Agent skill

Security Check

by gocronx-team in gocronx-team/gocron

Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

MITAuto-check passedSecurity

Install Security Check

skills CLI
$ npx skills add gocronx-team/gocron --skill security-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install gocronx-team/gocron security-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/gocronx-team/gocron.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-check .claude/skills/security-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-check
GitHub stars
808
Token cost
~690 tokens
SKILL.md length
290 words
Files
3 (incl. scripts)
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

  • Security reviews
  • SKILL.md covers Establish scope and trust…, Run deterministic gates and Triage and report
  • Runs Shell scripts from its folder; calls bash
  • Vulnerability remediation

What it does

Security Check is an agent skill from gocronx-team/gocron. Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities. Use for security reviews, vulnerability remediation, Dependabot security alerts, release hardening, or suspected exposure.

Its SKILL.md is about 690 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `agents/openai.yaml` and `scripts/security_gate.sh`).

It sits in Security, covering Dependency management, Web application vulnerabilities and Monorepo tooling. The repository describes itself as: distributed scheduled task management system. The licence is MIT.

When your agent uses it

  • Security reviews
  • Vulnerability remediation
  • Dependabot security alerts
  • Release hardening

Example prompts

  • “/security-check”

Requirements

  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit e76e9da. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Check loads about 690 tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 290 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~690

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from gocronx-team/gocron at commit e76e9da, republished under its MIT licence (© gocronx-team). 290 words, ~690 tokens.

Download SKILL.mdSave it as .claude/skills/security-check/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
security-check
description
Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities. Use for security reviews, vulnerability remediation, Dependabot security alerts, release hardening, or suspected exposure.

Check gocron security

Default to read-only review. A request to scan or report does not authorize dependency upgrades, source changes, alert dismissal, PR merges, or pushes.

Establish scope and trust boundaries

Inspect the diff when reviewing a change; inspect the relevant data flow when reviewing the repository. Prioritize internet-facing routes, API and agent tokens, password/2FA flows, command execution, host/URL inputs, uploaded/imported data, secret storage, logs, webhooks, AI provider calls, and RPC boundaries.

Check for:

  • missing authentication, authorization, ownership checks, or audit events;
  • SQL/command/template/path injection and unsafe shell construction;
  • SSRF, unrestricted redirects, unsafe downloads, and weak URL validation;
  • plaintext secrets, accidental logging, overly broad tokens, weak signing, insecure randomness, and missing expiry/rotation;
  • mass assignment, unbounded input/body/queue sizes, brute force, and DoS;
  • unsafe CORS/cookies/headers and frontend token exposure;
  • vulnerable direct and transitive dependencies and unsafe container defaults.

Trace sanitizers and middleware to their implementation; do not infer safety from function names. Do not print secret values while investigating.

Run deterministic gates

Run from the repository root:

bash
bash .agents/skills/security-check/scripts/security_gate.sh

The script runs independent checks and continues after failures. Missing tools or network access are SKIP, never PASS. Review git changes afterward because security tools must not silently alter lockfiles.

The default secret scan checks the current working tree. For the slower full-history scan, run:

bash
GOCRON_SECURITY_SCAN_HISTORY=1 bash .agents/skills/security-check/scripts/security_gate.sh

For authorization or input-validation changes, add focused negative tests and run the affected package with -race. Invoke $verify after fixes.

Triage and report

For each finding, provide severity, reachable attack path, affected file:line, evidence, impact, and smallest safe remediation. Distinguish:

  • confirmed exploitable behavior;
  • defense-in-depth improvement;
  • dependency advisory not reachable in this application;
  • false positive with concrete justification.

Never dismiss or ignore an alert solely because tests pass. Do not claim the repository is secure; state the scope covered and skipped checks.

© gocronx-team, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in .agents/skills/security-check of gocronx-team/gocron.

