Agent skill

Security Planner

by EmeaAppGbb in EmeaAppGbb/spec2cloud

Create a prioritized security remediation plan from security assessment findings.

MITAuto-check passedSecurity

Install Security Planner

skills CLI
$ npx skills add EmeaAppGbb/spec2cloud --skill security-planner -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install EmeaAppGbb/spec2cloud security-planner --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/EmeaAppGbb/spec2cloud.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/security-planner .claude/skills/security-planner && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-planner
GitHub stars
100
Token cost
~2.5k tokens
SKILL.md length
1,019 words
Files
1
Skills in repo
38
Repo updated
First seen
Licence
MIT

At a glance

Create a prioritized security remediation plan from security assessment findings.

  • Works in 4 steps: Classify Findings by Tier → Scope Each Fix → Define Verification → …
  • Transforming security assessment results into actionable fix items
  • SKILL.md covers Role, Inputs, Priority Tiers and Process, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Planner is an agent skill from EmeaAppGbb/spec2cloud. Create a prioritized security remediation plan from security assessment findings. Critical vulnerabilities first, then hardening improvements. Generate increments that feed into the standard Phase 2 delivery pipeline. Use when transforming security assessment results into actionable fix items.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review. The licence is MIT.

When your agent uses it

  • Transforming security assessment results into actionable fix items
  • Tasks that involve Security review

Example prompts

  • “/security-planner”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Classify Findings by Tier
  2. Scope Each Fix
  3. Define Verification
  4. Order Within Tiers

What it can do on your machine

Read from SKILL.md and the folder at commit 8e76618. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown and json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Planner loads about 2.5k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 1,019 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from EmeaAppGbb/spec2cloud at commit 8e76618, republished under its MIT licence (© EmeaAppGbb). 1,019 words, ~2,542 tokens.

Download SKILL.mdSave it as .claude/skills/security-planner/SKILL.md (or your agent's skills folder).
name
security-planner
description
Create a prioritized security remediation plan from security assessment findings. Critical vulnerabilities first, then hardening improvements. Generate increments that feed into the standard Phase 2 delivery pipeline. Use when transforming security assessment results into actionable fix items.

Security Planner

Role

You are the Security Planner. You transform findings from specs/assessment/security.md into a prioritized sequence of security remediation increments. Critical vulnerabilities are fixed first, then hardening improvements layer on. Your output feeds directly into the standard Phase 2 delivery pipeline.

You do NOT perform the fixes. You produce the plan.

Inputs

Before generating any increments, read:

  1. Security assessment (specs/assessment/security.md) — vulnerability findings, severity ratings, affected components, recommended fixes.
  2. ADRs (specs/adrs/) — security-related architectural decisions (auth strategy, encryption requirements, compliance standards).
  3. Dependency inventory (specs/assessment/dependencies.md) — known CVEs, vulnerable package versions, upgrade paths.
  4. Architecture map (specs/assessment/architecture.md) — attack surface, trust boundaries, data flow.
  5. Existing increment plan (specs/increment-plan.md) — append, never overwrite.

Priority Tiers

Order security increments using this strict priority hierarchy:

Tier 1 — Critical (Immediate)
  • Active CVEs with known exploits — publicly known vulnerabilities with exploit code available. Fix within the current sprint.
  • Authentication bypass — any flaw that allows unauthenticated access to protected resources.
  • Remote code execution — any input that can trigger arbitrary code execution.
  • Data exposure — secrets in source code, unencrypted PII at rest or in transit.
Tier 2 — High
  • Authentication/authorization gaps — missing auth on endpoints, broken access control, privilege escalation paths.
  • Input validation and injection — SQL injection, XSS, command injection, path traversal, SSRF.
  • Session management — weak session tokens, missing expiry, no revocation.
  • Dependency vulnerabilities — CVEs without known exploits but with high CVSS scores (≥7.0).
Tier 3 — Medium
  • Configuration hardening — insecure defaults, verbose error messages in production, missing security headers (CSP, HSTS, X-Frame-Options).
  • Logging and audit — security events not logged, no audit trail for sensitive operations.
  • Compliance gaps — OWASP Top 10 coverage, industry-specific compliance requirements.
Tier 4 — Low
  • Defense-in-depth additions — rate limiting, CAPTCHA, account lockout, honeypot fields.
  • Security monitoring — intrusion detection, anomaly alerting, WAF rules.
  • Future-proofing — algorithm upgrades (e.g., SHA-256 → SHA-3), key rotation automation.

Process

Step 1 — Classify Findings by Tier

Map every finding from the security assessment to a priority tier. If a finding spans multiple tiers, classify it at the highest applicable tier.

Step 2 — Scope Each Fix

For each finding, define the smallest possible change that addresses the vulnerability:

  • What changes: Specific files, functions, configurations.
  • What stays: Everything not directly related to the vulnerability.
  • Blast radius: What could break if the fix is incorrect.

