Agent skill

Kesekit Start Ko

by cdppcorp in cdppcorp/KESE-KIT

KISA 기반 보안 취약점 분석평가를 수행합니다. An agent skill from cdppcorp/KESE-KIT.

MITAuto-check passedSecurity

Install Kesekit Start Ko

skills CLI
$ npx skills add cdppcorp/KESE-KIT --skill kesekit-start-ko -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cdppcorp/KESE-KIT kesekit-start-ko --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cdppcorp/KESE-KIT.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills-ko/kesekit-start-ko .claude/skills/kesekit-start-ko && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kesekit-start-ko
GitHub stars
361
Token cost
~1.5k tokens
SKILL.md length
637 words
Files
75 (incl. scripts, references)
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

KISA 기반 보안 취약점 분석평가를 수행합니다. An agent skill from cdppcorp/KESE-KIT.

  • Works in 6 steps: 계획 및 설계 → 데이터 수집 및 준비 → 모델 개발 → …
  • Security work in your project
  • SKILL.md covers 가이드라인 선택, CII 분기 시, AI 보안 분기 시 and 로봇 보안 분기 시, plus 4 more sections

What it does

Kesekit Start Ko is an agent skill from cdppcorp/KESE-KIT. KISA 기반 보안 취약점 분석평가를 수행합니다. 주요정보통신기반시설(CII) 기술/관리/물리 취약점(560항목), AI 보안 안내서, 로봇 보안 체크리스트, 우주 보안(위성/GSaaS/공급망 53항목), 제로트러스트(8개 핵심요소, ~396항목) 평가를 지원합니다. "보안 점검", "취약점 분석", "기반시설 감사", "KISA 점검", "보안 평가", "AI 보안 점검", "로봇 보안 평가", "우주 보안 평가", "위성 보안", "제로트러스트", "ZTA", "ZTNA" 시 사용하세요.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 81 other files, including scripts and reference files (for example `references/ai-security/overview.md`, `references/ai-security/service-provider.md` and `references/ai-security/user-guide.md`).

It sits in Security. The repository describes itself as: KISA 주요정보통신기반시설 기술적 취약점 분석 평가방법 상세가이드 기반 Skills. The licence is MIT.

When your agent uses it

  • Security work in your project

Example prompts

  • “KISA 점검”
  • “AI 보안 점검”
  • “/kesekit-start-ko”

Requirements

  • Python 3
  • Node.js

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. 계획 및 설계
  2. 데이터 수집 및 준비
  3. 모델 개발
  4. 모델 배포
  5. 모니터링 및 유지보수
  6. 파기

What it can do on your machine

Read from SKILL.md and the folder at commit cd118f9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/, which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kesekit Start Ko loads about 1.5k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 74 tokens; SKILL.md has 637 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~17k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from cdppcorp/KESE-KIT at commit cd118f9, republished under its MIT licence (© cdppcorp). 637 words, ~1,490 tokens.

Download SKILL.mdSave it as .claude/skills/kesekit-start-ko/SKILL.md (or your agent's skills folder). This skill also uses 74 other files; get the full folder from GitHub.
name
kesekit-start-ko
description
KISA 기반 보안 취약점 분석평가를 수행합니다. 주요정보통신기반시설(CII) 기술/관리/물리 취약점(560항목), AI 보안 안내서, 로봇 보안 체크리스트, 우주 보안(위성/GSaaS/공급망 53항목), 제로트러스트(8개 핵심요소, ~396항목) 평가를 지원합니다. "보안 점검", "취약점 분석", "기반시설 감사", "KISA 점검", "보안 평가", "AI 보안 점검", "로봇 보안 평가", "우주 보안 평가", "위성 보안", "제로트러스트", "ZTA", "ZTNA" 시 사용하세요.

KESE 보안 취약점 분석평가

KISA 가이드라인에 따른 보안 취약점 분석평가를 수행합니다. 사용자의 환경과 목적에 맞는 가이드라인을 자동으로 선택하여 평가를 진행합니다.

가이드라인 선택

사용자에게 어떤 분야의 보안 점검을 원하는지 확인합니다. 명확하지 않으면 아래 목록을 보여주고 선택하게 합니다.

