Agent skill

Security Dashboard

by Community-Access in Community-Access/accessibility-agents

Triage Dependabot, code scanning and secret scanning alerts.

MITAuto-check passedFrontend & Design

Install Security Dashboard

skills CLI
$ npx skills add Community-Access/accessibility-agents --skill security-dashboard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Community-Access/accessibility-agents security-dashboard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Community-Access/accessibility-agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-dashboard .claude/skills/security-dashboard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-dashboard
GitHub stars
422
Token cost
~943 tokens
SKILL.md length
431 words
Files
2
Skills in repo
108
Repo updated
First seen
Licence
MIT

At a glance

Triage Dependabot, code scanning and secret scanning alerts.

  • Works in 5 steps: List Alerts — All alerts with severity,… → Alert Details — CVE/GHSA ID, CVSS score,… → Dismiss Alerts — With reason and… → …
  • Tasks that involve Dependency management
  • SKILL.md covers Security Dashboard Agent, Why This Agent Exists, Core Capabilities and Workflow, plus 2 more sections
  • Calls gh and node

What it does

Security Dashboard is an agent skill from Community-Access/accessibility-agents. Triage Dependabot, code scanning and secret scanning alerts.

Its SKILL.md is about 940 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Frontend & Design, covering Dependency management, Secrets management and Accessibility. It works with GitHub. The repository describes itself as: Accessibility review agents for Claude Code, GitHub Copilot, and Claude Desktop. Eleven specialists that enforce WCAG 2.2 AA compliance so AI coding tools stop generating… The licence is MIT.

When your agent uses it

  • Tasks that involve Dependency management
  • Tasks that involve Secrets management
  • Tasks that involve Accessibility

Example prompts

  • “/security-dashboard”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. List Alerts — All alerts with severity, package, ecosystem, vulnerable version range, and patched version.
  2. Alert Details — CVE/GHSA ID, CVSS score, description, affected versions, fix available, and related PR.
  3. Dismiss Alerts — With reason and optional comment.
  4. Fix PRs — List Dependabot-generated fix PRs and their merge status.
  5. Dependabot Config — Show and suggest improvements to dependabot.yml.

What it can do on your machine

Read from SKILL.md and the folder at commit decf6ba. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Dashboard loads about 943 tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 431 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~943

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Community-Access/accessibility-agents at commit decf6ba, republished under its MIT licence (© Community-Access). 431 words, ~943 tokens.

Download SKILL.mdSave it as .claude/skills/security-dashboard/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
security-dashboard
description
Triage Dependabot, code scanning and secret scanning alerts.
license
MIT
disable-model-invocation
true
metadata.tier
specialist
metadata.domain
github
metadata.output
report
metadata.effort
medium
metadata.title
Security Dashboard

Security Dashboard Agent

Shared instructions

Skills: github-workflow-standards, github-scanning

You are the Security Dashboard. You give screen reader users and keyboard-only users full control over GitHub's security features — Dependabot alerts, code scanning results, and secret scanning alerts — whose web UI uses color-coded severity badges, focus-trapping dismissal modals, and visually-overlaid code annotations that are largely inaccessible to assistive technology.

Why This Agent Exists

GitHub's security dashboards present severe accessibility barriers:

  • Severity badges are conveyed by color alone with inconsistent aria-labels
  • Dismissal modals open without moving focus
  • Code scanning annotations are visually overlaid but not semantically linked to source lines
  • Secret scanning "reveal" toggles are not consistently keyboard-accessible
  • Bulk operations use custom checkboxes that do not follow the checkbox ARIA pattern

This agent bypasses all of that by working directly through the GitHub REST API.

Core Capabilities

Dependabot Alerts
  1. List Alerts — All alerts with severity, package, ecosystem, vulnerable version range, and patched version.
  2. Alert Details — CVE/GHSA ID, CVSS score, description, affected versions, fix available, and related PR.
  3. Dismiss Alerts — With reason and optional comment.
  4. Fix PRs — List Dependabot-generated fix PRs and their merge status.
  5. Dependabot Config — Show and suggest improvements to dependabot.yml.
Code Scanning
  1. List Results — Alerts with rule ID, severity, description, file location, and tool.
  2. Alert Details — Specific code location, rule description, and recommended fix.
  3. Dismiss Results — With reason (false_positive, used_in_tests, won't_fix).
Secret Scanning
  1. List Secrets — Detected secrets with type, location, and resolution status.
  2. Resolve Secrets — Mark as false_positive, revoked, used_in_tests, or won't_fix.
Show full SKILL.md (180 more words)Show less
Cross-Cutting
  1. Security Overview — Unified summary across all three alert types with severity breakdown.
  2. Priority Triage — Auto-prioritize by CVSS score, exploitability, and fix availability.
  3. Aging Report — Flag alerts open longer than threshold.

Workflow

  1. Authenticate — Identify the current user via gh api user.
  2. Detect context — Infer the repo from the workspace.
  3. Scan — Pull all three alert types. Generate a unified security overview.
  4. Triage — Auto-prioritize by severity, exploitability, and fix availability.
  5. Act — Dismiss, reopen, or escalate alerts via API.
  6. Report — Save a structured security report to the workspace.

Boundaries

  • You read and manage security alerts only — you do not modify source code
  • You never present severity using color alone — always use text labels
  • You never instruct users to "click" anything in the web UI
  • All output must be navigable by screen reader

Output contract

Collect findings as JSON from each specialist you dispatch, write them to .a11y-history/<timestamp>/, then render the report with node skills/a11y-core/scripts/render-report.mjs. Do not type the report by hand.

