CodeQL Security Scan
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
KISA 가이드라인 기반 배포 전 보안 컴플라이언스 체크리스트를 실행합니다. An agent skill from cdppcorp/KESE-KIT.
$ npx skills add cdppcorp/KESE-KIT --skill kesekit-check-ko -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cdppcorp/KESE-KIT kesekit-check-ko --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cdppcorp/KESE-KIT.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills-ko/kesekit-check-ko .claude/skills/kesekit-check-ko && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "kesekit-check-ko" agent skill from https://github.com/cdppcorp/KESE-KIT/tree/main/skills-ko/kesekit-check-ko into .claude/skills/kesekit-check-ko/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kesekit-check-ko", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cdppcorp/KESE-KIT/tree/main/skills-ko/kesekit-check-koType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cdppcorp/KESE-KIT --skill kesekit-check-ko -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cdppcorp/KESE-KIT kesekit-check-ko --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdppcorp/KESE-KIT.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills-ko/kesekit-check-ko .agents/skills/kesekit-check-ko && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "kesekit-check-ko" agent skill from https://github.com/cdppcorp/KESE-KIT/tree/main/skills-ko/kesekit-check-ko into .agents/skills/kesekit-check-ko/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kesekit-check-ko", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cdppcorp/KESE-KIT --skill kesekit-check-ko -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cdppcorp/KESE-KIT kesekit-check-ko --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdppcorp/KESE-KIT.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills-ko/kesekit-check-ko .cursor/skills/kesekit-check-ko && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "kesekit-check-ko" agent skill from https://github.com/cdppcorp/KESE-KIT/tree/main/skills-ko/kesekit-check-ko into .cursor/skills/kesekit-check-ko/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kesekit-check-ko", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cdppcorp/KESE-KIT.git --path skills-ko/kesekit-check-ko--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cdppcorp/KESE-KIT --skill kesekit-check-ko -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cdppcorp/KESE-KIT kesekit-check-ko --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdppcorp/KESE-KIT.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills-ko/kesekit-check-ko .gemini/skills/kesekit-check-ko && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "kesekit-check-ko" agent skill from https://github.com/cdppcorp/KESE-KIT/tree/main/skills-ko/kesekit-check-ko into .gemini/skills/kesekit-check-ko/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kesekit-check-ko", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cdppcorp/KESE-KIT kesekit-check-koInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cdppcorp/KESE-KIT --skill kesekit-check-ko -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cdppcorp/KESE-KIT.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills-ko/kesekit-check-ko .github/skills/kesekit-check-ko && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "kesekit-check-ko" agent skill from https://github.com/cdppcorp/KESE-KIT/tree/main/skills-ko/kesekit-check-ko into .github/skills/kesekit-check-ko/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kesekit-check-ko", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cdppcorp/KESE-KIT --skill kesekit-check-ko -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cdppcorp/KESE-KIT kesekit-check-ko --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdppcorp/KESE-KIT.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills-ko/kesekit-check-ko .opencode/skills/kesekit-check-ko && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "kesekit-check-ko" agent skill from https://github.com/cdppcorp/KESE-KIT/tree/main/skills-ko/kesekit-check-ko into .opencode/skills/kesekit-check-ko/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kesekit-check-ko", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
kesekit-check-koKISA 가이드라인 기반 배포 전 보안 컴플라이언스 체크리스트를 실행합니다. An agent skill from cdppcorp/KESE-KIT.
Kesekit Check Ko is an agent skill from cdppcorp/KESE-KIT. KISA 가이드라인 기반 배포 전 보안 컴플라이언스 체크리스트를 실행합니다. CII 컴플라이언스(70항목), AI 보안 체크리스트, 로봇 보안 체크리스트, 우주 보안 체크리스트(12분야 53항목)를 지원합니다. "배포 전 점검", "컴플라이언스 체크", "보안 체크리스트", "우주 보안 점검", "위성 보안 체크" 시 사용하세요.
Its SKILL.md is about 960 tokens, which your agent loads only when the skill is triggered. The skill folder holds 81 other files, including scripts and reference files (for example `references/ai-security/overview.md`, `references/ai-security/service-provider.md` and `references/ai-security/user-guide.md`).