Security fixes must be surgical. No scope creep — fixing a SQL injection vulnerability is not the time to refactor the data access layer.

Step 3 — Define Verification

Each fix needs a test that proves the vulnerability is resolved:

  • Reproduction test — a test that exploits the vulnerability and fails before the fix, passes after.
  • Regression test — existing tests that verify the fix didn't break normal functionality.
  • Security scan — re-run the relevant security scanner to confirm the finding is resolved.
Step 4 — Order Within Tiers

Within each tier, order by:

  1. Fixes with no dependencies come first.
  2. Fixes that unblock other fixes come next.
  3. Quick wins (low effort, high impact) before complex remediations.

Increment Format

Each increment in specs/increment-plan.md follows this template:

markdown
## sec-001: Remediate SQL Injection in Search Endpoint

- **Type:** security
- **Tier:** 2 (High)
- **Vulnerability:** SQL injection via unsanitized user input in
  GET /api/search?q= parameter (finding SEC-2024-007)
- **Scope:** Parameterize SQL query in SearchService.search().
  No other changes.
- **Acceptance Criteria:**
  - [ ] Parameterized query prevents SQL injection payloads
  - [ ] Search functionality returns correct results
  - [ ] All existing search tests pass
- **Test Strategy:**
  - Add injection test: verify malicious input is safely escaped
  - Add boundary test: verify legitimate special characters still work
  - Run full regression suite
  - Re-run SAST scanner to confirm finding cleared
- **Behavioral Deltas:** (Track-dependent — see Behavioral Deltas section)
- **Dependencies:** none
- **Rollback Plan:** Revert SearchService.search() to previous implementation
- **Risk:** Low — isolated change to one method

Output

Append all generated increments to specs/increment-plan.md. Do NOT overwrite existing content. Group by tier with clear section headers.

After appending, update .spec2cloud/state.json:

json
{
  "incrementPlan": [
    { "id": "sec-001", "type": "security", "tier": 2, "status": "planned" },
    { "id": "sec-002", "type": "security", "tier": 1, "status": "planned" }
  ]
}

Append to .spec2cloud/audit.log:

[ISO-timestamp] step=security-planning action=increments-generated count={N} tier-1={N} tier-2={N} tier-3={N} tier-4={N} result=done

Behavioral Deltas

Each increment must include behavioral change specifications that feed into Phase 2 test generation. The format depends on the project's testability track (from .spec2cloud/state.json).

Track A (Testable) — Gherkin Deltas

For each increment, specify which Gherkin scenarios are affected:

  • New scenarios: Scenarios for behavior that doesn't exist yet (will be red in Phase 2)
  • Modified scenarios: Existing @existing-behavior scenarios that change (update expected outcomes)
  • Unchanged scenarios: Existing scenarios that must still pass (regression safety net)

Include Gherkin deltas in the increment format:

- **Gherkin Deltas:**
  - New: `Scenario: {description}` — {why this is needed}
  - Modified: `Scenario: {existing scenario name}` — Then step changes from X to Y
  - Regression: N existing scenarios must still pass unchanged
Show full SKILL.md (421 more words)Show less
Track B (Non-Testable) — Documentation Deltas

For each increment, specify behavioral documentation updates:

  • Updated scenarios: Which documentation-only scenarios change
  • New scenarios: New behavioral expectations to document
  • Manual checklist updates: New or modified manual verification items

Include documentation deltas in the increment format:

- **Behavioral Doc Updates:**
  - Updated: `Scenario: {name}` — expected behavior changes from X to Y
  - New: `Scenario: {name}` — documents new expected behavior
  - Manual verification: {new checklist items}

Self-Review Checklist

Before finalizing, verify:

  • Every Tier 1 finding has a corresponding increment with no blockers.
  • Every increment fixes exactly one vulnerability — no bundling.
  • Each increment has a reproduction test that validates the fix.
  • No increment modifies code beyond what is necessary for the fix.
  • Tier ordering is strict — no Tier 3 increment scheduled before Tier 1.
  • Rollback plans exist for every increment.
  • Dependency ordering within tiers is correct.
  • Acceptance criteria are specific: "input X no longer produces behavior Y".
  • No security fix introduces a new vulnerability (e.g., fixing XSS by disabling output encoding entirely).
  • Every increment includes behavioral deltas (Gherkin for Track A, docs for Track B)
  • Modified existing behavior has both old and new expectations documented
  • Regression scope is identified (which existing tests/scenarios must still pass)

Constraints

  • Smallest possible change. Security fixes must be surgical. Fix the vulnerability, nothing more.
  • No scope creep. Refactoring, modernization, and feature work do NOT belong in security increments. Create separate increments for those.
  • Tier ordering is mandatory. Tier 1 before Tier 2 before Tier 3 before Tier 4. No exceptions.
  • Every fix needs a test. No "just change the config" fixes without a test that verifies the vulnerability is resolved.
  • ADR compliance. Security fixes must align with security-related ADRs. If a fix conflicts with an ADR, flag it for human review.