사용 가능한 가이드라인
#가이드라인설명항목 수
1주요정보통신기반시설(CII)기술적(424)+관리적(127)+물리적(18) 취약점~560
2AI 보안AI 개발자/서비스제공자/이용자 보안 요구사항~54
3로봇 보안산업용/서비스용/의료용 로봇 보안 체크리스트 (11개 카테고리)~103
4우주 보안위성/GSaaS/공급망 체크리스트 (12개 분야)53
5시큐어코딩JavaScript/Python 시큐어코딩 (7개 카테고리, 46 CWE)46
6제로트러스트제로트러스트 성숙도 평가 (8개 핵심요소, 4단계 성숙도)~396
자동 판별 기준
  • 서버, 네트워크, 데이터베이스, 웹 서비스, 방화벽 등 → CII
  • AI 모델, LLM, 생성형 AI, 머신러닝, 프롬프트 등 → AI 보안
  • 로봇, 산업용 로봇, 서비스 로봇, 의료용 로봇, ROS, PLC 등 → 로봇 보안
  • 위성, 지상국, GSaaS, 우주 시스템, GNSS, VSAT, LEO 군집, 우주 공급망 → 우주 보안
  • JavaScript, Python, 웹 애플리케이션 코드, 시큐어코딩, CWE, OWASP → 시큐어코딩
  • Zero Trust, ZTA, ZTNA, 제로트러스트, 마이크로세그멘테이션, microsegmentation, SDP, SASE, PEP/PDP, never trust always verify → 제로트러스트
  • 클라우드, 가상화 → 맥락에 따라 CII 또는 AI 보안

CII 분기 시

templates/cii/ 디렉터리에서 대상 시스템에 해당하는 평가 템플릿 파일을 읽어 평가를 수행합니다. 점검/수정 스크립트는 scripts/cii/에 있습니다.

1단계: 환경 탐지

자동 탐지 또는 사용자 질문으로 대상 시스템을 파악합니다:

시스템reference 파일항목 수
Unix/Linux 서버templates/cii/unix.md67
Windows 서버templates/cii/windows.md64
웹 서비스templates/cii/web-service.md26
보안 장비templates/cii/security-equip.md23
네트워크 장비templates/cii/network.md38
제어시스템templates/cii/control-system.md46
PCtemplates/cii/pc.md18
DBMStemplates/cii/database.md26
이동통신templates/cii/mobile.md4
Web Applicationtemplates/cii/webapp.md21
가상화 장비templates/cii/virtualization.md25
클라우드templates/cii/cloud.md19
관리적 취약점templates/cii/admin.md127
물리적 취약점templates/cii/physical.md18
2단계: 취약점 분석

해당 reference 파일을 Read로 로드한 후, 각 항목에 대해 점검합니다.

3단계: 보고서 생성
reports/kese/
├── summary.md          ← 전체 평가 요약
├── technical/          ← 시스템별 기술적 취약점 결과
├── administrative/     ← 관리적 취약점 결과
└── physical/           ← 물리적 취약점 결과
판단 기준
판단설명
양호보안 설정이 적절히 적용됨
부분이행일부 구현되었으나 개선 필요
취약보안 취약점 존재
해당없음해당 환경에 적용 불가

AI 보안 분기 시

references/ai-security/ 디렉터리에서 대상에 해당하는 reference를 읽어 평가를 수행합니다.

1단계: 대상 확인
대상reference 파일
전체 개요references/ai-security/overview.md
AI 개발자templates/ai-security/developer.md
AI 서비스 제공자references/ai-security/service-provider.md
AI 이용자references/ai-security/user-guide.md
2단계: 생명주기별 평가

AI 보안은 6단계 생명주기에 따라 점검합니다:

  1. 계획 및 설계
  2. 데이터 수집 및 준비
  3. 모델 개발
  4. 모델 배포
  5. 모니터링 및 유지보수
  6. 파기
3단계: 보고서 생성
reports/ai-security/
├── summary.md          ← 전체 평가 요약
├── developer.md        ← 개발자 보안 검증 결과
├── service-provider.md ← 서비스 제공자 검증 결과
└── user-checklist.md   ← 이용자 체크리스트 결과

로봇 보안 분기 시

templates/robot-security/ 디렉터리에서 해당 템플릿을 읽어 평가를 수행합니다.

