Agent skill

Senior Security

by davila7 in davila7/claude-code-templates

Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing.

MITAuto-check: notesSecurity

Install Senior Security

skills CLI
$ npx skills add davila7/claude-code-templates --skill senior-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install davila7/claude-code-templates senior-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/davila7/claude-code-templates.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cli-tool/components/skills/development/senior-security .claude/skills/senior-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
senior-security
GitHub stars
32k
Used in
2 other repos
Token cost
~1.1k tokens
SKILL.md length
299 words
Files
7 (incl. scripts, references)
Skills in repo
477
Repo updated
First seen
Licence
MIT

At a glance

Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing.

  • Works in 6 steps: Threat Modeler → Security Auditor → Pentest Automator → …
  • Designing security architecture
  • SKILL.md covers Quick Start, Core Capabilities, Reference Documentation and Tech Stack, plus 5 more sections
  • Runs Python scripts from its folder; calls python, npm and pip

What it does

Senior Security is an agent skill from davila7/claude-code-templates. Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/cryptography_implementation.md`, `references/penetration_testing_guide.md` and `references/security_architecture_patterns.md`).

It sits in Security, covering Security review, Cryptography and Penetration testing. The repository describes itself as: CLI tool for configuring and monitoring Claude Code. The licence is MIT.

When your agent uses it

  • Designing security architecture
  • Conducting penetration tests
  • Implementing cryptography
  • Performing security audits

Example prompts

  • “/senior-security”

Requirements

  • Python 3
  • Node.js
  • Docker

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Threat Modeler
  2. Security Auditor
  3. Pentest Automator
  4. Setup and Configuration
  5. Run Quality Checks
  6. Implement Best Practices

What it can do on your machine

Read from SKILL.md and the folder at commit 14680ec. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • npm
    • pip
    • docker
    • docker-compose
    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, pip, docker and kubectl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Senior Security loads about 1.1k tokens when it runs, and up to ~2.4k if it reads all its reference files. Until then it costs about 96 tokens; SKILL.md has 299 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:126
    cp .env.example .env

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from davila7/claude-code-templates at commit 14680ec, republished under its MIT licence (© davila7). 299 words, ~1,133 tokens.

Download SKILL.mdSave it as .claude/skills/senior-security/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
senior-security
description
Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.

Senior Security

Complete toolkit for senior security with modern tools and best practices.

Quick Start

Main Capabilities

This skill provides three core capabilities through automated scripts:

bash
# Script 1: Threat Modeler
python scripts/threat_modeler.py [options]

# Script 2: Security Auditor
python scripts/security_auditor.py [options]

# Script 3: Pentest Automator
python scripts/pentest_automator.py [options]

Core Capabilities

1. Threat Modeler

Automated tool for threat modeler tasks.

Features:

  • Automated scaffolding
  • Best practices built-in
  • Configurable templates
  • Quality checks

Usage:

bash
python scripts/threat_modeler.py <project-path> [options]
2. Security Auditor

Comprehensive analysis and optimization tool.

Features:

  • Deep analysis
  • Performance metrics
  • Recommendations
  • Automated fixes

Usage:

bash
python scripts/security_auditor.py <target-path> [--verbose]
3. Pentest Automator

Advanced tooling for specialized tasks.

Features:

  • Expert-level automation
  • Custom configurations
  • Integration ready
  • Production-grade output

Usage:

bash
python scripts/pentest_automator.py [arguments] [options]

Reference Documentation

Security Architecture Patterns

Comprehensive guide available in references/security_architecture_patterns.md:

  • Detailed patterns and practices
  • Code examples
  • Best practices
  • Anti-patterns to avoid
  • Real-world scenarios
Penetration Testing Guide

Complete workflow documentation in references/penetration_testing_guide.md:

  • Step-by-step processes
  • Optimization strategies
  • Tool integrations
  • Performance tuning
  • Troubleshooting guide
Cryptography Implementation

Technical reference guide in references/cryptography_implementation.md:

  • Technology stack details
  • Configuration examples
  • Integration patterns
  • Security considerations
  • Scalability guidelines

Tech Stack

Languages: TypeScript, JavaScript, Python, Go, Swift, Kotlin Frontend: React, Next.js, React Native, Flutter Backend: Node.js, Express, GraphQL, REST APIs Database: PostgreSQL, Prisma, NeonDB, Supabase DevOps: Docker, Kubernetes, Terraform, GitHub Actions, CircleCI Cloud: AWS, GCP, Azure

Development Workflow

1. Setup and Configuration
bash
# Install dependencies
npm install
# or
pip install -r requirements.txt

# Configure environment
cp .env.example .env
2. Run Quality Checks
bash
# Use the analyzer script
python scripts/security_auditor.py .

# Review recommendations
# Apply fixes
3. Implement Best Practices

Follow the patterns and practices documented in:

  • references/security_architecture_patterns.md
  • references/penetration_testing_guide.md
  • references/cryptography_implementation.md

Best Practices Summary

Code Quality
  • Follow established patterns
  • Write comprehensive tests
  • Document decisions
  • Review regularly
Performance
  • Measure before optimizing
  • Use appropriate caching
  • Optimize critical paths
  • Monitor in production
Security
  • Validate all inputs
  • Use parameterized queries
  • Implement proper authentication
  • Keep dependencies updated
Maintainability
  • Write clear code
  • Use consistent naming
  • Add helpful comments
  • Keep it simple

Common Commands

bash
# Development
npm run dev
npm run build
npm run test
npm run lint

# Analysis
python scripts/security_auditor.py .
python scripts/pentest_automator.py --analyze

# Deployment
docker build -t app:latest .
docker-compose up -d
kubectl apply -f k8s/

Troubleshooting

Common Issues

Check the comprehensive troubleshooting section in references/cryptography_implementation.md.

