Agent skill

Kesekit Start

by cdppcorp in cdppcorp/KESE-KIT

Run a security vulnerability assessment based on KISA guidelines.

MITAuto-check passedSecurity

Install Kesekit Start

skills CLI
$ npx skills add cdppcorp/KESE-KIT --skill kesekit-start -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cdppcorp/KESE-KIT kesekit-start --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cdppcorp/KESE-KIT.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kesekit-start .claude/skills/kesekit-start && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kesekit-start
GitHub stars
361
Token cost
~2.3k tokens
SKILL.md length
775 words
Files
82 (incl. scripts, references)
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Run a security vulnerability assessment based on KISA guidelines.

  • Works in 5 steps: Determine target maturity level… → Select relevant core elements based on… → If OT/ICS detected, also load… → …
  • Security assessment
  • SKILL.md covers Guideline Selection, CII Branch, AI Security Branch and Robot Security Branch, plus 5 more sections
  • Vulnerability scan

What it does

Kesekit Start is an agent skill from cdppcorp/KESE-KIT. Run a security vulnerability assessment based on KISA guidelines. Supports CII (560+ items), AI Security Guide, Robot Security (103 items), Space Security (satellite/GSaaS/supply chain, 12 domains, 53 items), Secure Coding (46 CWE), Zero Trust (~396 items), and SW Supply Chain Security (SBOM, 29 items). Use when "security assessment", "vulnerability scan", "CII audit", "KISA assessment", "AI security", "robot security", "space security", "satellite security", "GSaaS security", "zero trust", "ZTA", "ZTNA", "supply…

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 89 other files, including scripts and reference files (for example `references/ai-security/overview.md`, `references/ai-security/service-provider.md` and `references/ai-security/user-guide.md`).

It sits in Security, covering Supply chain security, Prompt injection and agent security and Secure coding. The repository describes itself as: KISA 주요정보통신기반시설 기술적 취약점 분석 평가방법 상세가이드 기반 Skills. The licence is MIT.

When your agent uses it

  • Security assessment
  • Vulnerability scan
  • KISA assessment
  • Satellite security

Example prompts

  • “security assessment”
  • “vulnerability scan”
  • “CII audit”
  • “/kesekit-start”

Requirements

  • Python 3
  • Node.js

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Determine target maturity level (Traditional/Initial/Advanced/Optimal)
  2. Select relevant core elements based on system context
  3. If OT/ICS detected, also load ot-environment.md
  4. Assess items at or below target maturity level
  5. Generate gap analysis report

What it can do on your machine

Read from SKILL.md and the folder at commit cd118f9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kesekit Start loads about 2.3k tokens when it runs, and up to ~19k if it reads all its reference files. Until then it costs about 141 tokens; SKILL.md has 775 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~141
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~19k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from cdppcorp/KESE-KIT at commit cd118f9, republished under its MIT licence (© cdppcorp). 775 words, ~2,270 tokens.

Download SKILL.mdSave it as .claude/skills/kesekit-start/SKILL.md (or your agent's skills folder). This skill also uses 81 other files; get the full folder from GitHub.
name
kesekit-start
description
Run a security vulnerability assessment based on KISA guidelines. Supports CII (560+ items), AI Security Guide, Robot Security (103 items), Space Security (satellite/GSaaS/supply chain, 12 domains, 53 items), Secure Coding (46 CWE), Zero Trust (~396 items), and SW Supply Chain Security (SBOM, 29 items). Use when "security assessment", "vulnerability scan", "CII audit", "KISA assessment", "AI security", "robot security", "space security", "satellite security", "GSaaS security", "zero trust", "ZTA", "ZTNA", "supply chain", "SBOM", "공급망", "C-SCRM".

KESE Security Vulnerability Assessment

Perform comprehensive security vulnerability assessment based on KISA guidelines. Automatically selects the appropriate guideline based on user context.

