Agent skill

Security Verification Gate

by fengshao1227 in fengshao1227/ccg-workflow

Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

MITAuto-check: notesSecurity

SKILL.md written in Chinese; this summary is our English description.

Install Security Verification Gate

skills CLI
$ npx skills add fengshao1227/ccg-workflow --skill verify-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install fengshao1227/ccg-workflow verify-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/fengshao1227/ccg-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/dsh-ccg/skills/verify-security .claude/skills/verify-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify-security
GitHub stars
5.9k
Token cost
~621 tokens
SKILL.md length
79 words
Files
2 (incl. scripts)
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

  • Scanning a codebase for common vulnerability patterns before delivery
  • SKILL.md covers 核心原则, 自动扫描, 检测范围 and 危险模式速查, plus 3 more sections
  • Runs JavaScript scripts from its folder; calls node
  • Checking that authentication or encryption changes have documented security decisions

What it does

The skill is written in Chinese and acts as a gate on security-relevant work, holding that security decisions must be traceable and that Critical and High issues be fixed before delivery. It runs `node scripts/security_scanner.js` on a path, with a verbose flag, and groups findings by severity: injection and hardcoded secrets as Critical, XSS, unsafe deserialization, path traversal, SSRF and XXE as High, weak hashes and insecure randomness as Medium, and leftover debug code as Low.

Beyond the scan, it checks that security-related code has a DESIGN.md recording the threat model, the security decisions, trust boundaries and accepted risks. Quick-reference lists of dangerous patterns cover Python, JavaScript and Go, such as eval and shell execution. It triggers on new modules, changes to authentication, authorization, encryption or input handling, red and blue team tasks, finished refactors and before commits, and ends with a pass or fail report.

When your agent uses it

  • Scanning a codebase for common vulnerability patterns before delivery
  • Checking that authentication or encryption changes have documented security decisions
  • Looking for hardcoded keys, injection and XSS risks after a refactor

Example prompts

  • “Run a security scan on ./src and list the Critical and High findings.”
  • “Check whether our new auth module documents its threat model and trust boundaries.”
  • “Verify security before I commit and tell me what must be fixed first.”

Requirements

  • Node.js 18 or later
  • Compatibility (from SKILL.md): node>=18
  • Pre-approved tools (allowed-tools): Bash, Read, Grep

What it can do on your machine

Read from SKILL.md and the folder at commit f349e3d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    node>=18

    From compatibility in the SKILL.md frontmatter.

Context cost

Security Verification Gate loads about 621 tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 79 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~621

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from fengshao1227/ccg-workflow at commit f349e3d, republished under its MIT licence (© fengshao1227). 79 words, ~621 tokens.

Download SKILL.mdSave it as .claude/skills/verify-security/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
verify-security
description
安全校验关卡。自动扫描代码安全漏洞,检测危险模式,确保安全决策有文档记录。当用户提到安全扫描、漏洞检测、安全审计、代码安全、OWASP、注入检测、敏感信息泄露时使用。在新建模块、安全相关变更、攻防任务、重构完成时自动触发。
allowed-tools
Bash, Read, Grep
compatibility
node>=18
license
MIT
user-invocable
true
disable-model-invocation
false
argument-hint
<扫描路径>

⚖ 校验关卡 · 安全校验

核心原则

安全即道基,破则劫败
安全决策必须可追溯
Critical/High 问题必须修复后才能交付

自动扫描

运行安全扫描脚本(跨平台):

bash
# 在 skill 目录下运行
node scripts/security_scanner.js <扫描路径>
node scripts/security_scanner.js <扫描路径> -v           # 详细模式
node scripts/security_scanner.js <扫描路径> --json       # JSON 输出
node scripts/security_scanner.js <扫描路径> --exclude vendor  # 排除目录

