Cso
no-session/pstack
Chief Security Officer mode. An agent skill from no-session/pstack.
Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing.
$ npx skills add davila7/claude-code-templates --skill senior-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install davila7/claude-code-templates senior-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/davila7/claude-code-templates.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cli-tool/components/skills/development/senior-security .claude/skills/senior-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "senior-security" agent skill from https://github.com/davila7/claude-code-templates/tree/main/cli-tool/components/skills/development/senior-security into .claude/skills/senior-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "senior-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/davila7/claude-code-templates/tree/main/cli-tool/components/skills/development/senior-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add davila7/claude-code-templates --skill senior-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install davila7/claude-code-templates senior-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davila7/claude-code-templates.git skills-src && mkdir -p .agents/skills && cp -r skills-src/cli-tool/components/skills/development/senior-security .agents/skills/senior-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "senior-security" agent skill from https://github.com/davila7/claude-code-templates/tree/main/cli-tool/components/skills/development/senior-security into .agents/skills/senior-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "senior-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add davila7/claude-code-templates --skill senior-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install davila7/claude-code-templates senior-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davila7/claude-code-templates.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/cli-tool/components/skills/development/senior-security .cursor/skills/senior-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "senior-security" agent skill from https://github.com/davila7/claude-code-templates/tree/main/cli-tool/components/skills/development/senior-security into .cursor/skills/senior-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "senior-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/davila7/claude-code-templates.git --path cli-tool/components/skills/development/senior-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add davila7/claude-code-templates --skill senior-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install davila7/claude-code-templates senior-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davila7/claude-code-templates.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/cli-tool/components/skills/development/senior-security .gemini/skills/senior-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "senior-security" agent skill from https://github.com/davila7/claude-code-templates/tree/main/cli-tool/components/skills/development/senior-security into .gemini/skills/senior-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "senior-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install davila7/claude-code-templates senior-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add davila7/claude-code-templates --skill senior-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/davila7/claude-code-templates.git skills-src && mkdir -p .github/skills && cp -r skills-src/cli-tool/components/skills/development/senior-security .github/skills/senior-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "senior-security" agent skill from https://github.com/davila7/claude-code-templates/tree/main/cli-tool/components/skills/development/senior-security into .github/skills/senior-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "senior-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add davila7/claude-code-templates --skill senior-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install davila7/claude-code-templates senior-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davila7/claude-code-templates.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/cli-tool/components/skills/development/senior-security .opencode/skills/senior-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "senior-security" agent skill from https://github.com/davila7/claude-code-templates/tree/main/cli-tool/components/skills/development/senior-security into .opencode/skills/senior-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "senior-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
senior-securityComprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing.
Senior Security is an agent skill from davila7/claude-code-templates. Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/cryptography_implementation.md`, `references/penetration_testing_guide.md` and `references/security_architecture_patterns.md`).
It sits in Security, covering Security review, Cryptography and Penetration testing. The repository describes itself as: CLI tool for configuring and monitoring Claude Code. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 14680ec. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pythonnpmpipdockerdocker-composekubectlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, pip, docker and kubectl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Senior Security loads about 1.1k tokens when it runs, and up to ~2.4k if it reads all its reference files. Until then it costs about 96 tokens; SKILL.md has 299 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
cp .env.example .envAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from davila7/claude-code-templates at commit 14680ec, republished under its MIT licence (© davila7). 299 words, ~1,133 tokens.
.claude/skills/senior-security/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.Complete toolkit for senior security with modern tools and best practices.
This skill provides three core capabilities through automated scripts:
# Script 1: Threat Modeler
python scripts/threat_modeler.py [options]
# Script 2: Security Auditor
python scripts/security_auditor.py [options]
# Script 3: Pentest Automator
python scripts/pentest_automator.py [options]Automated tool for threat modeler tasks.
Features:
Usage:
python scripts/threat_modeler.py <project-path> [options]Comprehensive analysis and optimization tool.
Features:
Usage:
python scripts/security_auditor.py <target-path> [--verbose]Advanced tooling for specialized tasks.
