Agent skill

Security Assessment

by EmeaAppGbb in EmeaAppGbb/spec2cloud

Audit codebase for security vulnerabilities, insecure patterns, and compliance gaps.

MITAuto-check: notesSecurity

Install Security Assessment

skills CLI
$ npx skills add EmeaAppGbb/spec2cloud --skill security-assessment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install EmeaAppGbb/spec2cloud security-assessment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/EmeaAppGbb/spec2cloud.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/security-assessment .claude/skills/security-assessment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-assessment
GitHub stars
100
Token cost
~2.2k tokens
SKILL.md length
885 words
Files
1
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

Audit codebase for security vulnerabilities, insecure patterns, and compliance gaps.

  • Tasks that involve Security review
  • SKILL.md covers Role, Inputs, Adaptive Depth Levels and OWASP Top 10 Mapping, plus 5 more sections
  • Calls npm and dotnet
  • Tasks that involve Vulnerability scanning

What it does

Security Assessment is an agent skill from EmeaAppGbb/spec2cloud. Audit codebase for security vulnerabilities, insecure patterns, and compliance gaps. Adaptive depth — starts with dependency CVEs and obvious patterns, escalates to deep code analysis.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review, Vulnerability scanning and Web application vulnerabilities. The licence is MIT.

When your agent uses it

  • Tasks that involve Security review
  • Tasks that involve Vulnerability scanning
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/security-assessment”

What it can do on your machine

Read from SKILL.md and the folder at commit 8e76618. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • dotnet

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Assessment loads about 2.2k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 885 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:39
    - `.env` files committed to version control

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from EmeaAppGbb/spec2cloud at commit 8e76618, republished under its MIT licence (© EmeaAppGbb). 885 words, ~2,197 tokens.

Download SKILL.mdSave it as .claude/skills/security-assessment/SKILL.md (or your agent's skills folder).
name
security-assessment
description
Audit codebase for security vulnerabilities, insecure patterns, and compliance gaps. Adaptive depth — starts with dependency CVEs and obvious patterns, escalates to deep code analysis.

Role

You are a security auditor performing static analysis of an application codebase. Your job is to identify vulnerabilities, insecure patterns, and compliance gaps — then map findings to industry frameworks (OWASP Top 10) and provide actionable remediation guidance.

You are activated when the user selects the security path. You do not run automatically.

Inputs

  • specs/docs/technology/* — Technology inventory from extraction
  • specs/docs/architecture/* — Architecture documentation from extraction
  • specs/docs/dependencies/* — Dependency manifests and lock files
  • Source code access for pattern analysis
  • Existing security configurations (CORS, CSP, auth config, etc.)

Adaptive Depth Levels

Level 1 — Surface Scan

Fast scan for known vulnerabilities and obvious patterns:

  • Dependency CVE scan: Check dependency manifests against known vulnerability databases.
    • npm: npm audit / advisory database
    • Python: pip-audit / safety database
    • Java: OWASP dependency-check
    • .NET: dotnet list package --vulnerable
    • Go: govulncheck
  • Hardcoded secrets scan: Search for patterns indicating embedded credentials.
    • API keys, tokens, passwords in source files
    • Private keys or certificates in the repository
    • Connection strings with embedded credentials
    • .env files committed to version control
  • Basic pattern matching: Scan for common vulnerability patterns.
    • String concatenation in SQL queries (SQL injection risk)
    • Unescaped user input in HTML output (XSS risk)
    • eval(), exec(), or equivalent dynamic code execution
    • Disabled security features (e.g., CSRF protection turned off)
    • Insecure HTTP usage where HTTPS is expected
    • Weak cryptographic algorithms (MD5, SHA1 for security purposes)

Estimated time: 5–15 minutes of analysis.

Escalation trigger: If Level 1 finds any critical findings or >3 high-severity findings, auto-escalate to Level 2.

Level 2 — Pattern Analysis

Deeper analysis of authentication, authorization, and input handling:

  • Auth/authz pattern analysis:
    • Authentication mechanism review (session, JWT, OAuth, API keys)
    • Authorization enforcement — are access controls checked consistently?
    • Password handling — hashing algorithm, salt usage, strength requirements
    • Token management — expiration, refresh, revocation
    • Multi-tenancy isolation — can users access other tenants' data?
  • Input validation coverage:
    • Which endpoints validate input? Which don't?
    • Validation approach — allowlist vs blocklist, schema validation
    • File upload handling — type checking, size limits, storage location
    • Deserialization safety — are untrusted objects deserialized?
  • Error information leakage:
    • Stack traces in production error responses
    • Database error details exposed to clients
    • Debug endpoints or verbose logging in production config
    • Version information disclosure in headers
  • Security header configuration:
    • CORS policy — overly permissive origins?
    • Content-Security-Policy — present and effective?
    • X-Content-Type-Options, X-Frame-Options, Strict-Transport-Security
    • Cookie attributes — Secure, HttpOnly, SameSite

Estimated time: 20–45 minutes of analysis.

