Agent skill

Security Monitoring

by ibuilder in ibuilder/massing

How to monitor and fix security issues in Massing — CodeQL alerts, dependency audits, secret scanning, and ReDoS/XXE fixes.

MITAuto-check passedSecurity

Install Security Monitoring

skills CLI
$ npx skills add ibuilder/massing --skill security-monitoring -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ibuilder/massing security-monitoring --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ibuilder/massing.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/security-monitoring .claude/skills/security-monitoring && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-monitoring
GitHub stars
122
Token cost
~1.7k tokens
SKILL.md length
669 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

How to monitor and fix security issues in Massing — CodeQL alerts, dependency audits, secret scanning, and ReDoS/XXE fixes.

  • Tasks that involve Static analysis and SAST
  • SKILL.md covers CodeQL — check ALERTS, not run…, Common fixes, Local audits (run before a… and SEC-DATAFLOW — where to spend…, plus 3 more sections
  • Calls gh, python and npm
  • Tasks that involve Secrets management

What it does

Security Monitoring is an agent skill from ibuilder/massing. How to monitor and fix security issues in Massing — CodeQL alerts, dependency audits, secret scanning, and ReDoS/XXE fixes. Invoke after a push (standing directive) or when doing a hardening pass. Emphasises that a green CodeQL run != zero alerts.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Static analysis and SAST and Secrets management. The repository describes itself as: Open, self-hosted, IFC-native AEC platform: web BIM viewer + modeling, a ~100-module GC portal (RFIs, pay apps, CPM, construction accounting — double-entry GL/WIP → QuickBooks… The licence is MIT.

When your agent uses it

  • Tasks that involve Static analysis and SAST
  • Tasks that involve Secrets management

Example prompts

  • “/security-monitoring”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 523e5b3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • python
    • npm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, npm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Monitoring loads about 1.7k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 669 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ibuilder/massing at commit 523e5b3, republished under its MIT licence (© ibuilder). 669 words, ~1,748 tokens.

Download SKILL.mdSave it as .claude/skills/security-monitoring/SKILL.md (or your agent's skills folder).
name
security-monitoring
description
How to monitor and fix security issues in Massing — CodeQL alerts, dependency audits, secret scanning, and ReDoS/XXE fixes. Invoke after a push (standing directive) or when doing a hardening pass. Emphasises that a green CodeQL *run* != zero alerts.

Security monitoring — Massing

Standing directions for this repo: docs/roadmap-directions.md. Read those first.

Standing directive: check CodeQL after every push and fix any HIGH that appears.

CodeQL — check ALERTS, not run status

A "CodeQL Advanced" workflow run showing completed success only means the scan executed — it does NOT mean zero alerts. Alerts live in the code-scanning API:

gh api repos/ibuilder/massing/code-scanning/alerts --jq '[.[] | select(.state=="open")] | length'
gh api "repos/ibuilder/massing/code-scanning/alerts?state=open&per_page=30" \
  --jq '.[] | "\(.rule.security_severity_level // .rule.severity) | \(.rule.id) | \(.most_recent_instance.location.path):\(.most_recent_instance.location.start_line)"'

After pushing a fix, wait for the next CodeQL run to re-scan, then re-query — the count drops when alerts auto-close.

Common fixes

  • py/polynomial-redos (ReDoS): a free-text scanner using unbounded \d+ / [\d,]+ / \s* under re.search re-scans → polynomial on a crafted long string. Fix: bound the quantifiers ({1,n} not +/*) and cap the input (text[:20_000]) before the regex. Verify detection still works on real inputs + a 100k-char crafted input returns in <100 ms.
  • XXE: parse untrusted XML with defusedxml.ElementTree.fromstring (catch ET.ParseError + defusedxml.common.DefusedXmlException → return empty). Never bare xml.etree.
  • Weak-hash flags (py/weak-sensitive-data-hashing, bandit B324): SHA-1/MD5 used for non-crypto identity/cache keys → add usedforsecurity=False.