Guideline Selection

#GuidelineDescriptionItems
1CII (Critical Information Infrastructure)Technical(424)+Administrative(127)+Physical(18)~560
2AI SecurityAI Developer/Service Provider/User requirements~54
3Robot SecurityIndustrial/Service/Medical robot checklist (11 categories)~103
4Space SecuritySatellite/GSaaS/Supply chain checklist (12 domains)53
5Secure CodingJavaScript/Python secure coding (7 categories, 46 CWE)46
6Zero TrustZero Trust maturity assessment (8 elements, 4 maturity levels)~396
7SW Supply ChainSBOM-based supply chain security (5 phases, 29 items)29
Auto-detection
  • Servers, networks, databases, web services, firewalls → CII
  • AI models, LLM, generative AI, machine learning, prompts → AI Security
  • Robots, industrial robots, service robots, medical robots, ROS/ROS2, PLC-linked robot systems → Robot Security
  • Satellites, ground stations, GSaaS, space systems, GNSS, VSAT, LEO constellation, space supply chain → Space Security
  • JavaScript, Python, web application code, secure coding, CWE, OWASP → Secure Coding
  • Zero Trust, ZTA, ZTNA, 제로트러스트, 마이크로세그멘테이션, microsegmentation, SDP, SASE, PEP/PDP, never trust always verify → Zero Trust
  • SBOM, supply chain, 공급망, C-SCRM, SCA, CycloneDX, SPDX, npm audit, pip-audit, software bill of materials, 소프트웨어 공급망 → SW Supply Chain

CII Branch

Read the appropriate reference file from templates/cii/ based on the target system.

SystemReference FileItems
Unix/Linuxtemplates/cii/unix.md67
Windows Servertemplates/cii/windows.md64
Web Servicetemplates/cii/web-service.md26
Security Equipmenttemplates/cii/security-equip.md23
Network Equipmenttemplates/cii/network.md38
Control Systemtemplates/cii/control-system.md46
PCtemplates/cii/pc.md18
DBMStemplates/cii/database.md26
Mobiletemplates/cii/mobile.md4
Web Applicationtemplates/cii/webapp.md21
Virtualizationtemplates/cii/virtualization.md25
Cloudtemplates/cii/cloud.md19
Administrativetemplates/cii/admin.md127
Physicaltemplates/cii/physical.md18

Check commands available in scripts/cii/ directory.

Judgment Criteria
  • Pass: Security settings properly applied
  • Partial: Partially implemented, improvement needed
  • Fail: Vulnerability exists
  • N/A: Not applicable to the environment

AI Security Branch

Read from references/ai-security/ for overview and guidance, and templates/ai-security/ for assessment checklists.

TargetReference File
Overviewreferences/ai-security/overview.md
AI Developertemplates/ai-security/developer.md
Service Providerreferences/ai-security/service-provider.md
Userreferences/ai-security/user-guide.md

6-stage lifecycle: Planning → Data → Model Dev → Deploy → Monitoring → Decommission


Robot Security Branch

Read from templates/robot-security/ based on the target robot system or concern.

TopicReference File
Overviewtemplates/robot-security/overview.md
SSDF / secure software developmenttemplates/robot-security/ssdf.md
Supply chain securitytemplates/robot-security/supply-chain.md
IEC 62443 controls (IA, UC, SI, DP, DFR, ER, RA)templates/robot-security/iec62443.md
Cyber resiliencetemplates/robot-security/cyber-resilience.md
Wireless securitytemplates/robot-security/wireless.md

Assess the relevant categories for industrial, service, or medical robots and generate a dedicated reports/robot-security/ summary when robot security is selected.


Space Security Branch

Read from references/space-security/ for overview and supply chain guidance, and templates/space-security/ for assessment checklists.

TopicReference File
Overviewreferences/space-security/overview.md
Access Control & Authentication (AC, IA)templates/space-security/access-control.md
System & Communication Security (SC, SI)templates/space-security/system-security.md
Operations & Incident Response (SO, IR)templates/space-security/operations.md
Governance, Personnel, Physical, Risk, Contingency (PS, PE, RA, SG, CP)templates/space-security/governance.md
Supply Chain Management (SM) + Threat Scenariosreferences/space-security/supply-chain.md

12 domains, 53 items. Standards: CMMC, K-RMF, NIS2, ISMS-P. Generate reports in reports/space-security/.