Escalation trigger: If Level 2 finds auth/authz architectural issues or missing security boundaries, escalate to Level 3.

Level 3 — Deep Analysis

Business logic and architectural security review:

  • Business logic security:
    • Insecure Direct Object Reference (IDOR) — can users manipulate IDs to access other resources?
    • Privilege escalation paths — can a regular user reach admin functionality?
    • Race conditions — time-of-check to time-of-use vulnerabilities
    • Business rule bypass — can workflow steps be skipped?
  • Cryptographic usage review:
    • Algorithm selection — are modern algorithms used appropriately?
    • Key management — how are encryption keys stored and rotated?
    • Random number generation — cryptographically secure sources?
    • Data at rest encryption — sensitive fields encrypted in database?
  • Session management:
    • Session fixation resistance
    • Concurrent session handling
    • Session timeout and idle timeout
    • Secure session storage

Estimated time: 45–90 minutes of analysis.

Escalation Rules
Level 1: any critical OR >3 high     → auto-escalate to Level 2
Level 2: auth/authz architectural    → escalate to Level 3
User can force any level with:       "run security assessment at level 3"

OWASP Top 10 Mapping

Map every finding to the relevant OWASP Top 10 (2021) category:

IDCategory
A01Broken Access Control
A02Cryptographic Failures
A03Injection
A04Insecure Design
A05Security Misconfiguration
A06Vulnerable and Outdated Components
A07Identification and Authentication Failures
A08Software and Data Integrity Failures
A09Security Logging and Monitoring Failures
A10Server-Side Request Forgery (SSRF)
Show full SKILL.md (326 more words)Show less

Severity Ratings

  • Critical: Actively exploitable vulnerability with high impact (data breach, RCE, auth bypass). Fix immediately.
  • High: Exploitable with moderate effort or high-impact misconfiguration. Fix before deployment.
  • Medium: Vulnerability requiring specific conditions or moderate impact. Fix in next iteration.
  • Low: Minor issue, defense-in-depth improvement, or informational finding.

Output Format

Generate specs/assessment/security.md with this structure:

markdown
# Security Assessment

## Summary
- Assessment depth: Level [1/2/3]
- Total findings: [N]
- Critical: [N] | High: [N] | Medium: [N] | Low: [N]
- OWASP categories affected: [list]
- Escalation triggered: [yes/no — reason]

## Findings

### Critical
| # | OWASP | Finding | Location | Remediation | Effort |
|---|-------|---------|----------|-------------|--------|

### High
(same table format)

### Medium
(same table format)

### Low
(same table format)

## OWASP Top 10 Coverage
| OWASP ID | Category | Findings | Status |
|----------|----------|----------|--------|

## Remediation Roadmap
Priority-ordered list of fixes with dependencies noted.

## Decision Points
Items requiring user decision — linked to generated ADRs.

ADR Triggers

Generate ADRs via the adr skill for major security architecture decisions:

  • Authentication mechanism change: e.g., migrate from session-based to JWT, or adopt OAuth 2.0 / OIDC
  • Authorization model redesign: e.g., move from role-based to attribute-based access control
  • Secrets management strategy: e.g., adopt Azure Key Vault, move from env vars to managed secrets
  • API security approach: e.g., adopt API gateway, implement rate limiting strategy

Important Notes

  • This is static analysis. You are reviewing code patterns, not running exploit tools.
  • Do not claim a vulnerability is confirmed exploitable without runtime evidence — describe the risk pattern.
  • Severity ratings reflect potential impact, not confirmed exploitation.
  • Focus remediation guidance on practical steps the team can take, not theoretical best practices.
  • If the codebase uses a framework with built-in security features, check whether they are properly enabled rather than reimplemented.
  • Secrets found in code should be reported but never included verbatim in the assessment output.

Mandatory Completion Checklist

The orchestrator MUST verify ALL of the following before marking security-assessment as complete:

  • specs/assessment/security.md exists with: executive summary, findings by OWASP category, severity ratings, and remediation guidance
  • Every finding has a severity level (critical / high / medium / low) and a clear remediation path
  • Dependency CVE scan results are included (even if no CVEs found — state "0 known CVEs")
  • Authentication and authorization patterns are reviewed and documented
  • Secrets-in-code scan completed (no secrets included verbatim in output)
  • At least one ADR exists in specs/adrs/ for significant security architecture decisions
  • State JSON and audit log are updated

BLOCKING: If any item is unchecked, the skill has NOT completed successfully. The orchestrator must loop back and complete the missing items before advancing to planning.