Shared rules, dispatch contract and schemas: skills/a11y-core/SKILL.md. Authoritative specifications for this skill: skills/a11y-core/references/sources.md.

© Community-Access, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/security-dashboard of Community-Access/accessibility-agents.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit decf6ba

Compare with similar skills

Security Dashboard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Dashboard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Dashboard this skillCommunity-Access/accessibility-agents422—~943Automated safety check: PassMIT
Sicurezza GitHubccplugins/awesome-claude-code-plugins968—~486Automated safety check: NotesApache-2.0
Triaging Security Findingsbitwarden/ai-plugins154—~2.2kAutomated safety check: PassCustom licence
OpenClaw Design Auditopenclaw/clawhub9.5k—~498Automated safety check: PassMIT
Triage Codeqlnetdata/netdata81k—~1.8kAutomated safety check: NotesGPL-3.0
Implementing GitHub Advanced Security For Code Scanningmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0

Similar skills

  • Sicurezza GitHub

    ccplugins/awesome-claude-code-plugins

    Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot.

    968 GitHub stars~486 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Triaging Security Findings

    bitwarden/ai-plugins

    Official

    This skill should be used when the user asks to "triage security findings", "fix an Aikido finding", "review Aikido issues", "dismiss a false positive", "check SAST/IaC alerts", or needs to work…

    154 GitHub stars~2.2k tokensUpdated today
    SecurityAuto-check passed
  • OpenClaw Design Audit

    openclaw/clawhub

    Audits OpenClaw frontend code and rendered pages for token misuse, reimplemented primitives, accessibility and responsive defects and off-brand copy, with an evidence-based report.

    9.5k GitHub stars~498 tokensUpdated today
    Frontend & DesignAuto-check passed
  • Triage Codeql

    netdata/netdata

    Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

    81k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Implementing GitHub Advanced Security For Code Scanning

    mukul975/Anthropic-Cybersecurity-Skills

    Configures GitHub Advanced Security (code scanning with CodeQL, secret scanning, dependency review, and Dependabot alerts) to perform automated static analysis and vulnerability detection across…

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed

More from Community-Access/accessibility-agents

All 108 skills in this repo
  • A11y Core

    Community-Access/accessibility-agents

    Shared contract for the Accessibility Agents skills - dispatch, findings schema, report rules.

    422 GitHub stars~1.2k tokensUpdated 14 days ago
    Auto-check passed
  • Kb Web Scanning

    Community-Access/accessibility-agents

    Reference data, not a reviewer. An agent skill from Community-Access/accessibility-agents.

    422 GitHub stars~1.2k tokensUpdated 14 days ago
    Auto-check passed
  • Accessibility Lead

    Community-Access/accessibility-agents

    Web UI accessibility lead. An agent skill from Community-Access/accessibility-agents.

    422 GitHub stars~932 tokensUpdated 14 days ago
    Auto-check passed
  • Alt Text Headings

    Community-Access/accessibility-agents

    Alt text, SVGs, figures, charts, heading order, page titles and landmarks.

    422 GitHub stars~1.5k tokensUpdated 14 days ago
    Auto-check passed
  • Aria Specialist

    Community-Access/accessibility-agents

    ARIA roles, states and properties for custom widgets and dynamic content.

    422 GitHub stars~1.6k tokensUpdated 14 days ago
    Auto-check passed
  • Cognitive Accessibility

    Community-Access/accessibility-agents

    Plain language, WCAG 2.2 cognitive criteria, COGA guidance and auth UX.

    422 GitHub stars~1.4k tokensUpdated 14 days ago
    Auto-check passed

Works with

Questions about Security Dashboard

What does Security Dashboard do?

Triage Dependabot, code scanning and secret scanning alerts. Security Dashboard is an agent skill from Community-Access/accessibility-agents. Triage Dependabot, code scanning and secret scanning alerts.

When should I use Security Dashboard?

Security Dashboard fits situations like: tasks that involve Dependency management; tasks that involve Secrets management; tasks that involve Accessibility.

How do I install Security Dashboard in Claude Code?

Run `npx skills add Community-Access/accessibility-agents --skill security-dashboard -a claude-code`. Or copy the skill folder (skills/security-dashboard in Community-Access/accessibility-agents) into .claude/skills/security-dashboard in your project. Claude Code loads it when a task matches its description.

How do I install Security Dashboard in Codex?

Run `npx skills add Community-Access/accessibility-agents --skill security-dashboard -a codex`. Or copy the skill folder (skills/security-dashboard in Community-Access/accessibility-agents) into .agents/skills/security-dashboard in your project. Codex loads it when a task matches its description.

Can I use Security Dashboard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Community-Access/accessibility-agents --skill security-dashboard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-dashboard, .gemini/skills/security-dashboard, .github/skills/security-dashboard and .opencode/skills/security-dashboard in your project.

What does Security Dashboard need to run?

Going by SKILL.md and its folder, Security Dashboard needs the command-line tools its instructions call (gh and node).

Does Security Dashboard access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Dashboard safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Dashboard use?

Security Dashboard is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Dashboard use?

About 943 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Dashboard?

Skills that share tags, products or a category with Security Dashboard: Sicurezza GitHub (ccplugins/awesome-claude-code-plugins, 968 stars), Triaging Security Findings (bitwarden/ai-plugins, 154 stars), OpenClaw Design Audit (openclaw/clawhub, 9.5k stars) and Triage Codeql (netdata/netdata, 81k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Dashboard?

Community-Access (a GitHub organization) maintains it in Community-Access/accessibility-agents, which has 422 GitHub stars. The repository holds 108 skills in this directory. The repository was last updated on September 23, 2026.

Source: Community-Access/accessibility-agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.