Show full SKILL.md (267 more words)Show less
1단계: 대상 확인
대상reference 파일
전체 개요templates/robot-security/overview.md
SSDF (보안 SW 개발)templates/robot-security/ssdf.md
공급망 보안templates/robot-security/supply-chain.md
IEC 62443 기반 (IA, UC, SI, DP, DFR, ER, RA)templates/robot-security/iec62443.md
사이버 복원력templates/robot-security/cyber-resilience.md
무선 보안templates/robot-security/wireless.md
2단계: 카테고리별 평가

11개 카테고리, 총 ~103개 체크리스트 항목을 점검합니다.

3단계: 보고서 생성
reports/robot-security/
├── summary.md          ← 전체 평가 요약
├── ssdf.md             ← SSDF 19항목 결과
├── supply-chain.md     ← 공급망 7항목 결과
├── iec62443.md         ← IEC 62443 50항목 결과
├── cyber-resilience.md ← 사이버 복원력 13항목 결과
└── wireless.md         ← 무선 보안 14항목 결과

우선순위

긴급 (즉시 조치)
  • 계정 관리 취약점, 미패치 취약점, 인젝션, 민감 데이터 미암호화
높음 (일정 내 조치)
  • 설정 취약점, 보안 헤더 누락, 불완전한 로깅
보통 (개선 권고)
  • 하드닝 권고, 문서화 부족

시큐어코딩 분기 시

references/secure-coding/에서 개요와 의사 코드 패턴을, templates/secure-coding/에서 언어별 평가 템플릿을 읽어 평가를 수행합니다.

주제reference 파일
개요 (7개 카테고리, 49 CWE)references/secure-coding/overview.md
의사 코드 (46항목, 언어 무관)references/secure-coding/pseudocode.md
JavaScript (Express.js, Node.js, Sequelize)templates/secure-coding/javascript.md
Python (Django, Flask, SQLAlchemy)templates/secure-coding/python.md
판단 기준
  • 양호: 시큐어 코딩 패턴이 올바르게 적용됨
  • 부분이행: 패턴이 부분적으로 적용됨, 개선 필요
  • 취약: 취약한 패턴 감지됨 (UNSAFE 코드 존재)
  • 해당없음: 코드베이스에 해당 없음

제로트러스트 분기 시

references/zero-trust/에서 아키텍처 개요와 성숙도 모델을, templates/zero-trust/에서 핵심요소별 평가 체크리스트를 읽어 평가를 수행합니다.

주제reference 파일
개요templates/zero-trust/overview.md
식별자 및 디바이스templates/zero-trust/identity-device.md
네트워크 및 시스템templates/zero-trust/network-system.md
애플리케이션 및 데이터templates/zero-trust/app-data.md
가시성 및 자동화templates/zero-trust/visibility-automation.md
OT/ICS 환경templates/zero-trust/ot-environment.md
ZT 아키텍처 참조references/zero-trust/overview.md
성숙도 모델 상세references/zero-trust/maturity-model.md
OT 배포 가이드references/zero-trust/ot-guide.md

8개 핵심요소, ~396개 항목, 4단계 성숙도. 표준: KISA 제로트러스트 가이드라인 2.0, NIST SP 800-207, CISA ZT Maturity Model.

평가 흐름
  1. 목표 성숙도 수준 결정 (전통적/기본/고도화/최적화)
  2. 시스템 맥락에 따른 관련 핵심요소 선택
  3. OT/ICS 환경이 감지되면 ot-environment.md도 로드
  4. 목표 성숙도 이하의 항목을 평가
  5. 갭 분석 보고서 생성

참고사항

  • 평가 중 파일을 수정하지 마세요 — 읽기 전용입니다
  • 해당 기술이 환경에 없는 경우 해당없음으로 표시하세요
  • 발견된 각 취약점에 대해 구체적인 조치 방안을 제시하세요

© cdppcorp, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 74 other files (scripts, references) in skills-ko/kesekit-start-ko of cdppcorp/KESE-KIT.