© EmeaAppGbb, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/security-assessment of EmeaAppGbb/spec2cloud.

Open the folder on GitHubat commit 8e76618

Compare with similar skills

Security Assessment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Assessment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Assessment this skillEmeaAppGbb/spec2cloud100—~2.2kAutomated safety check: NotesMIT
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Octopus Security Auditnyldn/claude-octopus4.2k1 repos~2.3kAutomated safety check: PassMIT
Security Checkgocronx-team/gocron808—~690Automated safety check: PassMIT

Similar skills

  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Octopus Security Audit

    nyldn/claude-octopus

    OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

    4.2k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check passed
  • Security Check

    gocronx-team/gocron

    Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

    808 GitHub stars~690 tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    281 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings

More from EmeaAppGbb/spec2cloud

All 39 skills in this repo
  • Azure Deployment

    EmeaAppGbb/spec2cloud

    Provision Azure infrastructure, deploy to Azure Container Apps, and verify via smoke tests.

    100 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Contract Generation

    EmeaAppGbb/spec2cloud

    Generate API contracts, shared TypeScript types, and infrastructure resource definitions from Gherkin scenarios and test files.

    100 GitHub stars~1.6k tokensUpdated 5 mo ago
    Auto-check passed
  • Ddd Modeling

    EmeaAppGbb/spec2cloud

    Create Domain-Driven Design proposals from product specs or brownfield extraction outputs.

    100 GitHub stars~2.4k tokensUpdated 5 mo ago
    Auto-check passed
  • Implementation

    EmeaAppGbb/spec2cloud

    Write application code to make failing tests pass using contract-driven, slice-based architecture.

    100 GitHub stars~2.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Spec Refinement

    EmeaAppGbb/spec2cloud

    Review PRDs and FRDs through product and technical lenses. An agent skill from EmeaAppGbb/spec2cloud.

    100 GitHub stars~2.2k tokensUpdated 5 mo ago
    Auto-check passed
  • State Management

    EmeaAppGbb/spec2cloud

    Read, write, and maintain .spec2cloud/state.json across phases and increments.

    100 GitHub stars~1.5k tokensUpdated 5 mo ago
    Auto-check passed

Categories

Questions about Security Assessment

What does Security Assessment do?

Audit codebase for security vulnerabilities, insecure patterns, and compliance gaps. Security Assessment is an agent skill from EmeaAppGbb/spec2cloud. Audit codebase for security vulnerabilities, insecure patterns, and compliance gaps.

When should I use Security Assessment?

Security Assessment fits situations like: tasks that involve Security review; tasks that involve Vulnerability scanning; tasks that involve Web application vulnerabilities.

How do I install Security Assessment in Claude Code?

Run `npx skills add EmeaAppGbb/spec2cloud --skill security-assessment -a claude-code`. Or copy the skill folder (.github/skills/security-assessment in EmeaAppGbb/spec2cloud) into .claude/skills/security-assessment in your project. Claude Code loads it when a task matches its description.

How do I install Security Assessment in Codex?

Run `npx skills add EmeaAppGbb/spec2cloud --skill security-assessment -a codex`. Or copy the skill folder (.github/skills/security-assessment in EmeaAppGbb/spec2cloud) into .agents/skills/security-assessment in your project. Codex loads it when a task matches its description.

Can I use Security Assessment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EmeaAppGbb/spec2cloud --skill security-assessment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-assessment, .gemini/skills/security-assessment, .github/skills/security-assessment and .opencode/skills/security-assessment in your project.

What does Security Assessment need to run?

Going by SKILL.md and its folder, Security Assessment needs the command-line tools its instructions call (npm and dotnet).

Does Security Assessment access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Assessment safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Assessment use?

Security Assessment is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Assessment use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Assessment?

Skills that share tags, products or a category with Security Assessment: Security Auditor (eigent-ai/eigent, 15k stars), Code Audit (3stoneBrother/code-audit, 893 stars), Security Audit Scanner (ruvnet/ruflo, 74k stars) and Octopus Security Audit (nyldn/claude-octopus, 4.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Assessment?

EmeaAppGbb (a GitHub organization) maintains it in EmeaAppGbb/spec2cloud, which has 100 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on April 16, 2026.

Source: EmeaAppGbb/spec2cloud on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.