Deepsec Documentation Guide
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
Create a prioritized security remediation plan from security assessment findings.
$ npx skills add EmeaAppGbb/spec2cloud --skill security-planner -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install EmeaAppGbb/spec2cloud security-planner --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/EmeaAppGbb/spec2cloud.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/security-planner .claude/skills/security-planner && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-planner" agent skill from https://github.com/EmeaAppGbb/spec2cloud/tree/vNext/.github/skills/security-planner into .claude/skills/security-planner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-planner", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/EmeaAppGbb/spec2cloud/tree/vNext/.github/skills/security-plannerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add EmeaAppGbb/spec2cloud --skill security-planner -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install EmeaAppGbb/spec2cloud security-planner --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EmeaAppGbb/spec2cloud.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/security-planner .agents/skills/security-planner && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-planner" agent skill from https://github.com/EmeaAppGbb/spec2cloud/tree/vNext/.github/skills/security-planner into .agents/skills/security-planner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-planner", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add EmeaAppGbb/spec2cloud --skill security-planner -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install EmeaAppGbb/spec2cloud security-planner --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EmeaAppGbb/spec2cloud.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/security-planner .cursor/skills/security-planner && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-planner" agent skill from https://github.com/EmeaAppGbb/spec2cloud/tree/vNext/.github/skills/security-planner into .cursor/skills/security-planner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-planner", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/EmeaAppGbb/spec2cloud.git --path .github/skills/security-planner--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add EmeaAppGbb/spec2cloud --skill security-planner -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install EmeaAppGbb/spec2cloud security-planner --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EmeaAppGbb/spec2cloud.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/security-planner .gemini/skills/security-planner && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-planner" agent skill from https://github.com/EmeaAppGbb/spec2cloud/tree/vNext/.github/skills/security-planner into .gemini/skills/security-planner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-planner", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install EmeaAppGbb/spec2cloud security-plannerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add EmeaAppGbb/spec2cloud --skill security-planner -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/EmeaAppGbb/spec2cloud.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/security-planner .github/skills/security-planner && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-planner" agent skill from https://github.com/EmeaAppGbb/spec2cloud/tree/vNext/.github/skills/security-planner into .github/skills/security-planner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-planner", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add EmeaAppGbb/spec2cloud --skill security-planner -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install EmeaAppGbb/spec2cloud security-planner --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EmeaAppGbb/spec2cloud.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/security-planner .opencode/skills/security-planner && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-planner" agent skill from https://github.com/EmeaAppGbb/spec2cloud/tree/vNext/.github/skills/security-planner into .opencode/skills/security-planner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-planner", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-plannerCreate a prioritized security remediation plan from security assessment findings.
Security Planner is an agent skill from EmeaAppGbb/spec2cloud. Create a prioritized security remediation plan from security assessment findings. Critical vulnerabilities first, then hardening improvements. Generate increments that feed into the standard Phase 2 delivery pipeline. Use when transforming security assessment results into actionable fix items.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security review. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8e76618. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown and json).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Planner loads about 2.5k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 1,019 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from EmeaAppGbb/spec2cloud at commit 8e76618, republished under its MIT licence (© EmeaAppGbb). 1,019 words, ~2,542 tokens.
.claude/skills/security-planner/SKILL.md (or your agent's skills folder).You are the Security Planner. You transform findings from
specs/assessment/security.md into a prioritized sequence of security
remediation increments. Critical vulnerabilities are fixed first, then
hardening improvements layer on. Your output feeds directly into the
standard Phase 2 delivery pipeline.
You do NOT perform the fixes. You produce the plan.
Before generating any increments, read:
specs/assessment/security.md) — vulnerability
findings, severity ratings, affected components, recommended fixes.specs/adrs/) — security-related architectural decisions
(auth strategy, encryption requirements, compliance standards).specs/assessment/dependencies.md) — known CVEs,
vulnerable package versions, upgrade paths.specs/assessment/architecture.md) — attack surface,
trust boundaries, data flow.specs/increment-plan.md) — append, never overwrite.Order security increments using this strict priority hierarchy:
Map every finding from the security assessment to a priority tier. If a finding spans multiple tiers, classify it at the highest applicable tier.
For each finding, define the smallest possible change that addresses the vulnerability:
Security fixes must be surgical. No scope creep — fixing a SQL injection vulnerability is not the time to refactor the data access layer.
Each fix needs a test that proves the vulnerability is resolved:
Within each tier, order by:
Each increment in specs/increment-plan.md follows this template:
## sec-001: Remediate SQL Injection in Search Endpoint
- **Type:** security
- **Tier:** 2 (High)
- **Vulnerability:** SQL injection via unsanitized user input in
GET /api/search?q= parameter (finding SEC-2024-007)
- **Scope:** Parameterize SQL query in SearchService.search().
No other changes.
- **Acceptance Criteria:**
- [ ] Parameterized query prevents SQL injection payloads
- [ ] Search functionality returns correct results
- [ ] All existing search tests pass
- **Test Strategy:**
- Add injection test: verify malicious input is safely escaped
- Add boundary test: verify legitimate special characters still work
- Run full regression suite
- Re-run SAST scanner to confirm finding cleared
- **Behavioral Deltas:** (Track-dependent — see Behavioral Deltas section)
- **Dependencies:** none
- **Rollback Plan:** Revert SearchService.search() to previous implementation
- **Risk:** Low — isolated change to one methodAppend all generated increments to specs/increment-plan.md. Do NOT overwrite
existing content. Group by tier with clear section headers.