检测范围

自动检测的漏洞类型
类别检测项严重度
注入SQL 注入、命令注入、代码注入🔴 Critical
敏感信息硬编码密钥、AWS Key、私钥🔴 Critical
XSSinnerHTML、dangerouslySetInnerHTML🟠 High
反序列化pickle.loads、yaml.load🟠 High
路径遍历未验证的文件路径操作🟠 High
SSRF未验证的 URL 请求🟠 High
XXE不安全的 XML 解析🟠 High
弱加密MD5、SHA1 用于安全场景🟡 Medium
不安全随机random 模块用于安全场景🟡 Medium
调试代码console.log、print、debugger🔵 Low
文档层面检查

安全相关代码必须在 DESIGN.md 中记录:

  • 威胁模型 — 防御哪些攻击
  • 安全决策 — 为何选择此方案
  • 安全边界 — 信任边界在哪里
  • 已知风险 — 接受了哪些风险

危险模式速查

Python
python
# 🔴 危险 - 触犯道基
eval(), exec(), os.system()
subprocess(..., shell=True)
pickle.loads(), yaml.load()
cursor.execute(f"SELECT * FROM t WHERE id = {id}")

# ✅ 安全替代 - 道基稳固
ast.literal_eval()
subprocess([...], shell=False)
yaml.safe_load()
cursor.execute("SELECT * FROM t WHERE id = %s", (id,))
JavaScript
javascript
// 🔴 危险 - 触犯道基
eval(), innerHTML, document.write()
new Function(userInput)

// ✅ 安全替代 - 道基稳固
JSON.parse(), textContent
模板引擎自动转义
Go
go
// 🔴 危险 - 触犯道基
exec.Command("sh", "-c", userInput)
template.HTML(userInput)

// ✅ 安全替代 - 道基稳固
exec.Command("cmd", args...)
html/template 自动转义

校验流程

1. 运行 security_scanner.js 自动扫描
2. 分析扫描结果,按严重度排序
3. 检查安全决策是否有文档记录
4. 输出安全校验报告
5. Critical/High 问题必须修复后才能交付

自动触发时机

场景触发条件
新建模块模块创建完成时
安全相关变更涉及认证、授权、加密、输入处理
攻防任务红队/蓝队任务完成时
重构完成重构任务完成时
提交前代码提交前检查

校验报告格式

## 安全校验报告

✓ 通过 | ✗ 未通过

- 🔴 Critical: N
- 🟠 High: N
- 🟡 Medium: N
- 🔵 Low: N

### 发现问题

| 文件 | 行号 | 类型 | 严重度 | 描述 |
|------|------|------|--------|------|
| ... | ... | ... | ... | ... |

### 结论

可交付 / 需修复后交付

© fengshao1227, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in dsh-ccg/skills/verify-security of fengshao1227/ccg-workflow.

  • SKILL.md
  • scripts/security_scanner.js

Open the folder on GitHubat commit f349e3d

Compare with similar skills

Security Verification Gate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Verification Gate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Verification Gate this skillfengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Cyber NeoHainrixz/cyber-neo283—~5.9kAutomated safety check: WarnMIT
Constant-Time Analysistrailofbits/skills7.4k—~3.3kAutomated safety check: NotesCC-BY-SA-4.0
Taint Instrumentation AssistantArabelaTso/Skills-4-SE253—~2.9kAutomated safety check: PassApache-2.0
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT

Similar skills

  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    283 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Constant-Time Analysis

    trailofbits/skills

    Official

    Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

    7.4k GitHub stars~3.3k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Taint Instrumentation Assistant

    ArabelaTso/Skills-4-SE

    Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations.

    253 GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Xss Prevention

    secondsky/claude-skills

    XSS attack prevention with input sanitization, output encoding, Content Security Policy.

    227 GitHub stars~1.5k tokensUpdated 11 days ago
    SecurityAuto-check passed

More from fengshao1227/ccg-workflow

  • Change Verification Gate

    fengshao1227/ccg-workflow

    Analyzes a code diff for documentation sync, test coverage and impact scope, warning when docs or tests lag behind a design-level change or a large edit.

