Agent skill

Threat Database Update

by FlorianBruniaux in FlorianBruniaux/claude-code-ultimate-guide

Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed.

CC-BY-SA-4.0Auto-check passedSecurity

Install Threat Database Update

skills CLI
$ npx skills add FlorianBruniaux/claude-code-ultimate-guide --skill update-threat-db -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install FlorianBruniaux/claude-code-ultimate-guide update-threat-db --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/FlorianBruniaux/claude-code-ultimate-guide.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/update-threat-db .claude/skills/update-threat-db && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
update-threat-db
GitHub stars
6.1k
Token cost
~680 tokens
SKILL.md length
309 words
Files
2
Skills in repo
14
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed.

  • Works in 5 steps: Pass the AgentSec validation gates and… → Synchronize the approved public feed… → Refresh the guide's compatibility… → …
  • Refreshing the guide's threat database with new coding-agent advisories
  • SKILL.md covers Resolve the workflow, Evidence and changes and Completion checks
  • Calls python3

What it does

The skill is scoped to the Claude Code guide repository and its AgentSec and landing consumers, and it does not change global agent configuration. It reads the update-threat-db command file from the guide root in full, resolves the AgentSec checkout from AGENTSEC_REPO or the sibling ../agentsec-triage, verifies the required files, and runs that workflow. The research window runs from the last recorded update date through today, and unrelated edits in every checkout are preserved.

New records are accepted only after reviewing primary sources. Evidence sources, dated events, exact detector inputs and the public feed stay separate, affected ranges and fixed versions are recorded only when a source supports them, CVE and GHSA aliases are deduplicated, and corrections become dated events. A regression test comes before each accepted change, detection states stay distinct (detected, partial, not_detected, not_applicable), and malicious samples are never run.

Completion requires passing the AgentSec validation gates twice without drift, syncing the approved feed into the guide and landing with byte equality, refreshing the compatibility database and changelogs, and running a check with scripts/sync-threat-skill.py. Commit, push, tagging and publication are separate states that need their own authorization.

When your agent uses it

  • Refreshing the guide's threat database with new coding-agent advisories
  • Researching new MCP security advisories and adding vetted records
  • Synchronizing the approved security feed into the guide and landing page

Example prompts

  • “Update the threat database and report the research window and accepted records.”
  • “Research new MCP server advisories since the last update and add regression-tested records.”
  • “Sync the approved public feed into the guide and landing, and verify they match byte for byte.”

Requirements

  • A checkout of AgentSec Triage
  • Python 3 for scripts/sync-threat-skill.py

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Pass the AgentSec validation gates and regenerate artifacts twice without drift.
  2. Synchronize the approved public feed into the guide and landing; verify byte
  3. Refresh the guide's compatibility database and reader guidance only after the
  4. Run python3 scripts/sync-threat-skill.py --check after editing this skill or
  5. Report the research window, accepted and deferred records, detector limits,

What it can do on your machine

Read from SKILL.md and the folder at commit f499217. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Threat Database Update loads about 680 tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 309 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~680

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from FlorianBruniaux/claude-code-ultimate-guide at commit f499217, republished under its CC-BY-SA-4.0 licence (© FlorianBruniaux). 309 words, ~680 tokens.

Download SKILL.mdSave it as .claude/skills/update-threat-db/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
update-threat-db
description
Update the guide's threat intelligence through AgentSec Triage, research new coding-agent and MCP security advisories, and synchronize the security feed. Use for threat database refreshes or mise a jour de la base de menaces, not repository security scans or Claude Code release tracking.

Update threat intelligence through AgentSec

Scope: this guide repository and its AgentSec and landing consumers. This skill does not change global agent configuration. Its canonical source is .claude/skills/update-threat-db/; regenerate the Codex projection with python3 scripts/sync-threat-skill.py --write from the guide root.

Resolve the workflow

Read .claude/commands/update-threat-db.md from the guide root in full. It owns the delegation contract and consumer checks. Resolve AGENTSEC_REPO if set, otherwise the sibling ../agentsec-triage. Verify the required files before continuing. Do not silently substitute the guide's compatibility database.

Read the resolved AgentSec AGENTS.md and .claude/commands/update-threat-db.md in full, then execute that workflow. Preserve unrelated edits in all checkouts. Use the latest recorded update date through today's date as the research window.

Evidence and changes

Review primary sources before accepting new records. Keep the evidence sources, dated events, exact detector inputs and public feed as separate artifacts. Record affected ranges, fixed versions and uncertainty only when the source supports them. Deduplicate CVE/GHSA aliases. Keep corrections as dated events.

Add the required regression test before each accepted data change. Distinguish detected, partial, not_detected and not_applicable; a documented CVE does not prove executable detection. Do not run malicious samples.

Completion checks

  1. Pass the AgentSec validation gates and regenerate artifacts twice without drift.
  2. Synchronize the approved public feed into the guide and landing; verify byte equality and run each consumer's integration checks.
  3. Refresh the guide's compatibility database and reader guidance only after the canonical records pass. Update each affected repository's changelog.
  4. Run python3 scripts/sync-threat-skill.py --check after editing this skill or its routing scenarios. Validate both host routes with the installed router.
  5. Report the research window, accepted and deferred records, detector limits, file changes, validation results and synchronization state.

Commit, push, tagging and publication are separate states. Follow AgentSec's authorization and data-license boundaries; a local update does not authorize a public release. State any unfinished gate explicitly.

© FlorianBruniaux, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/update-threat-db of FlorianBruniaux/claude-code-ultimate-guide.