Show full SKILL.md (318 more words)Show less

Secure Coding Branch

Read from references/secure-coding/ for overview and pseudo code patterns, and templates/secure-coding/ for language-specific assessment.

TopicReference File
Overview (7 categories, 49 CWE)references/secure-coding/overview.md
Pseudo Code (46 items, language-agnostic)references/secure-coding/pseudocode.md
JavaScript (Express.js, Node.js, Sequelize)templates/secure-coding/javascript.md
Python (Django, Flask, SQLAlchemy)templates/secure-coding/python.md
Judgment Criteria
  • Pass: Secure coding pattern applied correctly
  • Partial: Pattern partially applied, improvement needed
  • Fail: Vulnerable pattern detected (UNSAFE code present)
  • N/A: Not applicable to the codebase

Zero Trust Branch

Read from references/zero-trust/ for overview and maturity model, and templates/zero-trust/ for assessment checklists.

TopicReference File
Overviewtemplates/zero-trust/overview.md
Identity & Devicetemplates/zero-trust/identity-device.md
Network & Systemtemplates/zero-trust/network-system.md
Application & Datatemplates/zero-trust/app-data.md
Visibility & Automationtemplates/zero-trust/visibility-automation.md
OT/ICS Environmenttemplates/zero-trust/ot-environment.md
ZT Architecture Referencereferences/zero-trust/overview.md
Maturity Model Detailsreferences/zero-trust/maturity-model.md
OT Deployment Guidereferences/zero-trust/ot-guide.md

8 core elements, ~396 items across 4 maturity levels. Standards: KISA ZT Guideline 2.0, NIST SP 800-207, CISA ZT Maturity Model.

Assessment Flow
  1. Determine target maturity level (Traditional/Initial/Advanced/Optimal)
  2. Select relevant core elements based on system context
  3. If OT/ICS detected, also load ot-environment.md
  4. Assess items at or below target maturity level
  5. Generate gap analysis report

SW Supply Chain Branch

Read from references/supply-chain/ for overview and threat scenarios, and templates/supply-chain/ for assessment checklists. Use scripts/supply-chain/ for SBOM generation and vulnerability scanning commands.

TopicReference File
Overview (C-SCRM, SBOM, Regulations)references/supply-chain/overview.md
Assessment Overview (6 categories)templates/supply-chain/overview.md
Self-Assessment Checklist (29 items)templates/supply-chain/sbom-checklist.md
SBOM Generation Scriptsscripts/supply-chain/sbom-generate.md
Vulnerability Scanning Scriptsscripts/supply-chain/sbom-vuln-scan.md

5 phases: Design (5) → Development (11) → Supply (3) → Operations (7) → Maintenance (3). Standards: NIST SP 800-161r1 (C-SCRM), NIST SP 800-218 (SSDF), NTIA SBOM, NIS-SBOM.

Assessment Flow
  1. Start with references/supply-chain/overview.md for context
  2. Load templates/supply-chain/sbom-checklist.md for the 29-item checklist
  3. Assess each phase (Design → Development → Supply → Operations → Maintenance)
  4. Critical items (SC-10, SC-14, SC-15) must ALL pass
  5. Use scripts/supply-chain/sbom-generate.md for SBOM creation commands
  6. Use scripts/supply-chain/sbom-vuln-scan.md for vulnerability scanning

Notes

  • Do not modify files during assessment — read-only
  • Mark N/A for technologies not present
  • Provide specific remediation for each finding

© cdppcorp, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 81 other files (scripts, references) in skills/kesekit-start of cdppcorp/KESE-KIT.

  • SKILL.md
  • references/ai-security/overview.md
  • references/ai-security/service-provider.md
  • references/ai-security/user-guide.md
  • references/secure-coding/overview.md
  • references/secure-coding/pseudocode.md
  • references/space-security/overview.md
  • references/space-security/supply-chain.md
  • references/supply-chain/overview.md
  • references/zero-trust/maturity-model.md
  • references/zero-trust/ot-guide.md
  • references/zero-trust/overview.md
  • scripts/ai-security/api-security-check.md
  • … and 69 more

