Agent skill

Security Guardian

by CaoMeiYouRen in CaoMeiYouRen/caomei-auth

对鉴权、权限、输入处理、数据写入、依赖配置、密钥、日志和外部调用进行安全审计时使用。用户提到 security、auth、permission、vulnerability、secret、injection、审计登录逻辑、权限合规时都应触发。

MITAuto-check passed

Install Security Guardian

skills CLI
$ npx skills add CaoMeiYouRen/caomei-auth --skill security-guardian -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install CaoMeiYouRen/caomei-auth security-guardian --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/CaoMeiYouRen/caomei-auth.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/security-guardian .claude/skills/security-guardian && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-guardian
GitHub stars
220
Token cost
~210 tokens
SKILL.md length
47 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

对鉴权、权限、输入处理、数据写入、依赖配置、密钥、日志和外部调用进行安全审计时使用。用户提到 security、auth、permission、vulnerability、secret、injection、审计登录逻辑、权限合规时都应触发。

  • SKILL.md covers 工作流, 反模式 and 交付前检查
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Guardian is an agent skill from CaoMeiYouRen/caomei-auth. 对鉴权、权限、输入处理、数据写入、依赖配置、密钥、日志和外部调用进行安全审计时使用。用户提到 security、auth、permission、vulnerability、secret、injection、审计登录逻辑、权限合规时都应触发。

Its SKILL.md is about 210 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: 草梅 Auth 是一个基于 Nuxt 全栈框架的统一登录平台。支持 OAuth2.0 协议,集成邮箱、用户名、手机号、验证码、社交媒体等多种登录注册方式。 The licence is MIT.

Example prompts

  • “/security-guardian”

What it can do on your machine

Read from SKILL.md and the folder at commit 7bd3bae. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Guardian loads about 210 tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 47 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~210

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from CaoMeiYouRen/caomei-auth at commit 7bd3bae, republished under its MIT licence (© CaoMeiYouRen). 47 words, ~210 tokens.

Download SKILL.mdSave it as .claude/skills/security-guardian/SKILL.md (or your agent's skills folder).
name
security-guardian
description
对鉴权、权限、输入处理、数据写入、依赖配置、密钥、日志和外部调用进行安全审计时使用。用户提到 security、auth、permission、vulnerability、secret、injection、审计登录逻辑、权限合规时都应触发。
metadata.internal
true

Security Guardian

铁律:把“没有看到明显校验”视为真实风险,直到证据证明它是安全的。

工作流

  • Step 1: 标记敏感面 ⚠️ REQUIRED
    • 1.1 识别登录、会话、权限、数据写入、文件访问、外部请求和 secrets。
    • 1.2 标记涉及用户身份、租户边界和高价值数据的路径。
  • Step 2: 逐类审计 ⚠️ REQUIRED
    • 2.1 查鉴权与授权是否完整。
    • 2.2 查输入处理是否存在注入、XSS、路径遍历或命令执行风险。
    • 2.3 查日志、配置和提交内容是否泄露 secrets。
    • 2.4 查依赖与默认配置是否存在危险默认值。
  • Step 3: 评估影响
    • 3.1 明确可利用性、影响范围和修复优先级。
    • 3.2 不确定时说明需要人工核验的点,而不是轻率放行。

反模式

  • 只扫 secrets,不审权限与输入处理。
  • 看到 helper 名字像 requireAuth 就默认安全。
  • 把“本地环境”“内部系统”当成可接受的安全豁免。

交付前检查

  • 已覆盖鉴权、授权、输入、日志、配置和依赖几个维度。
  • 每个高风险点都说明了利用方式或影响。
  • 不确定的点已明确标注人工核验需求。
  • 没有以环境或规模为理由弱化安全结论。

© CaoMeiYouRen, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/security-guardian of CaoMeiYouRen/caomei-auth.

Open the folder on GitHubat commit 7bd3bae

Compare with similar skills

Security Guardian next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Guardian compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Guardian this skillCaoMeiYouRen/caomei-auth220—~210Automated safety check: PassMIT
Context Guardiansickn33/agentic-awesome-skills47k2 repos~3.3kAutomated safety check: PassMIT
Tool Use Guardiansickn33/agentic-awesome-skills47k2 repos~849Automated safety check: PassMIT
Fullstack GuardianJeffallan/claude-skills12k—~1.5kAutomated safety check: PassMIT
Openclaw GuardianLeoYeAI/openclaw-master-skills2.2k—~634Automated safety check: WarnMIT
Scope Guardian Reviewerudecode/plate17k—~812Automated safety check: PassCustom licence

Similar skills

  • Context Guardian

    sickn33/agentic-awesome-skills

    Guardiao de contexto que preserva dados criticos antes da compactacao automatica.

    47k GitHub starsUsed in 2 repos~3.3k tokens
    Auto-check passed
  • Tool Use Guardian

    sickn33/agentic-awesome-skills

    FREE — Intelligent tool-call reliability wrapper. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~849 tokens
    Backend & APIsAuto-check passed
  • Fullstack Guardian

    Jeffallan/claude-skills

    Plans and builds full-stack features with frontend, backend and security handled together, including a written design and a security checklist before any code.

    12k GitHub stars~1.5k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Openclaw Guardian

    LeoYeAI/openclaw-master-skills

    Deploy and manage a Guardian watchdog process for OpenClaw Gateway.