    5.9k GitHub stars~511 tokensUpdated 24 days ago
    Auto-check: notes
  • Module Completeness Check

    fengshao1227/ccg-workflow

    Scans a module directory for the required README.md and DESIGN.md plus recommended files and reports what is missing, so a module is not delivered incomplete.

    5.9k GitHub stars~473 tokensUpdated 24 days ago
    Auto-check: notes
  • Code Quality Gate

    fengshao1227/ccg-workflow

    Scans code for complexity, long functions, duplicated blocks, naming problems and code smells with a Node script, then reports and suggests refactors.

    5.9k GitHub stars~593 tokensUpdated 24 days ago
    Auto-check: notes
  • README and DESIGN Generator

    fengshao1227/ccg-workflow

    Generates README.md and DESIGN.md skeletons for a module by scanning its structure with a Node script, then lists what to fill in by hand.

    5.9k GitHub stars~410 tokensUpdated 24 days ago
    Auto-check: notes
  • Ccg Workflow

    fengshao1227/ccg-workflow

    How to run a non-trivial change end to end with the CCG role tools (ccganalyze / ccgdesign / ccgbuild / ccgdebug / ccgoptimize / ccgreview / ccgtest) and the verify- quality gates.

    5.9k GitHub stars~2.3k tokensUpdated 24 days ago
    Auto-check passed

Categories

Questions about Security Verification Gate

What does Security Verification Gate do?

Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented. The skill is written in Chinese and acts as a gate on security-relevant work, holding that security decisions must be traceable and that Critical and High issues be fixed before delivery.js` on a path, with a verbose flag, and groups findings by severity: injection and hardcoded secrets as Critical, XSS, unsafe deserialization, path traversal, SSRF and XXE as High, weak hashes and insecure randomness as Medium, and leftover debug code as Low.

When should I use Security Verification Gate?

Security Verification Gate fits situations like: scanning a codebase for common vulnerability patterns before delivery; checking that authentication or encryption changes have documented security decisions; looking for hardcoded keys, injection and XSS risks after a refactor.

How do I install Security Verification Gate in Claude Code?

Run `npx skills add fengshao1227/ccg-workflow --skill verify-security -a claude-code`. Or copy the skill folder (dsh-ccg/skills/verify-security in fengshao1227/ccg-workflow) into .claude/skills/verify-security in your project. Claude Code loads it when a task matches its description.

How do I install Security Verification Gate in Codex?

Run `npx skills add fengshao1227/ccg-workflow --skill verify-security -a codex`. Or copy the skill folder (dsh-ccg/skills/verify-security in fengshao1227/ccg-workflow) into .agents/skills/verify-security in your project. Codex loads it when a task matches its description.

Can I use Security Verification Gate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fengshao1227/ccg-workflow --skill verify-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-security, .gemini/skills/verify-security, .github/skills/verify-security and .opencode/skills/verify-security in your project.

What does Security Verification Gate need to run?

Going by SKILL.md and its folder, Security Verification Gate needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js 18 or later. Its frontmatter pre-approves these tools: Bash, Read, Grep. Compatibility (from SKILL.md): node>=18.

Does Security Verification Gate access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Verification Gate safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Verification Gate use?

Security Verification Gate is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Verification Gate use?

About 621 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Verification Gate?

Skills that share tags, products or a category with Security Verification Gate: CodeQL Security Scan (trailofbits/skills, 7.4k stars), Cyber Neo (Hainrixz/cyber-neo, 283 stars), Constant-Time Analysis (trailofbits/skills, 7.4k stars) and Taint Instrumentation Assistant (ArabelaTso/Skills-4-SE, 253 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Verification Gate?

fengshao1227 (a GitHub user) maintains it in fengshao1227/ccg-workflow, which has 5,932 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 15, 2026.

Source: fengshao1227/ccg-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.