Handoff

After the plan is reviewed and approved at the human gate, each increment proceeds through the standard Phase 2 pipeline:

  1. Test generation — create reproduction and regression tests for each fix
  2. Contract generation — update contracts if API behavior changes
  3. Implementation — apply the minimal fix
  4. Build & deploy — verify the fix in CI, re-run security scanners

Mandatory Completion Checklist

The orchestrator MUST verify ALL of the following before marking security-planner as complete:

  • specs/increment-plan.md is updated with all security fix increments (unique IDs, scope, severity, effort)
  • Increments are ordered by severity: critical → high → medium → low (no exceptions)
  • Every fix increment has a corresponding reproduction test specified
  • Increments are consistent with security-related ADRs; conflicts are flagged
  • Dependency CVE fixes are separate increments from code-level vulnerability fixes
  • State JSON and audit log are updated

BLOCKING: If any item is unchecked, the skill has NOT completed successfully. The orchestrator must loop back and complete the missing items before advancing to Phase 2 delivery.

© EmeaAppGbb, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/security-planner of EmeaAppGbb/spec2cloud.

Open the folder on GitHubat commit 8e76618

Compare with similar skills

Security Planner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Planner compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Planner this skillEmeaAppGbb/spec2cloud100—~2.5kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Agentlas Security Scanagentlas-ai/Agentlas-OS1.6k1 repos~822Automated safety check: PassApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated today
    SecurityAuto-check: notes
  • Agentlas Security Scan

    agentlas-ai/Agentlas-OS

    A skill your agent uses when an agent folder must pass the Agentlas Cloud 2-stage security scan (static rules + BYOK LLM judgment) before private sync or public publish, or when asked to…

    1.6k GitHub starsUsed in 1 repo~822 tokens
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated today
    SecurityAuto-check: notes
  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from EmeaAppGbb/spec2cloud

All 38 skills in this repo
  • Azure Deployment

    EmeaAppGbb/spec2cloud

    Provision Azure infrastructure, deploy to Azure Container Apps, and verify via smoke tests.

    100 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Contract Generation

    EmeaAppGbb/spec2cloud

    Generate API contracts, shared TypeScript types, and infrastructure resource definitions from Gherkin scenarios and test files.

    100 GitHub stars~1.6k tokensUpdated 5 mo ago
    Auto-check passed
  • Ddd Modeling

    EmeaAppGbb/spec2cloud

    Create Domain-Driven Design proposals from product specs or brownfield extraction outputs.

    100 GitHub stars~2.4k tokensUpdated 5 mo ago
    Auto-check passed
  • Implementation

    EmeaAppGbb/spec2cloud

    Write application code to make failing tests pass using contract-driven, slice-based architecture.

    100 GitHub stars~2.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Spec Refinement

    EmeaAppGbb/spec2cloud

    Review PRDs and FRDs through product and technical lenses. An agent skill from EmeaAppGbb/spec2cloud.

    100 GitHub stars~2.2k tokensUpdated 5 mo ago
    Auto-check passed
  • State Management

    EmeaAppGbb/spec2cloud

    Read, write, and maintain .spec2cloud/state.json across phases and increments.

    100 GitHub stars~1.5k tokensUpdated 5 mo ago
    Auto-check passed

Categories

Questions about Security Planner

What does Security Planner do?

Create a prioritized security remediation plan from security assessment findings. Security Planner is an agent skill from EmeaAppGbb/spec2cloud. Create a prioritized security remediation plan from security assessment findings.

When should I use Security Planner?

Security Planner fits situations like: transforming security assessment results into actionable fix items; tasks that involve Security review.

How do I install Security Planner in Claude Code?

Run `npx skills add EmeaAppGbb/spec2cloud --skill security-planner -a claude-code`. Or copy the skill folder (.github/skills/security-planner in EmeaAppGbb/spec2cloud) into .claude/skills/security-planner in your project. Claude Code loads it when a task matches its description.

How do I install Security Planner in Codex?

Run `npx skills add EmeaAppGbb/spec2cloud --skill security-planner -a codex`. Or copy the skill folder (.github/skills/security-planner in EmeaAppGbb/spec2cloud) into .agents/skills/security-planner in your project. Codex loads it when a task matches its description.

Can I use Security Planner in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EmeaAppGbb/spec2cloud --skill security-planner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-planner, .gemini/skills/security-planner, .github/skills/security-planner and .opencode/skills/security-planner in your project.

What does Security Planner need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Planner is instructions for the agent only.

Does Security Planner access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Planner safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Planner use?

Security Planner is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Planner use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Planner?

Skills that share tags, products or a category with Security Planner: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Agentlas Security Scan (agentlas-ai/Agentlas-OS, 1.6k stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Planner?

EmeaAppGbb (a GitHub organization) maintains it in EmeaAppGbb/spec2cloud, which has 100 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on April 16, 2026.

Source: EmeaAppGbb/spec2cloud on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.