It sits in Security. It works with JavaScript and Python. The repository describes itself as: KISA 주요정보통신기반시설 기술적 취약점 분석 평가방법 상세가이드 기반 Skills. The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit cd118f9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/, which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Kesekit Check Ko loads about 956 tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 51 tokens; SKILL.md has 453 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from cdppcorp/KESE-KIT at commit cd118f9, republished under its MIT licence (© cdppcorp). 453 words, ~956 tokens.
.claude/skills/kesekit-check-ko/SKILL.md (or your agent's skills folder). This skill also uses 74 other files; get the full folder from GitHub.배포 전 보안 점검을 수행합니다. 사용자의 환경에 맞는 가이드라인을 자동 선택합니다.
| # | 가이드라인 | 설명 |
|---|---|---|
| 1 | CII 컴플라이언스 | 주요정보통신기반시설 배포 전 70항목 체크 |
| 2 | AI 보안 체크리스트 | AI 개발자/서비스제공자 보안 검증항목 체크 |
| 3 | 로봇 보안 체크리스트 | 로봇 시스템 11개 카테고리 103항목 체크 |
| 4 | 우주 보안 체크리스트 | 위성/GSaaS/공급망 12분야 53항목 체크 |
| 5 | 시큐어코딩 체크리스트 | JavaScript/Python 코드 리뷰 (7개 카테고리, 46 CWE) |
| 6 | 제로트러스트 체크리스트 | 제로트러스트 성숙도 평가 (8개 핵심요소, 4단계 성숙도, ~396항목) |
서버, 인프라, 웹 서비스 → CII / AI 모델, LLM, AI 서비스 → AI 보안 / 로봇, ROS/ROS2, 의료용 로봇, AMR/AGV → 로봇 보안 / 위성, 지상국, GSaaS, 우주 공급망 → 우주 보안 / JavaScript, Python, 웹 앱 코드 → 시큐어코딩 Zero Trust, ZTA, ZTNA, 제로트러스트, 마이크로세그멘테이션, microsegmentation, SDP, SASE, PEP/PDP, never trust always verify → 제로트러스트
대상 환경을 탐지한 후, 해당하는 템플릿 파일을 templates/cii/에서 로드하여 체크리스트를 실행합니다. 점검/수정 스크립트는 scripts/cii/에 있습니다. 템플릿 파일 목록은 start 스킬과 동일합니다.
============================================================
KESE CII 배포 준비 보고서
============================================================
프로젝트: [프로젝트명]
일시: [날짜]
요약: 전체 [N]항목 / 통과 [N] / 실패 [N] / 건너뜀 [N]
배포 결정: [승인 / 차단 / 조건부]
============================================================references/ai-security/ 및 templates/ai-security/ 디렉터리에서 대상에 해당하는 파일을 로드합니다.
templates/ai-security/developer.md를 로드하여 6단계 생명주기별 54개 검증항목을 점검합니다.
references/ai-security/service-provider.md를 로드하여 서비스 운영 관점의 보안 요구사항을 점검합니다.
references/ai-security/user-guide.md를 로드하여 7개 보안 수칙 이행 여부를 점검합니다.
templates/robot-security/ 디렉터리에서 관련 템플릿을 로드합니다. 먼저 overview.md를 읽고, 로봇 유형과 통신 인터페이스, 적용 표준에 따라 ssdf.md, supply-chain.md, iec62443.md, cyber-resilience.md, wireless.md 중 필요한 파일을 선택합니다.
references/secure-coding/overview.md에서 카테고리/CWE 매핑을 로드한 후, templates/secure-coding/javascript.md 또는 templates/secure-coding/python.md로 언어별 체크리스트를 실행합니다. 기타 언어는 references/secure-coding/pseudocode.md를 사용합니다.
우선순위: 긴급 (8항목) → 높음 (13항목) → 보통 (25항목). 긴급 CWE가 발견되면 배포를 차단합니다.
references/zero-trust/에서 아키텍처 참조와 성숙도 모델을, templates/zero-trust/에서 핵심요소별 체크리스트를 로드합니다. templates/zero-trust/overview.md부터 시작하여 시스템 맥락에 맞는 핵심요소를 선택합니다. OT/ICS 환경이 감지되면 templates/zero-trust/ot-environment.md도 로드합니다.