  • SKILL.md
  • agents/openai.yaml
  • scripts/security_gate.sh

Open the folder on GitHubat commit e76e9da

Compare with similar skills

Security Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Check this skillgocronx-team/gocron808—~690Automated safety check: PassMIT
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Discover Securityrand/cc-polymath181—~1.9kAutomated safety check: PassMIT
Security Auditorcuriositech/some_claude_skills243—~2.2kAutomated safety check: PassMIT
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Strix Code Vulnerability Scanusestrix/strix67k—~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Discover Security

    rand/cc-polymath

    Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management.

    181 GitHub stars~1.9k tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • Security Auditor

    curiositech/some_claude_skills

    Security vulnerability scanner and OWASP compliance auditor for codebases.

    243 GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    67k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed

More from gocronx-team/gocron

All 8 skills in this repo
  • Migration

    gocronx-team/gocron

    Create, review, or verify gocron database migrations across SQLite, MySQL, and PostgreSQL.

    808 GitHub stars~1.1k tokensUpdated 6 days ago
    Auto-check passed
  • Dependency Update

    gocronx-team/gocron

    Review, apply, verify, or merge gocron dependency updates from Dependabot or manual requests.

    808 GitHub stars~891 tokensUpdated 6 days ago
    Auto-check passed
  • Scheduler Change

    gocronx-team/gocron

    Safely implement, diagnose, or review changes to gocron scheduling and task execution.

    808 GitHub stars~1.1k tokensUpdated 6 days ago
    Auto-check passed
  • API Feature

    gocronx-team/gocron

    Implement or review an end-to-end gocron HTTP API change. An agent skill from gocronx-team/gocron.

    808 GitHub stars~1.2k tokensUpdated 6 days ago
    Auto-check passed
  • Release

    gocronx-team/gocron

    Prepare or publish a safe gocron release by choosing a SemVer bump, updating AppVersion and migrations, invoking the complete verification gate, committing, checking CI, and creating an annotated tag.

    808 GitHub stars~1.1k tokensUpdated 6 days ago
    Auto-check passed
  • Release

    gocronx-team/gocron

    Cut a gocron release — bump AppVersion, align the migration version id, run the full CI check locally, and tag only when everything is green.

    808 GitHub stars~586 tokensUpdated 6 days ago
    Auto-check passed

Categories

Questions about Security Check

What does Security Check do?

Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities. Security Check is an agent skill from gocronx-team/gocron. Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

When should I use Security Check?

Security Check fits situations like: security reviews; vulnerability remediation; dependabot security alerts; release hardening.

How do I install Security Check in Claude Code?

Run `npx skills add gocronx-team/gocron --skill security-check -a claude-code`. Or copy the skill folder (.agents/skills/security-check in gocronx-team/gocron) into .claude/skills/security-check in your project. Claude Code loads it when a task matches its description.

How do I install Security Check in Codex?

Run `npx skills add gocronx-team/gocron --skill security-check -a codex`. Or copy the skill folder (.agents/skills/security-check in gocronx-team/gocron) into .agents/skills/security-check in your project. Codex loads it when a task matches its description.

Can I use Security Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gocronx-team/gocron --skill security-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-check, .gemini/skills/security-check, .github/skills/security-check and .opencode/skills/security-check in your project.

What does Security Check need to run?

Going by SKILL.md and its folder, Security Check needs a shell for the scripts in its folder and the command-line tools its instructions call (bash). Our summary lists: A Bash shell.

Does Security Check access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Check use?

Security Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Check use?

About 690 tokens (SKILL.md is roughly 2.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Check?

Skills that share tags, products or a category with Security Check: Security Review (github/awesome-copilot, 40k stars), Discover Security (rand/cc-polymath, 181 stars), Security Auditor (curiositech/some_claude_skills, 243 stars) and Security Auditor (eigent-ai/eigent, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Check?

gocronx-team (a GitHub organization) maintains it in gocronx-team/gocron, which has 808 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 2, 2026.

Source: gocronx-team/gocron on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.