Security review checklist with optional engagement scoping. An agent skill from hashgraph-online/awesome-codex-plugins.

Apache-2.0Auto-check: notesSecurity

Install Secure

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill secure -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins secure --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/epicsagas/epic-harness/skills/secure .claude/skills/secure && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secure
GitHub stars
1.2k
Token cost
~1.5k tokens
SKILL.md length
775 words
Files
1
Skills in repo
686
Repo updated
First seen
Licence
Apache-2.0

At a glance

Security review checklist with optional engagement scoping. An agent skill from hashgraph-online/awesome-codex-plugins.

  • Works in 4 steps: Load Engagement Context (Optional) → Identify Security-Relevant Changes → Run Checklist → …
  • Secrets code is touched
  • SKILL.md covers Iron Law, Process, When to Trigger and Checklist, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Secure is an agent skill from hashgraph-online/awesome-codex-plugins. Security review checklist with optional engagement scoping. Use when auth, DB, API, infra, or secrets code is touched.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is Apache-2.0.

When your agent uses it

  • Secrets code is touched
  • Tasks that involve Security review

Example prompts

  • “/secure”

Requirements

  • Docker

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Load Engagement Context (Optional)
  2. Identify Security-Relevant Changes
  3. Run Checklist
  4. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 78497e5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secure loads about 1.5k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 775 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:71
    - [ ] `.env` files in `.gitignore` — committed `.env` files expose secrets permanently even after deletion (git history
  • NoteMentions a .env fileSKILL.md:101
    - [ ] `.env` in `.gitignore`: confirmed

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 78497e5, republished under its Apache-2.0 licence (© hashgraph-online). 775 words, ~1,519 tokens.

Download SKILL.mdSave it as .claude/skills/secure/SKILL.md (or your agent's skills folder).
name
secure
description
Security review checklist with optional engagement scoping. Use when auth, DB, API, infra, or secrets code is touched.
dimension
control_and_safety

Secure — Security Review

Iron Law

NO DEPLOYMENT WITHOUT SECURITY REVIEW OF ALL CHANGED FILES. Every code change is a potential attack vector.

Process

Step 0: Load Engagement Context (Optional)

Check for engagement scoping:

bash
cat .harness/engagement.md 2>/dev/null

If .harness/engagement.md exists:

  1. Parse the Scope, Constraints, and Exclusions sections
  2. Restrict security checks to in-scope components
  3. Apply rules of engagement (method, rate limits, no-exfil rules)
  4. Skip findings matching exclusion patterns
  5. Include engagement reference in report header

If not found: apply full OWASP Top 10 checklist (default behavior). No scope restrictions.

See references/engagement.md for the engagement file format.

Step 1: Identify Security-Relevant Changes

Identify security-relevant changes from the diff (auth, DB, API, infra, secrets).

Step 2: Run Checklist

Run the Checklist below, marking each item as pass, fail, or N/A with reason.

Step 3: Report

For each failure, cite the file and line number with severity (CRITICAL/HIGH/MEDIUM). Report findings using the Evidence Required section.

When to Trigger

  • Authentication or authorization code changed
  • Database queries written or modified
  • API endpoints added or changed
  • Environment variables or secrets referenced
  • File upload, user input parsing, or serialization code
  • Infrastructure config (Docker, K8s, CI/CD)

Checklist

Injection
  • All user input sanitized/escaped before use in queries — unsanitized input is the #1 attack vector for SQL injection, XSS, and command injection
  • Parameterized queries used (no string concatenation in SQL) — string concatenation enables SQL injection even with escaping; parameterized queries are the only safe default
  • No eval(), exec(), or template injection vectors — these functions execute arbitrary code and bypass all input validation
Authentication & Authorization
  • Auth checks on every protected endpoint — missing checks on a single endpoint exposes the entire system
  • Tokens validated and not just decoded — decoding without signature verification lets attackers forge any token
  • Session expiry and refresh logic correct — stale sessions allow account takeover; refresh token rotation prevents replay attacks
  • No hardcoded credentials or secrets in code — hardcoded secrets end up in version control and are impossible to rotate
Data Exposure
  • Sensitive data not logged (passwords, tokens, PII) — logs are often accessible to more people than the database and persist indefinitely
  • API responses don't leak internal details — stack traces, DB schemas, and server versions help attackers craft targeted exploits
  • Error messages don't reveal system internals — generic errors in production prevent information disclosure; detailed errors belong in server logs only
  • .env files in .gitignore — committed .env files expose secrets permanently even after deletion (git history retains them)
Access Control
  • RBAC/permissions checked before data access — authorization must happen at the data layer, not just the UI layer, to prevent IDOR and privilege escalation
  • No IDOR (Insecure Direct Object Reference) vulnerabilities — replacing an ID in a URL should never grant access to another user's resource
  • Rate limiting on authentication endpoints — without rate limiting, brute-force and credential-stuffing attacks are trivial

See references/security.md for the full OWASP Top 10 checklist.