    2.2k GitHub stars~634 tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: warnings
  • Reviews planning documents for scope alignment and unjustified complexity -- challenges unnecessary abstractions, premature frameworks, and scope that exceeds stated goals.

    17k GitHub stars~812 tokensUpdated today
    Auto-check passed
  • Secure Code Guardian

    Jeffallan/claude-skills

    Guides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks.

    12k GitHub stars~1.8k tokensUpdated 6 days ago
    SecurityAuto-check passed

More from CaoMeiYouRen/caomei-auth

All 14 skills in this repo
  • Code Reviewer

    CaoMeiYouRen/caomei-auth

    审查当前 git 变更、PR、提交范围、技能定义文件、架构调整或安全敏感代码时使用。输出结构化 Review Gate 结论(Pass/Reject)、问题分级(blocker/warning/suggest)、最低验证矩阵、证据链与复查基线。覆盖正确性、安全、架构、SOLID、可删除代码、性能、异常处理与测试风险;默认只输出 review,不直接修改代码。用户提到 review、code…

    220 GitHub stars~1.5k tokensUpdated 9 days ago
    Auto-check passed
  • Full Stack Master

    CaoMeiYouRen/caomei-auth

    需要统筹需求澄清、上下文扫描、技术方案、前后端实现、UI 验证、测试、质量审查、文档同步和提交节奏时使用。它负责编排多技能协作,而不是亲自替代所有专业技能。用户提到 end-to-end workflow、全流程开发、从需求到提交、PDTFC+、多技能编排时都应触发。

    220 GitHub stars~1k tokensUpdated 9 days ago
    Auto-check passed
  • Quality Guardian

    CaoMeiYouRen/caomei-auth

    运行并解读 lint、类型检查、测试等质量门时使用。它不只是执行命令,还要根据变更范围选择最小充分检查、分析失败原因,并给出是否允许继续提交或发布的判断。用户提到 lint、typecheck、tests、quality gate、验证改动时都应触发。

    220 GitHub stars~358 tokensUpdated 9 days ago
    Auto-check passed
  • Devops Specialist

    CaoMeiYouRen/caomei-auth

    修改 Docker、CI/CD、部署配置、环境变量、运行时参数、构建脚本和发布流程时使用。优先覆盖 Docker、Vercel、Cloudflare 与 GitHub Actions 场景。用户提到 deploy、Dockerfile、workflow、CI、CD、environment variables、build pipeline、release config 时都应触发。

    220 GitHub stars~446 tokensUpdated 9 days ago
    Auto-check: notes
  • Gh CLI

    CaoMeiYouRen/caomei-auth

    使用 GitHub CLI(gh)处理仓库、issue、pull request、workflow、project、release、codespace、gist、search、api、auth、config、alias、secret、variable、extension、ruleset 和 status 等命令行操作时使用。用户提到 gh、gh cli、GitHub CLI、gh…

    220 GitHub stars~460 tokensUpdated 9 days ago
    Auto-check passed
  • Backend Expert

    CaoMeiYouRen/caomei-auth

    设计或实现后端 API、服务层、数据库读写、鉴权权限控制、输入校验、事务处理与错误处理时使用。用户提到 API、route、handler、server、auth、permission、drizzle、database、zod、Hono、Nuxt server routes、backend bug 修复时都应触发。

    220 GitHub stars~329 tokensUpdated 9 days ago
    Auto-check passed

Questions about Security Guardian

What does Security Guardian do?

对鉴权、权限、输入处理、数据写入、依赖配置、密钥、日志和外部调用进行安全审计时使用。用户提到 security、auth、permission、vulnerability、secret、injection、审计登录逻辑、权限合规时都应触发。. Security Guardian is an agent skill from CaoMeiYouRen/caomei-auth.

How do I install Security Guardian in Claude Code?

Run `npx skills add CaoMeiYouRen/caomei-auth --skill security-guardian -a claude-code`. Or copy the skill folder (.github/skills/security-guardian in CaoMeiYouRen/caomei-auth) into .claude/skills/security-guardian in your project. Claude Code loads it when a task matches its description.

How do I install Security Guardian in Codex?

Run `npx skills add CaoMeiYouRen/caomei-auth --skill security-guardian -a codex`. Or copy the skill folder (.github/skills/security-guardian in CaoMeiYouRen/caomei-auth) into .agents/skills/security-guardian in your project. Codex loads it when a task matches its description.

Can I use Security Guardian in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CaoMeiYouRen/caomei-auth --skill security-guardian -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-guardian, .gemini/skills/security-guardian, .github/skills/security-guardian and .opencode/skills/security-guardian in your project.

What does Security Guardian need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Guardian is instructions for the agent only.

Does Security Guardian access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Guardian safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Guardian use?

Security Guardian is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Guardian use?

About 210 tokens (SKILL.md is roughly 840 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Guardian?

Skills that share tags, products or a category with Security Guardian: Context Guardian (sickn33/agentic-awesome-skills, 47k stars), Tool Use Guardian (sickn33/agentic-awesome-skills, 47k stars), Fullstack Guardian (Jeffallan/claude-skills, 12k stars) and Openclaw Guardian (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Guardian?

CaoMeiYouRen (a GitHub user) maintains it in CaoMeiYouRen/caomei-auth, which has 220 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 1, 2026.

Source: CaoMeiYouRen/caomei-auth on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.