Agent skill

Kesekit Check Ko

by cdppcorp in cdppcorp/KESE-KIT

KISA 가이드라인 기반 배포 전 보안 컴플라이언스 체크리스트를 실행합니다. An agent skill from cdppcorp/KESE-KIT.

MITAuto-check passedSecurity

Install Kesekit Check Ko

skills CLI
$ npx skills add cdppcorp/KESE-KIT --skill kesekit-check-ko -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cdppcorp/KESE-KIT kesekit-check-ko --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cdppcorp/KESE-KIT.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills-ko/kesekit-check-ko .claude/skills/kesekit-check-ko && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kesekit-check-ko
GitHub stars
360
Token cost
~956 tokens
SKILL.md length
453 words
Files
75 (incl. scripts, references)
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

KISA 가이드라인 기반 배포 전 보안 컴플라이언스 체크리스트를 실행합니다. An agent skill from cdppcorp/KESE-KIT.

  • Works in 6 steps: 계정 보안 (15항목) — root/Admin 원격접속, 패스워드 정책,… → 접근 제어 (15항목) — 파일 권한, 방화벽, 포트, 네트워크 분리 → 암호화 및 데이터 보호 (12항목) — HTTPS, TLS, 패스워드… → …
  • Security work in your project
  • SKILL.md covers 가이드라인 선택, CII 분기 시, AI 보안 분기 시 and 로봇 보안 분기 시, plus 3 more sections

What it does

Kesekit Check Ko is an agent skill from cdppcorp/KESE-KIT. KISA 가이드라인 기반 배포 전 보안 컴플라이언스 체크리스트를 실행합니다. CII 컴플라이언스(70항목), AI 보안 체크리스트, 로봇 보안 체크리스트, 우주 보안 체크리스트(12분야 53항목)를 지원합니다. "배포 전 점검", "컴플라이언스 체크", "보안 체크리스트", "우주 보안 점검", "위성 보안 체크" 시 사용하세요.

Its SKILL.md is about 960 tokens, which your agent loads only when the skill is triggered. The skill folder holds 81 other files, including scripts and reference files (for example `references/ai-security/overview.md`, `references/ai-security/service-provider.md` and `references/ai-security/user-guide.md`).

It sits in Security. It works with JavaScript and Python. The repository describes itself as: KISA 주요정보통신기반시설 기술적 취약점 분석 평가방법 상세가이드 기반 Skills. The licence is MIT.

When your agent uses it

  • Security work in your project

Example prompts

  • “/kesekit-check-ko”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. 계정 보안 (15항목) — root/Admin 원격접속, 패스워드 정책, 계정 잠금
  2. 접근 제어 (15항목) — 파일 권한, 방화벽, 포트, 네트워크 분리
  3. 암호화 및 데이터 보호 (12항목) — HTTPS, TLS, 패스워드 해시, 하드코딩 금지
  4. 로깅 및 모니터링 (10항목) — 시스템 로깅, 인증 로그, 디버그 모드
  5. 서비스 하드닝 (12항목) — 불필요 서비스, 보안 헤더, CSRF, SQLi 방지
  6. 패치 및 업데이트 (6항목) — OS 패치, 프레임워크 업데이트, CVE 점검

What it can do on your machine

Read from SKILL.md and the folder at commit cd118f9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/, which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kesekit Check Ko loads about 956 tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 51 tokens; SKILL.md has 453 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~956
With references · SKILL.md plus every file in references/, read only if the agent opens them
~16k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from cdppcorp/KESE-KIT at commit cd118f9, republished under its MIT licence (© cdppcorp). 453 words, ~956 tokens.

Download SKILL.mdSave it as .claude/skills/kesekit-check-ko/SKILL.md (or your agent's skills folder). This skill also uses 74 other files; get the full folder from GitHub.
name
kesekit-check-ko
description
KISA 가이드라인 기반 배포 전 보안 컴플라이언스 체크리스트를 실행합니다. CII 컴플라이언스(70항목), AI 보안 체크리스트, 로봇 보안 체크리스트, 우주 보안 체크리스트(12분야 53항목)를 지원합니다. "배포 전 점검", "컴플라이언스 체크", "보안 체크리스트", "우주 보안 점검", "위성 보안 체크" 시 사용하세요.