Getting Help
  • Review reference documentation
  • Check script output messages
  • Consult tech stack documentation
  • Review error logs

Resources

  • Pattern Reference: references/security_architecture_patterns.md
  • Workflow Guide: references/penetration_testing_guide.md
  • Technical Guide: references/cryptography_implementation.md
  • Tool Scripts: scripts/ directory

© davila7, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in cli-tool/components/skills/development/senior-security of davila7/claude-code-templates.

  • SKILL.md
  • references/cryptography_implementation.md
  • references/penetration_testing_guide.md
  • references/security_architecture_patterns.md
  • scripts/pentest_automator.py
  • scripts/security_auditor.py
  • scripts/threat_modeler.py

Open the folder on GitHubat commit 14680ec

Used in 2 other repositories

We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in davila7/claude-code-templates, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Senior Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Senior Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Senior Security this skilldavila7/claude-code-templates32k2 repos~1.1kAutomated safety check: NotesMIT
Csono-session/pstack134—~12kAutomated safety check: NotesMIT
Secure By Designooiyeefei/ccc494—~1.5kAutomated safety check: PassMIT
Strix Code Vulnerability Scanusestrix/strix67k—~1.1kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence

Similar skills

  • Cso

    no-session/pstack

    Chief Security Officer mode. An agent skill from no-session/pstack.

    134 GitHub stars~12k tokensUpdated 6 mo ago
    SecurityAuto-check: notes
  • Secure By Design

    ooiyeefei/ccc

    Run an enterprise security review of a system design or existing code before it ships.

    494 GitHub stars~1.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    67k GitHub stars~1.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed

More from davila7/claude-code-templates

All 477 skills in this repo
  • Perplexity Web Search

    davila7/claude-code-templates

    Runs web-grounded searches through Perplexity's Sonar models over OpenRouter for current events, recent literature and cited facts beyond the model's training cutoff.

    32k GitHub starsUsed in 12 repos~3.5k tokens
    Auto-check: notes
  • Neuropixels Data Analysis

    davila7/claude-code-templates

    Analyzes Neuropixels recordings from SpikeGLX or Open Ephys through preprocessing, drift correction, Kilosort4 spike sorting, quality metrics and curation.

    32k GitHub starsUsed in 10 repos~2.8k tokens
    Auto-check passed
  • Scientific Venue Templates

    davila7/claude-code-templates

    Supplies LaTeX templates and formatting rules for journals, conferences, posters, and grant proposals, then can check a draft against them.

    32k GitHub starsUsed in 9 repos~5.1k tokens
    Auto-check: notes
  • Brand Voice Content Creator

    davila7/claude-code-templates

    Analyzes a brand's existing writing to lock in a consistent voice, then builds SEO blog posts and platform-specific social content around it.

    32k GitHub starsUsed in 3 repos~1.9k tokens
    Auto-check passed
  • CAPA Officer

    davila7/claude-code-templates

    Guides corrective and preventive action (CAPA) work in a quality management system, from initiation and root cause analysis through effectiveness verification.

    32k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Fda Consultant Specialist

    davila7/claude-code-templates

    Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.

    32k GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed

Categories

Questions about Senior Security

What does Senior Security do?

Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Senior Security is an agent skill from davila7/claude-code-templates. Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing.

When should I use Senior Security?

Senior Security fits situations like: designing security architecture; conducting penetration tests; implementing cryptography; performing security audits.

How do I install Senior Security in Claude Code?

Run `npx skills add davila7/claude-code-templates --skill senior-security -a claude-code`. Or copy the skill folder (cli-tool/components/skills/development/senior-security in davila7/claude-code-templates) into .claude/skills/senior-security in your project. Claude Code loads it when a task matches its description.

How do I install Senior Security in Codex?

Run `npx skills add davila7/claude-code-templates --skill senior-security -a codex`. Or copy the skill folder (cli-tool/components/skills/development/senior-security in davila7/claude-code-templates) into .agents/skills/senior-security in your project. Codex loads it when a task matches its description.

Can I use Senior Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davila7/claude-code-templates --skill senior-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/senior-security, .gemini/skills/senior-security, .github/skills/senior-security and .opencode/skills/senior-security in your project.

What does Senior Security need to run?

Going by SKILL.md and its folder, Senior Security needs Python for the scripts in its folder and the command-line tools its instructions call (python, npm, pip, docker, docker-compose and kubectl). Our summary lists: Python 3; Node.js; Docker.

Does Senior Security access the network?

SKILL.md contains no URLs. Its commands use npm, pip and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Senior Security safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Senior Security use?

Senior Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Senior Security use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Senior Security?

Skills that share tags, products or a category with Senior Security: Cso (no-session/pstack, 134 stars), Secure By Design (ooiyeefei/ccc, 494 stars), Strix Code Vulnerability Scan (usestrix/strix, 67k stars) and Code Audit (3stoneBrother/code-audit, 893 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Senior Security?

davila7 (a GitHub user) maintains it in davila7/claude-code-templates, which has 32,463 GitHub stars. The repository holds 477 skills in this directory. The repository was last updated on October 8, 2026.

Source: davila7/claude-code-templates on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.