  • SKILL.md
  • references/ai-security/overview.md
  • references/ai-security/service-provider.md
  • references/ai-security/user-guide.md
  • references/secure-coding/overview.md
  • references/secure-coding/pseudocode.md
  • references/space-security/overview.md
  • references/space-security/supply-chain.md
  • references/zero-trust/maturity-model.md
  • references/zero-trust/ot-guide.md
  • references/zero-trust/overview.md
  • scripts/ai-security/api-security-check.md
  • scripts/ai-security/data-pipeline-check.md
  • scripts/ai-security/model-security-check.md
  • … and 61 more

Open the folder on GitHubat commit cd118f9

Compare with similar skills

Kesekit Start Ko next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kesekit Start Ko compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kesekit Start Ko this skillcdppcorp/KESE-KIT361—~1.5kAutomated safety check: PassMIT
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from cdppcorp/KESE-KIT

All 8 skills in this repo
  • Kesekit Check

    cdppcorp/KESE-KIT

    Run a pre-deployment security compliance checklist based on KISA guidelines.

    361 GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Kesekit Check Ko

    cdppcorp/KESE-KIT

    KISA 가이드라인 기반 배포 전 보안 컴플라이언스 체크리스트를 실행합니다. An agent skill from cdppcorp/KESE-KIT.

    361 GitHub stars~956 tokensUpdated 6 mo ago
    Auto-check passed
  • Kesekit Fix

    cdppcorp/KESE-KIT

    Auto-fix security vulnerabilities found in CII, AI, robot, space, and supply chain systems.

    361 GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • Kesekit Fix Ko

    cdppcorp/KESE-KIT

    보안 취약점 자동 수정 및 하드닝 스크립트를 생성합니다. An agent skill from cdppcorp/KESE-KIT.

    361 GitHub stars~1k tokensUpdated 6 mo ago
    Auto-check passed
  • Kesekit Guide

    cdppcorp/KESE-KIT

    Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot).

    361 GitHub stars~1.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Kesekit Guide Ko

    cdppcorp/KESE-KIT

    AI 도구(Claude, ChatGPT, Cursor, Copilot)용 시큐어 코딩 프롬프트와 가이드를 생성합니다.

    361 GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed

Categories

Questions about Kesekit Start Ko

What does Kesekit Start Ko do?

KISA 기반 보안 취약점 분석평가를 수행합니다. An agent skill from cdppcorp/KESE-KIT. Kesekit Start Ko is an agent skill from cdppcorp/KESE-KIT. KISA 기반 보안 취약점 분석평가를 수행합니다.

When should I use Kesekit Start Ko?

Kesekit Start Ko fits situations like: security work in your project.

How do I install Kesekit Start Ko in Claude Code?

Run `npx skills add cdppcorp/KESE-KIT --skill kesekit-start-ko -a claude-code`. Or copy the skill folder (skills-ko/kesekit-start-ko in cdppcorp/KESE-KIT) into .claude/skills/kesekit-start-ko in your project. Claude Code loads it when a task matches its description.

How do I install Kesekit Start Ko in Codex?

Run `npx skills add cdppcorp/KESE-KIT --skill kesekit-start-ko -a codex`. Or copy the skill folder (skills-ko/kesekit-start-ko in cdppcorp/KESE-KIT) into .agents/skills/kesekit-start-ko in your project. Codex loads it when a task matches its description.

Can I use Kesekit Start Ko in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdppcorp/KESE-KIT --skill kesekit-start-ko -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kesekit-start-ko, .gemini/skills/kesekit-start-ko, .github/skills/kesekit-start-ko and .opencode/skills/kesekit-start-ko in your project.

What does Kesekit Start Ko need to run?

SKILL.md names no scripts, command-line tools or credentials: Kesekit Start Ko is instructions for the agent only. Our summary lists: Python 3; Node.js.

Does Kesekit Start Ko access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kesekit Start Ko safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Kesekit Start Ko use?

Kesekit Start Ko is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kesekit Start Ko use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.

What are the alternatives to Kesekit Start Ko?

Skills that share tags, products or a category with Kesekit Start Ko: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kesekit Start Ko?

cdppcorp (a GitHub organization) maintains it in cdppcorp/KESE-KIT, which has 361 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on April 9, 2026.

Source: cdppcorp/KESE-KIT on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.