After appending, update .spec2cloud/state.json:
{
"incrementPlan": [
{ "id": "sec-001", "type": "security", "tier": 2, "status": "planned" },
{ "id": "sec-002", "type": "security", "tier": 1, "status": "planned" }
]
}Append to .spec2cloud/audit.log:
[ISO-timestamp] step=security-planning action=increments-generated count={N} tier-1={N} tier-2={N} tier-3={N} tier-4={N} result=doneEach increment must include behavioral change specifications that feed into Phase 2 test generation. The format depends on the project's testability track (from .spec2cloud/state.json).
For each increment, specify which Gherkin scenarios are affected:
@existing-behavior scenarios that change (update expected outcomes)Include Gherkin deltas in the increment format:
- **Gherkin Deltas:**
- New: `Scenario: {description}` — {why this is needed}
- Modified: `Scenario: {existing scenario name}` — Then step changes from X to Y
- Regression: N existing scenarios must still pass unchangedFor each increment, specify behavioral documentation updates:
Include documentation deltas in the increment format:
- **Behavioral Doc Updates:**
- Updated: `Scenario: {name}` — expected behavior changes from X to Y
- New: `Scenario: {name}` — documents new expected behavior
- Manual verification: {new checklist items}Before finalizing, verify:
After the plan is reviewed and approved at the human gate, each increment proceeds through the standard Phase 2 pipeline:
The orchestrator MUST verify ALL of the following before marking security-planner as complete:
specs/increment-plan.md is updated with all security fix increments (unique IDs, scope, severity, effort)BLOCKING: If any item is unchecked, the skill has NOT completed successfully. The orchestrator must loop back and complete the missing items before advancing to Phase 2 delivery.
© EmeaAppGbb, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/security-planner of EmeaAppGbb/spec2cloud.
Open the folder on GitHubat commit 8e76618
Security Planner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Planner this skillEmeaAppGbb/spec2cloud | 100 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Kubernetes Network Security Auditkubeshark/kubeshark | 12k | — | ~7.3k | Automated safety check: Notes | Apache-2.0 | |
| Agentlas Security Scanagentlas-ai/Agentlas-OS | 1.6k | 1 repos | ~822 | Automated safety check: Pass | Apache-2.0 | |
| Native Dependency Updatemono/SkiaSharp | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT | |
| Semgrep Security Scantrailofbits/skills | 7.4k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 |
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
kubeshark/kubeshark
Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.
agentlas-ai/Agentlas-OS
A skill your agent uses when an agent folder must pass the Agentlas Cloud 2-stage security scan (static rules + BYOK LLM judgment) before private sync or public publish, or when asked to…
mono/SkiaSharp
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
Fangcun-AI/SkillWard
Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.
EmeaAppGbb/spec2cloud
Provision Azure infrastructure, deploy to Azure Container Apps, and verify via smoke tests.
EmeaAppGbb/spec2cloud
Generate API contracts, shared TypeScript types, and infrastructure resource definitions from Gherkin scenarios and test files.
EmeaAppGbb/spec2cloud
Create Domain-Driven Design proposals from product specs or brownfield extraction outputs.
EmeaAppGbb/spec2cloud
Write application code to make failing tests pass using contract-driven, slice-based architecture.
EmeaAppGbb/spec2cloud
Review PRDs and FRDs through product and technical lenses. An agent skill from EmeaAppGbb/spec2cloud.
EmeaAppGbb/spec2cloud
Read, write, and maintain .spec2cloud/state.json across phases and increments.
Categories
Create a prioritized security remediation plan from security assessment findings. Security Planner is an agent skill from EmeaAppGbb/spec2cloud. Create a prioritized security remediation plan from security assessment findings.
Security Planner fits situations like: transforming security assessment results into actionable fix items; tasks that involve Security review.
Run `npx skills add EmeaAppGbb/spec2cloud --skill security-planner -a claude-code`. Or copy the skill folder (.github/skills/security-planner in EmeaAppGbb/spec2cloud) into .claude/skills/security-planner in your project. Claude Code loads it when a task matches its description.
Run `npx skills add EmeaAppGbb/spec2cloud --skill security-planner -a codex`. Or copy the skill folder (.github/skills/security-planner in EmeaAppGbb/spec2cloud) into .agents/skills/security-planner in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EmeaAppGbb/spec2cloud --skill security-planner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-planner, .gemini/skills/security-planner, .github/skills/security-planner and .opencode/skills/security-planner in your project.
SKILL.md names no scripts, command-line tools or credentials: Security Planner is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Planner is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Planner: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Agentlas Security Scan (agentlas-ai/Agentlas-OS, 1.6k stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
EmeaAppGbb (a GitHub organization) maintains it in EmeaAppGbb/spec2cloud, which has 100 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on April 16, 2026.
Source: EmeaAppGbb/spec2cloud on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.