KESE 배포 전 보안 컴플라이언스 체크리스트

배포 전 보안 점검을 수행합니다. 사용자의 환경에 맞는 가이드라인을 자동 선택합니다.

가이드라인 선택

#가이드라인설명
1CII 컴플라이언스주요정보통신기반시설 배포 전 70항목 체크
2AI 보안 체크리스트AI 개발자/서비스제공자 보안 검증항목 체크
3로봇 보안 체크리스트로봇 시스템 11개 카테고리 103항목 체크
4우주 보안 체크리스트위성/GSaaS/공급망 12분야 53항목 체크
5시큐어코딩 체크리스트JavaScript/Python 코드 리뷰 (7개 카테고리, 46 CWE)
6제로트러스트 체크리스트제로트러스트 성숙도 평가 (8개 핵심요소, 4단계 성숙도, ~396항목)

서버, 인프라, 웹 서비스 → CII / AI 모델, LLM, AI 서비스 → AI 보안 / 로봇, ROS/ROS2, 의료용 로봇, AMR/AGV → 로봇 보안 / 위성, 지상국, GSaaS, 우주 공급망 → 우주 보안 / JavaScript, Python, 웹 앱 코드 → 시큐어코딩 Zero Trust, ZTA, ZTNA, 제로트러스트, 마이크로세그멘테이션, microsegmentation, SDP, SASE, PEP/PDP, never trust always verify → 제로트러스트


CII 분기 시

대상 환경을 탐지한 후, 해당하는 템플릿 파일을 templates/cii/에서 로드하여 체크리스트를 실행합니다. 점검/수정 스크립트는 scripts/cii/에 있습니다. 템플릿 파일 목록은 start 스킬과 동일합니다.

심각도 수준
  • 긴급: 배포 차단. 운영 전 반드시 수정
  • 높음: 수정 필요. 문서화된 위험 수용 시 배포 가능
  • 중간: 개선 권고. 단기간 내 수정 계획 수립
  • 낮음: 권장 사항. 배포 차단하지 않음
체크 카테고리
  1. 계정 보안 (15항목) — root/Admin 원격접속, 패스워드 정책, 계정 잠금
  2. 접근 제어 (15항목) — 파일 권한, 방화벽, 포트, 네트워크 분리
  3. 암호화 및 데이터 보호 (12항목) — HTTPS, TLS, 패스워드 해시, 하드코딩 금지
  4. 로깅 및 모니터링 (10항목) — 시스템 로깅, 인증 로그, 디버그 모드
  5. 서비스 하드닝 (12항목) — 불필요 서비스, 보안 헤더, CSRF, SQLi 방지
  6. 패치 및 업데이트 (6항목) — OS 패치, 프레임워크 업데이트, CVE 점검
배포 준비 보고서
============================================================
     KESE CII 배포 준비 보고서
============================================================
프로젝트: [프로젝트명]
일시: [날짜]

요약: 전체 [N]항목 / 통과 [N] / 실패 [N] / 건너뜀 [N]
배포 결정: [승인 / 차단 / 조건부]
============================================================

AI 보안 분기 시

references/ai-security/ 및 templates/ai-security/ 디렉터리에서 대상에 해당하는 파일을 로드합니다.

AI 개발자 체크리스트

templates/ai-security/developer.md를 로드하여 6단계 생명주기별 54개 검증항목을 점검합니다.

Show full SKILL.md (181 more words)Show less
AI 서비스 제공자 체크리스트

references/ai-security/service-provider.md를 로드하여 서비스 운영 관점의 보안 요구사항을 점검합니다.

AI 이용자 체크리스트

references/ai-security/user-guide.md를 로드하여 7개 보안 수칙 이행 여부를 점검합니다.