Features:
Usage:
python scripts/pentest_automator.py [arguments] [options]Comprehensive guide available in references/security_architecture_patterns.md:
Complete workflow documentation in references/penetration_testing_guide.md:
Technical reference guide in references/cryptography_implementation.md:
Languages: TypeScript, JavaScript, Python, Go, Swift, Kotlin Frontend: React, Next.js, React Native, Flutter Backend: Node.js, Express, GraphQL, REST APIs Database: PostgreSQL, Prisma, NeonDB, Supabase DevOps: Docker, Kubernetes, Terraform, GitHub Actions, CircleCI Cloud: AWS, GCP, Azure
# Install dependencies
npm install
# or
pip install -r requirements.txt
# Configure environment
cp .env.example .env# Use the analyzer script
python scripts/security_auditor.py .
# Review recommendations
# Apply fixesFollow the patterns and practices documented in:
references/security_architecture_patterns.mdreferences/penetration_testing_guide.mdreferences/cryptography_implementation.md# Development
npm run dev
npm run build
npm run test
npm run lint
# Analysis
python scripts/security_auditor.py .
python scripts/pentest_automator.py --analyze
# Deployment
docker build -t app:latest .
docker-compose up -d
kubectl apply -f k8s/Check the comprehensive troubleshooting section in references/cryptography_implementation.md.
references/security_architecture_patterns.mdreferences/penetration_testing_guide.mdreferences/cryptography_implementation.mdscripts/ directory© davila7, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (scripts, references) in cli-tool/components/skills/development/senior-security of davila7/claude-code-templates.
Open the folder on GitHubat commit 14680ec
We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in davila7/claude-code-templates, which our catalogue first saw on October 7, 2026.
Senior Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Senior Security this skilldavila7/claude-code-templates | 32k | 2 repos | ~1.1k | Automated safety check: Notes | MIT | |
| Csono-session/pstack | 134 | — | ~12k | Automated safety check: Notes | MIT | |
| Secure By Designooiyeefei/ccc | 494 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Strix Code Vulnerability Scanusestrix/strix | 67k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Code Audit3stoneBrother/code-audit | 893 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence |
no-session/pstack
Chief Security Officer mode. An agent skill from no-session/pstack.
ooiyeefei/ccc
Run an enterprise security review of a system design or existing code before it ships.
usestrix/strix
Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
davila7/claude-code-templates
Runs web-grounded searches through Perplexity's Sonar models over OpenRouter for current events, recent literature and cited facts beyond the model's training cutoff.
davila7/claude-code-templates
Analyzes Neuropixels recordings from SpikeGLX or Open Ephys through preprocessing, drift correction, Kilosort4 spike sorting, quality metrics and curation.
davila7/claude-code-templates
Supplies LaTeX templates and formatting rules for journals, conferences, posters, and grant proposals, then can check a draft against them.
davila7/claude-code-templates
Analyzes a brand's existing writing to lock in a consistent voice, then builds SEO blog posts and platform-specific social content around it.
davila7/claude-code-templates
Guides corrective and preventive action (CAPA) work in a quality management system, from initiation and root cause analysis through effectiveness verification.
davila7/claude-code-templates
Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.
Categories
Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Senior Security is an agent skill from davila7/claude-code-templates. Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing.
Senior Security fits situations like: designing security architecture; conducting penetration tests; implementing cryptography; performing security audits.
Run `npx skills add davila7/claude-code-templates --skill senior-security -a claude-code`. Or copy the skill folder (cli-tool/components/skills/development/senior-security in davila7/claude-code-templates) into .claude/skills/senior-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add davila7/claude-code-templates --skill senior-security -a codex`. Or copy the skill folder (cli-tool/components/skills/development/senior-security in davila7/claude-code-templates) into .agents/skills/senior-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davila7/claude-code-templates --skill senior-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/senior-security, .gemini/skills/senior-security, .github/skills/senior-security and .opencode/skills/senior-security in your project.
Going by SKILL.md and its folder, Senior Security needs Python for the scripts in its folder and the command-line tools its instructions call (python, npm, pip, docker, docker-compose and kubectl). Our summary lists: Python 3; Node.js; Docker.
SKILL.md contains no URLs. Its commands use npm, pip and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Senior Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Senior Security: Cso (no-session/pstack, 134 stars), Secure By Design (ooiyeefei/ccc, 494 stars), Strix Code Vulnerability Scan (usestrix/strix, 67k stars) and Code Audit (3stoneBrother/code-audit, 893 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
davila7 (a GitHub user) maintains it in davila7/claude-code-templates, which has 32,463 GitHub stars. The repository holds 477 skills in this directory. The repository was last updated on October 8, 2026.
Source: davila7/claude-code-templates on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.