Open the folder on GitHubat commit cd118f9

Compare with similar skills

Kesekit Start next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kesekit Start compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kesekit Start this skillcdppcorp/KESE-KIT361—~2.3kAutomated safety check: PassMIT
Skill InspectorNVIDIA/SkillSpector20k1 repos~1.8kAutomated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Pre-Commit Security Scanzereight/gitlab-mcp2k1 repos~859Automated safety check: NotesMIT

Similar skills

  • Skill Inspector

    NVIDIA/SkillSpector

    Official

    Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

    20k GitHub starsUsed in 1 repo~1.8k tokens
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Pre-Commit Security Scan

    zereight/gitlab-mcp

    Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

    2k GitHub starsUsed in 1 repo~859 tokens
    SecurityAuto-check: notes
  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed

More from cdppcorp/KESE-KIT

All 8 skills in this repo
  • Kesekit Check

    cdppcorp/KESE-KIT

    Run a pre-deployment security compliance checklist based on KISA guidelines.

    361 GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Kesekit Check Ko

    cdppcorp/KESE-KIT

    KISA 가이드라인 기반 배포 전 보안 컴플라이언스 체크리스트를 실행합니다. An agent skill from cdppcorp/KESE-KIT.

    361 GitHub stars~956 tokensUpdated 6 mo ago
    Auto-check passed
  • Kesekit Fix

    cdppcorp/KESE-KIT

    Auto-fix security vulnerabilities found in CII, AI, robot, space, and supply chain systems.

    361 GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Kesekit Fix Ko

    cdppcorp/KESE-KIT

    보안 취약점 자동 수정 및 하드닝 스크립트를 생성합니다. An agent skill from cdppcorp/KESE-KIT.

    361 GitHub stars~1k tokensUpdated 6 mo ago
    Auto-check passed
  • Kesekit Guide

    cdppcorp/KESE-KIT

    Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot).

    361 GitHub stars~1.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Kesekit Guide Ko

    cdppcorp/KESE-KIT

    AI 도구(Claude, ChatGPT, Cursor, Copilot)용 시큐어 코딩 프롬프트와 가이드를 생성합니다.

    361 GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed

Categories

Questions about Kesekit Start

What does Kesekit Start do?

Run a security vulnerability assessment based on KISA guidelines. Kesekit Start is an agent skill from cdppcorp/KESE-KIT. Run a security vulnerability assessment based on KISA guidelines.

When should I use Kesekit Start?

Kesekit Start fits situations like: security assessment; vulnerability scan; KISA assessment; satellite security.

How do I install Kesekit Start in Claude Code?

Run `npx skills add cdppcorp/KESE-KIT --skill kesekit-start -a claude-code`. Or copy the skill folder (skills/kesekit-start in cdppcorp/KESE-KIT) into .claude/skills/kesekit-start in your project. Claude Code loads it when a task matches its description.

How do I install Kesekit Start in Codex?

Run `npx skills add cdppcorp/KESE-KIT --skill kesekit-start -a codex`. Or copy the skill folder (skills/kesekit-start in cdppcorp/KESE-KIT) into .agents/skills/kesekit-start in your project. Codex loads it when a task matches its description.

Can I use Kesekit Start in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdppcorp/KESE-KIT --skill kesekit-start -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kesekit-start, .gemini/skills/kesekit-start, .github/skills/kesekit-start and .opencode/skills/kesekit-start in your project.

What does Kesekit Start need to run?

SKILL.md names no scripts, command-line tools or credentials: Kesekit Start is instructions for the agent only. Our summary lists: Python 3; Node.js.

Does Kesekit Start access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kesekit Start safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Kesekit Start use?

Kesekit Start is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kesekit Start use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16k tokens, read only when the agent opens those files.

What are the alternatives to Kesekit Start?

Skills that share tags, products or a category with Kesekit Start: Skill Inspector (NVIDIA/SkillSpector, 20k stars), Skill Scanner (getsentry/skills, 1k stars), Forensify (alexgreensh/repo-forensics, 188 stars) and Security Audit (TheDecipherist/claude-code-mastery, 550 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kesekit Start?

cdppcorp (a GitHub organization) maintains it in cdppcorp/KESE-KIT, which has 361 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on April 9, 2026.

Source: cdppcorp/KESE-KIT on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.