| 주제 | reference 파일 |
|---|---|
| 개요 | templates/zero-trust/overview.md |
| 식별자 및 디바이스 | templates/zero-trust/identity-device.md |
| 네트워크 및 시스템 | templates/zero-trust/network-system.md |
| 애플리케이션 및 데이터 | templates/zero-trust/app-data.md |
| 가시성 및 자동화 | templates/zero-trust/visibility-automation.md |
| OT/ICS 환경 | templates/zero-trust/ot-environment.md |
| ZT 아키텍처 참조 | references/zero-trust/overview.md |
| 성숙도 모델 상세 | references/zero-trust/maturity-model.md |
| OT 배포 가이드 | references/zero-trust/ot-guide.md |
8개 핵심요소, ~396개 항목, 4단계 성숙도. 표준: KISA 제로트러스트 가이드라인 2.0, NIST SP 800-207, CISA ZT Maturity Model.
© cdppcorp, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 74 other files (scripts, references) in skills-ko/kesekit-check-ko of cdppcorp/KESE-KIT.
Open the folder on GitHubat commit cd118f9
Kesekit Check Ko next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Kesekit Check Ko this skillcdppcorp/KESE-KIT | 360 | — | ~956 | Automated safety check: Pass | MIT | |
| CodeQL Security Scantrailofbits/skills | 7.5k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Skylosduriantaco/skylos | 844 | — | ~581 | Automated safety check: Pass | Apache-2.0 | |
| Security Verification Gatefengshao1227/ccg-workflow | 5.9k | — | ~621 | Automated safety check: Notes | MIT | |
| Skylos Securityduriantaco/skylos | 844 | — | ~545 | Automated safety check: Pass | Apache-2.0 | |
| npm Supply Chain Checkmajiayu000/spellbook | 287 | — | ~1.5k | Automated safety check: Pass | MIT |
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
duriantaco/skylos
Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.
fengshao1227/ccg-workflow
Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.
duriantaco/skylos
Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.
majiayu000/spellbook
Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.
microsoft/haste
Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste.
cdppcorp/KESE-KIT
Run a pre-deployment security compliance checklist based on KISA guidelines.
cdppcorp/KESE-KIT
Auto-fix security vulnerabilities found in CII, AI, robot, space, and supply chain systems.
cdppcorp/KESE-KIT
보안 취약점 자동 수정 및 하드닝 스크립트를 생성합니다. An agent skill from cdppcorp/KESE-KIT.
cdppcorp/KESE-KIT
Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot).
cdppcorp/KESE-KIT
AI 도구(Claude, ChatGPT, Cursor, Copilot)용 시큐어 코딩 프롬프트와 가이드를 생성합니다.
cdppcorp/KESE-KIT
Run a security vulnerability assessment based on KISA guidelines.
Works with
Categories
KISA 가이드라인 기반 배포 전 보안 컴플라이언스 체크리스트를 실행합니다. An agent skill from cdppcorp/KESE-KIT. Kesekit Check Ko is an agent skill from cdppcorp/KESE-KIT. KISA 가이드라인 기반 배포 전 보안 컴플라이언스 체크리스트를 실행합니다.
Kesekit Check Ko fits situations like: security work in your project.
Run `npx skills add cdppcorp/KESE-KIT --skill kesekit-check-ko -a claude-code`. Or copy the skill folder (skills-ko/kesekit-check-ko in cdppcorp/KESE-KIT) into .claude/skills/kesekit-check-ko in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cdppcorp/KESE-KIT --skill kesekit-check-ko -a codex`. Or copy the skill folder (skills-ko/kesekit-check-ko in cdppcorp/KESE-KIT) into .agents/skills/kesekit-check-ko in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdppcorp/KESE-KIT --skill kesekit-check-ko -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kesekit-check-ko, .gemini/skills/kesekit-check-ko, .github/skills/kesekit-check-ko and .opencode/skills/kesekit-check-ko in your project.
SKILL.md names no scripts, command-line tools or credentials: Kesekit Check Ko is instructions for the agent only. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Kesekit Check Ko is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 956 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Kesekit Check Ko: CodeQL Security Scan (trailofbits/skills, 7.5k stars), Skylos (duriantaco/skylos, 844 stars), Security Verification Gate (fengshao1227/ccg-workflow, 5.9k stars) and Skylos Security (duriantaco/skylos, 844 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cdppcorp (a GitHub organization) maintains it in cdppcorp/KESE-KIT, which has 360 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on April 9, 2026.
Source: cdppcorp/KESE-KIT on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.