Show full SKILL.md (309 more words)Show less

Anti-Rationalization

ExcuseRebuttalWhat to do instead
"This is internal-only, no security risk"Internal tools get exposed. Assume every endpoint is public-facing.Apply the same security standards as public APIs.
"We'll add security later"Security debt compounds exponentially. Fix it now or pay 10x later.Build it secure from the start. Retrofitting misses edge cases.
"The framework handles security"Frameworks provide tools, not guarantees. OWASP Top 10 still applies.Verify framework defaults and add application-layer checks.
"Security review is overkill for this"One missed injection is a breach. Every input surface matters.Run the checklist. It takes 2 minutes, a breach takes months.
"We'll harden it before production"Security bolted on later is always incomplete.Build it secure now. Retrofitting misses edge cases.
"It's an internal API, no one will abuse it"Lateral movement attacks start from internal APIs.Internal does not mean trusted. Validate and authorize every request.
"I'll just disable CORS for development"Dev shortcuts leak into production.Use a proper CORS allow-list from day one.
"Engagement scoping is bureaucratic overhead"Unscoped assessments waste time on irrelevant surface area.Define scope once, get focused results. Opt-in only.

Evidence Required

Before claiming security review is complete, show ALL applicable:

  • Checklist above completed: each item marked pass or N/A with reason
  • No secrets in code: grep -r "sk-\|password\s*=" --include="*.{ts,js,py}" . shows clean
  • Parameterized queries used: show the query code (no string concat)
  • Auth checks present on new endpoints: show the middleware/guard
  • .env in .gitignore: confirmed
  • Engagement context loaded (or confirmed absent): scope applied to findings

A blank checklist is not a review. Each item needs a pass or N/A.

Red Flags

  • Storing secrets in code or config files committed to git
  • Using HTTP instead of HTTPS for sensitive data
  • eval() or string-concatenated SQL anywhere
  • Skipping engagement scope when .harness/engagement.md is present
  • Reporting findings outside authorized scope as blockers (informational only)

© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/epicsagas/epic-harness/skills/secure of hashgraph-online/awesome-codex-plugins.

Open the folder on GitHubat commit 78497e5

Compare with similar skills

Secure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secure compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secure this skillhashgraph-online/awesome-codex-plugins1.2k—~1.5kAutomated safety check: NotesApache-2.0
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Agentlas Security Scanagentlas-ai/Agentlas-OS1.6k1 repos~822Automated safety check: PassApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated today
    SecurityAuto-check: notes
  • Agentlas Security Scan

    agentlas-ai/Agentlas-OS

    A skill your agent uses when an agent folder must pass the Agentlas Cloud 2-stage security scan (static rules + BYOK LLM judgment) before private sync or public publish, or when asked to…

    1.6k GitHub starsUsed in 1 repo~822 tokens
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated today
    SecurityAuto-check: notes
  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from hashgraph-online/awesome-codex-plugins

All 686 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.2k GitHub stars~922 tokensUpdated today
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.2k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.2k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.2k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.2k GitHub stars~618 tokensUpdated today
    Auto-check passed
  • Manuscript Engagement Analytics

    hashgraph-online/awesome-codex-plugins

    Analyze nonfiction manuscripts for reader engagement signals, including heading-level word counts, slow starts, long slogs, weak takeaway titles, value pacing, beta-reader comment dropoff, and…

    1.2k GitHub stars~875 tokensUpdated today
    Auto-check passed

Categories

Questions about Secure

What does Secure do?

Security review checklist with optional engagement scoping. An agent skill from hashgraph-online/awesome-codex-plugins. Secure is an agent skill from hashgraph-online/awesome-codex-plugins. Security review checklist with optional engagement scoping.

When should I use Secure?

Secure fits situations like: secrets code is touched; tasks that involve Security review.

How do I install Secure in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill secure -a claude-code`. Or copy the skill folder (plugins/epicsagas/epic-harness/skills/secure in hashgraph-online/awesome-codex-plugins) into .claude/skills/secure in your project. Claude Code loads it when a task matches its description.

How do I install Secure in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill secure -a codex`. Or copy the skill folder (plugins/epicsagas/epic-harness/skills/secure in hashgraph-online/awesome-codex-plugins) into .agents/skills/secure in your project. Codex loads it when a task matches its description.

Can I use Secure in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill secure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secure, .gemini/skills/secure, .github/skills/secure and .opencode/skills/secure in your project.

What does Secure need to run?

SKILL.md names no scripts, command-line tools or credentials: Secure is instructions for the agent only. Our summary lists: Docker.

Does Secure access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Secure safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Secure use?

Secure is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secure use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secure?

Skills that share tags, products or a category with Secure: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Agentlas Security Scan (agentlas-ai/Agentlas-OS, 1.6k stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secure?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,242 GitHub stars. The repository holds 686 skills in this directory. The repository was last updated on October 8, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.