  • SKILL.md
  • evals/scenarios.json

Open the folder on GitHubat commit f499217

Compare with similar skills

Threat Database Update next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Threat Database Update compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Threat Database Update this skillFlorianBruniaux/claude-code-ultimate-guide6.1k—~680Automated safety check: PassCC-BY-SA-4.0
Skill InspectorNVIDIA/SkillSpector20k—~1.8kAutomated safety check: PassApache-2.0
Forensifyalexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesCustom licence
Slowmist Agent Securityslowmist/slowmist-agent-security508—~1.4kAutomated safety check: PassMIT
AI SAFE2 Secure Build CopilotCyberStrategyInstitute/ai-safe2-framework147—~1.2kAutomated safety check: PassCustom licence
China AI Compliance AuditjnMetaCode/shellward140—~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • Skill Inspector

    NVIDIA/SkillSpector

    Official

    Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

    20k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    190 GitHub stars~2.5k tokensUpdated 14 days ago
    SecurityAuto-check: notes
  • Slowmist Agent Security

    slowmist/slowmist-agent-security

    Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security.

    508 GitHub stars~1.4k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • AI SAFE2 Secure Build Copilot

    CyberStrategyInstitute/ai-safe2-framework

    Applies the AI SAFE2 framework to security reviews, code reviews and compliance mapping for AI agents, RAG pipelines and MCP servers.

    147 GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • China AI Compliance Audit

    jnMetaCode/shellward

    按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's…

    140 GitHub stars~1.1k tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Reins Runtime Security

    pegasi-ai/reins

    Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision.

    392 GitHub stars~1.4k tokensUpdated yesterday
    SecurityAuto-check: warnings

More from FlorianBruniaux/claude-code-ultimate-guide

All 14 skills in this repo
  • Changelog Social Recap

    FlorianBruniaux/claude-code-ultimate-guide

    Turns CHANGELOG.md entries for a release or a week into LinkedIn, Twitter/X, newsletter and Slack posts in French and English.

    6.1k GitHub stars~1.8k tokensUpdated today
    Auto-check: notes
  • Codex Skill Self-Assessment

    FlorianBruniaux/claude-code-ultimate-guide

    Runs an interactive quiz in a quick or comprehensive mode, scores your skill level by topic and generates a personalized learning path with practice projects.

    6.1k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Whitepaper Bare Section Prose Filler

    FlorianBruniaux/claude-code-ultimate-guide

    Adds two to four sentences of intro prose before each bare heading in the French and English whitepapers, splitting the work across nine parallel agents.

    6.1k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Audit Whitepapers

    FlorianBruniaux/claude-code-ultimate-guide

    Audits version freshness, French and English parity and metadata of whitepapers and recap cards in the claude-code-ultimate-guide repo, with optional fix suggestions.

    6.1k GitHub stars~3.8k tokensUpdated today
    Auto-check passed
  • Methodology Advisor

    FlorianBruniaux/claude-code-ultimate-guide

    Reads a codebase silently, asks only what it cannot infer, and recommends one AI-assisted development methodology stack with a contextual quick start.

    6.1k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Guide and Landing Sync Check

    FlorianBruniaux/claude-code-ultimate-guide

    Check guide/landing synchronization status

    6.1k GitHub stars~692 tokensUpdated today
    Auto-check passed

Categories

Questions about Threat Database Update

What does Threat Database Update do?

Refreshes the guide's coding-agent and MCP security threat data through AgentSec Triage: research advisories, add tested records and synchronize the public feed. The skill is scoped to the Claude Code guide repository and its AgentSec and landing consumers, and it does not change global agent configuration./agentsec-triage, verifies the required files, and runs that workflow.

When should I use Threat Database Update?

Threat Database Update fits situations like: refreshing the guide's threat database with new coding-agent advisories; researching new MCP security advisories and adding vetted records; synchronizing the approved security feed into the guide and landing page.

How do I install Threat Database Update in Claude Code?

Run `npx skills add FlorianBruniaux/claude-code-ultimate-guide --skill update-threat-db -a claude-code`. Or copy the skill folder (.agents/skills/update-threat-db in FlorianBruniaux/claude-code-ultimate-guide) into .claude/skills/update-threat-db in your project. Claude Code loads it when a task matches its description.

How do I install Threat Database Update in Codex?

Run `npx skills add FlorianBruniaux/claude-code-ultimate-guide --skill update-threat-db -a codex`. Or copy the skill folder (.agents/skills/update-threat-db in FlorianBruniaux/claude-code-ultimate-guide) into .agents/skills/update-threat-db in your project. Codex loads it when a task matches its description.

Can I use Threat Database Update in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FlorianBruniaux/claude-code-ultimate-guide --skill update-threat-db -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-threat-db, .gemini/skills/update-threat-db, .github/skills/update-threat-db and .opencode/skills/update-threat-db in your project.

What does Threat Database Update need to run?

Going by SKILL.md and its folder, Threat Database Update needs the command-line tools its instructions call (python3). Our summary lists: A checkout of AgentSec Triage; Python 3 for scripts/sync-threat-skill.py.

Does Threat Database Update access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Threat Database Update safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Threat Database Update use?

Threat Database Update is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Threat Database Update use?

About 680 tokens (SKILL.md is roughly 2.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Threat Database Update?

Skills that share tags, products or a category with Threat Database Update: Skill Inspector (NVIDIA/SkillSpector, 20k stars), Forensify (alexgreensh/repo-forensics, 190 stars), Slowmist Agent Security (slowmist/slowmist-agent-security, 508 stars) and AI SAFE2 Secure Build Copilot (CyberStrategyInstitute/ai-safe2-framework, 147 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Threat Database Update?

FlorianBruniaux (a GitHub user) maintains it in FlorianBruniaux/claude-code-ultimate-guide, which has 6,143 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 10, 2026.

Source: FlorianBruniaux/claude-code-ultimate-guide on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.