/win-loss-memo/.agents/skills/security in BuilderIO/agent-native) into .agents/skills/security in your project. Codex loads it when a task matches its description.

Can I use Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BuilderIO/agent-native --skill security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security, .gemini/skills/security, .github/skills/security and .opencode/skills/security in your project.

What does Security need to run?

Going by SKILL.md and its folder, Security needs the command-line tools its instructions call (pnpm) and credentials named BETTER_AUTH_SECRET, OPENAI_API_KEY and SECRETS_ENCRYPTION_KEY. Our summary lists: A credential in OPENAI_API_KEY; A credential in SECRETS_ENCRYPTION_KEY.

Does Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security use?

No licence was found for Security or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Security use?

About 5.2k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security?

Skills that share tags, products or a category with Security: Security And Hardening (penpot/penpot, 61k stars), Fix Strix Security Findings (usestrix/strix, 67k stars), Security Audit Scanner (ruvnet/ruflo, 74k stars) and Security Verification Gate (fengshao1227/ccg-workflow, 5.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security?

BuilderIO (a GitHub organization) maintains it in BuilderIO/agent-native, which has 7,087 GitHub stars. The repository holds 102 skills in this directory. The repository was last updated on October 8, 2026.

Source: BuilderIO/agent-native on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.