로봇 보안 분기 시

templates/robot-security/ 디렉터리에서 관련 템플릿을 로드합니다. 먼저 overview.md를 읽고, 로봇 유형과 통신 인터페이스, 적용 표준에 따라 ssdf.md, supply-chain.md, iec62443.md, cyber-resilience.md, wireless.md 중 필요한 파일을 선택합니다.


시큐어코딩 분기 시

references/secure-coding/overview.md에서 카테고리/CWE 매핑을 로드한 후, templates/secure-coding/javascript.md 또는 templates/secure-coding/python.md로 언어별 체크리스트를 실행합니다. 기타 언어는 references/secure-coding/pseudocode.md를 사용합니다.

우선순위: 긴급 (8항목) → 높음 (13항목) → 보통 (25항목). 긴급 CWE가 발견되면 배포를 차단합니다.


제로트러스트 분기 시

references/zero-trust/에서 아키텍처 참조와 성숙도 모델을, templates/zero-trust/에서 핵심요소별 체크리스트를 로드합니다. templates/zero-trust/overview.md부터 시작하여 시스템 맥락에 맞는 핵심요소를 선택합니다. OT/ICS 환경이 감지되면 templates/zero-trust/ot-environment.md도 로드합니다.

주제reference 파일
개요templates/zero-trust/overview.md
식별자 및 디바이스templates/zero-trust/identity-device.md
네트워크 및 시스템templates/zero-trust/network-system.md
애플리케이션 및 데이터templates/zero-trust/app-data.md
가시성 및 자동화templates/zero-trust/visibility-automation.md
OT/ICS 환경templates/zero-trust/ot-environment.md
ZT 아키텍처 참조references/zero-trust/overview.md
성숙도 모델 상세references/zero-trust/maturity-model.md
OT 배포 가이드references/zero-trust/ot-guide.md

8개 핵심요소, ~396개 항목, 4단계 성숙도. 표준: KISA 제로트러스트 가이드라인 2.0, NIST SP 800-207, CISA ZT Maturity Model.


중요 규칙

  • 긴급 심각도 항목은 절대 건너뛰지 마세요
  • 수정을 위한 구체적인 파일 경로와 명령어를 제공하세요
  • 통과율이 60% 미만이면 배포를 강력히 권고하지 않습니다

© cdppcorp, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 74 other files (scripts, references) in skills-ko/kesekit-check-ko of cdppcorp/KESE-KIT.

  • SKILL.md
  • references/ai-security/overview.md
  • references/ai-security/service-provider.md
  • references/ai-security/user-guide.md
  • references/secure-coding/overview.md
  • references/secure-coding/pseudocode.md
  • references/space-security/overview.md
  • references/space-security/supply-chain.md
  • references/zero-trust/maturity-model.md
  • references/zero-trust/ot-guide.md
  • references/zero-trust/overview.md
  • scripts/ai-security/api-security-check.md
  • scripts/ai-security/data-pipeline-check.md
  • scripts/ai-security/model-security-check.md
  • … and 61 more

Open the folder on GitHubat commit cd118f9

Compare with similar skills

Kesekit Check Ko next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kesekit Check Ko compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kesekit Check Ko this skillcdppcorp/KESE-KIT360—~956Automated safety check: PassMIT
CodeQL Security Scantrailofbits/skills7.5k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Skylosduriantaco/skylos844—~581Automated safety check: PassApache-2.0
Security Verification Gatefengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT
Skylos Securityduriantaco/skylos844—~545Automated safety check: PassApache-2.0
npm Supply Chain Checkmajiayu000/spellbook287—~1.5kAutomated safety check: PassMIT

Similar skills

  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.5k GitHub stars~4.6k tokensUpdated today
    SecurityAuto-check: notes
  • Skylos

    duriantaco/skylos

    Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

    844 GitHub stars~581 tokensUpdated today
    SecurityAuto-check passed
  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 25 days ago
    SecurityAuto-check: notes
  • Skylos Security

    duriantaco/skylos

    Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.

    844 GitHub stars~545 tokensUpdated today
    SecurityAuto-check passed
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    287 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Analysis

    microsoft/haste

    Official

    Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste.

    107 GitHub stars~1k tokensUpdated today
    SecurityAuto-check passed

More from cdppcorp/KESE-KIT

All 8 skills in this repo
  • Kesekit Check

    cdppcorp/KESE-KIT

    Run a pre-deployment security compliance checklist based on KISA guidelines.

    360 GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Kesekit Fix

    cdppcorp/KESE-KIT

    Auto-fix security vulnerabilities found in CII, AI, robot, space, and supply chain systems.

    360 GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Kesekit Fix Ko

    cdppcorp/KESE-KIT

    보안 취약점 자동 수정 및 하드닝 스크립트를 생성합니다. An agent skill from cdppcorp/KESE-KIT.

    360 GitHub stars~1k tokensUpdated 6 mo ago
    Auto-check passed
  • Kesekit Guide

    cdppcorp/KESE-KIT

    Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot).

    360 GitHub stars~1.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Kesekit Guide Ko

    cdppcorp/KESE-KIT

    AI 도구(Claude, ChatGPT, Cursor, Copilot)용 시큐어 코딩 프롬프트와 가이드를 생성합니다.

    360 GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Kesekit Start

    cdppcorp/KESE-KIT

    Run a security vulnerability assessment based on KISA guidelines.

    360 GitHub stars~2.3k tokensUpdated 6 mo ago
    Auto-check passed

Categories

Questions about Kesekit Check Ko

What does Kesekit Check Ko do?

KISA 가이드라인 기반 배포 전 보안 컴플라이언스 체크리스트를 실행합니다. An agent skill from cdppcorp/KESE-KIT. Kesekit Check Ko is an agent skill from cdppcorp/KESE-KIT. KISA 가이드라인 기반 배포 전 보안 컴플라이언스 체크리스트를 실행합니다.

When should I use Kesekit Check Ko?

Kesekit Check Ko fits situations like: security work in your project.

How do I install Kesekit Check Ko in Claude Code?

Run `npx skills add cdppcorp/KESE-KIT --skill kesekit-check-ko -a claude-code`. Or copy the skill folder (skills-ko/kesekit-check-ko in cdppcorp/KESE-KIT) into .claude/skills/kesekit-check-ko in your project. Claude Code loads it when a task matches its description.

How do I install Kesekit Check Ko in Codex?

Run `npx skills add cdppcorp/KESE-KIT --skill kesekit-check-ko -a codex`. Or copy the skill folder (skills-ko/kesekit-check-ko in cdppcorp/KESE-KIT) into .agents/skills/kesekit-check-ko in your project. Codex loads it when a task matches its description.

Can I use Kesekit Check Ko in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdppcorp/KESE-KIT --skill kesekit-check-ko -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kesekit-check-ko, .gemini/skills/kesekit-check-ko, .github/skills/kesekit-check-ko and .opencode/skills/kesekit-check-ko in your project.

What does Kesekit Check Ko need to run?

SKILL.md names no scripts, command-line tools or credentials: Kesekit Check Ko is instructions for the agent only. Our summary lists: Python 3.

Does Kesekit Check Ko access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kesekit Check Ko safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Kesekit Check Ko use?

Kesekit Check Ko is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kesekit Check Ko use?

About 956 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.

What are the alternatives to Kesekit Check Ko?

Skills that share tags, products or a category with Kesekit Check Ko: CodeQL Security Scan (trailofbits/skills, 7.5k stars), Skylos (duriantaco/skylos, 844 stars), Security Verification Gate (fengshao1227/ccg-workflow, 5.9k stars) and Skylos Security (duriantaco/skylos, 844 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kesekit Check Ko?

cdppcorp (a GitHub organization) maintains it in cdppcorp/KESE-KIT, which has 360 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on April 9, 2026.

Source: cdppcorp/KESE-KIT on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.