Local audits (run before a hardening release)

cd apps/web && npm audit --omit=dev
cd services/api && ./.venv/Scripts/python.exe -m bandit -r src ../data/src -ll -ii     # HIGH+MED, high-confidence
cd services/api && ./.venv/Scripts/python.exe -m pip_audit --progress-spinner off       # pip install pip-audit first
# secret scan (no gitleaks): grep the source tree for high-signal patterns, exclude node_modules/venv/tests

Pin CVE'd transitive deps in services/data/requirements.txt (e.g. pillow>=12.3.0).

SEC-DATAFLOW — where to spend review effort (empirical, from vuln-localization research)

Difficulty follows structure, not severity: multi-file / cross-import data flows are the hardest class to localize and the least covered by SAST pattern matching. Prioritize hand/agentic review on flows spanning router → dependency helper → model/engine → storage (request data crossing module boundaries), not single-file sinks CodeQL already patterns. SAST is coverage-limited by its rules; the search→verify→refine agentic review (the security-review subagent + this checklist) is the complement, not a duplicate.

Hand-audit checklist (HARDEN passes — beyond CodeQL's reach)

Run over a release range (git diff vX..vY --stat, then read the changed files). Every class below produced a real finding in the v0.3.510 HARDEN-2 pass:

  • Privilege side doors: a stricter endpoint (admin + audited) whose work is ALSO reachable through a generic gate — the job queue (routers/jobs.py _KIND_MIN_ROLE), bulk endpoints, MCP dispatch. New privileged operations must gate every path, not just the front door, and audit each.
  • Unbounded stored data → cheap-GET amplification: anything an editor stores that a viewer-level GET later evaluates (rules, configs, lists) needs count/size caps at save (rule_library.MAX_* is the pattern; schedule_baselines._MAX too).
  • Payload caps must keep the NEWEST rows: order_by(asc).limit() silently hides everything created after row N — cap with desc().limit() then re-sort ascending for stable display.
  • innerHTML interpolation: any file/server/model-derived free-text must pass esc() (panels, from ui/charts) or escapeHtml (viewer). Numbers/.toFixed/server-constant labels are fine. CodeQL catches some (js/xss-through-dom) but not all sinks.
  • Hand-rolled parsers: operator splitting must be leftmost + quote-aware (the QUERY-DSL _find_op fix); validate what stored selectors will DO, not just that they parse — a silently-never-matching rule is a false "pass" downstream.
  • Serializer/format parity on swaps: replacing a serializer (orjson) or parser needs the FULL suite as the parity gate + explicit deltas checked: non-str keys, float subclasses (numpy.float64), NaN/Infinity, tuples/sets, str subclasses.
  • Live-UI teardown: modal/panel tools with timers or visibility state need an onClose hook (ui/result.ts showResult(title, render, onClose)) — closing must stop timers + restore state.
  • External-format imports: skip container/rollup rows (MSPDI <Summary>1</Summary>; XER non-TASK tables) — named+dated summary rows import as phantom records otherwise.
Show full SKILL.md (170 more words)Show less

SEC-SUPPLY — license / SBOM audit (run before a hardening release)

aec_api.supply_chain is a dependency-free (stdlib importlib.metadata) supply-chain tool:

cd services/api && PYTHONPATH="src;../data/src" ./.venv/Scripts/python.exe -m aec_api.supply_chain          # informational
cd services/api && PYTHONPATH="src;../data/src" ./.venv/Scripts/python.exe -m aec_api.supply_chain --gate    # exit 1 on STRONG copyleft
  • Classifies every installed distribution's license: permitted (MIT/BSD/Apache/ISC/PSF/Unlicense/Zlib) · copyleft · unknown, splitting STRONG (GPL/AGPL — the disallowed hard line) from weak (LGPL/MPL — accepted for the ifcopenshell/certifi core deps, but surfaced). Word-boundary matched (naive substring makes "EXEMPLARY" false-match mpl).
  • --gate fails only on STRONG copyleft, so it never breaks CI over the known LGPL/MPL core deps. Known strong hits are venv-incidental, NOT declared deps (e.g. pymupdf/AGPL, pyinstaller/GPL build tool) — confirm a strong hit is absent from services/*/requirements* before acting; a declared strong-copyleft dep is a real violation to remove.
  • supply_chain.sbom() emits a minimal CycloneDX 1.5 component list. supply_chain.pdf_sanity(bytes) is a lightweight pre-ingest PDF check (header/EOF/size + active-content flags: JavaScript/Launch/EmbeddedFile/OpenAction) — NOT a full parser (no AGPL PyMuPDF).

Not a vulnerability (don't manufacture fixes)

Per the security-review exclusions: DoS/resource-exhaustion, secrets-on-disk (handled elsewhere), rate-limiting, SSRF that only controls the path, client-side authz, log-spoofing, outdated-dep advisories (handled separately). Fix concrete, exploitable HIGH/MED with a clear path.

See memory: codeql-monitoring, perf-sec-p0-patterns, innerhtml-xss-esc, query-dsl-selector-spine.

© ibuilder, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/security-monitoring of ibuilder/massing.

Open the folder on GitHubat commit 523e5b3

Compare with similar skills

Security Monitoring next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Monitoring compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Monitoring this skillibuilder/massing122—~1.7kAutomated safety check: PassMIT
Triage Codeqlnetdata/netdata81k—~1.8kAutomated safety check: NotesGPL-3.0
Sast Hardcodedsecretsutkusen/sast-skills1.3k—~6.5kAutomated safety check: NotesMIT
Implementing GitHub Advanced Security For Code Scanningmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
Aeon Vuln ScannerBankrBot/skills1.2k—~858Automated safety check: PassNone
Triaging Security Findingsbitwarden/ai-plugins155—~2.2kAutomated safety check: PassCustom licence

Similar skills

  • Triage Codeql

    netdata/netdata

    Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

    81k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Sast Hardcodedsecrets

    utkusen/sast-skills

    Detect hardcoded sensitive data (API keys, access tokens, private keys, passwords, etc.) in publicly accessible code — frontend JavaScript, mobile apps, client-side bundles, and HTML templates.

    1.3k GitHub stars~6.5k tokensUpdated 6 mo ago
    SecurityAuto-check: notes
  • Implementing GitHub Advanced Security For Code Scanning

    mukul975/Anthropic-Cybersecurity-Skills

    Configures GitHub Advanced Security (code scanning with CodeQL, secret scanning, dependency review, and Dependabot alerts) to perform automated static analysis and vulnerability detection across…

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Aeon Vuln Scanner

    BankrBot/skills

    Audit trending repos for real exploitable vulnerabilities and disclose responsibly — Private Vulnerability Reporting for code flaws and verified secrets, public PRs only for already-disclosed…

    1.2k GitHub stars~858 tokensUpdated yesterday
    SecurityAuto-check passed
  • Triaging Security Findings

    bitwarden/ai-plugins

    Official

    This skill should be used when the user asks to "triage security findings", "fix an Aikido finding", "review Aikido issues", "dismiss a false positive", "check SAST/IaC alerts", or needs to work…

    155 GitHub stars~2.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Detection Breadth

    deonmenezes/mantishack

    When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

    503 GitHub stars~510 tokensUpdated 8 days ago
    SecurityAuto-check passed

More from ibuilder/massing

  • Backend Tests

    ibuilder/massing

    How to run and add Python tests in the Massing API/data services.

    122 GitHub stars~836 tokensUpdated 2 days ago
    Auto-check passed
  • Massing Bim

    ibuilder/massing

    Drive a Massing BIM/AEC project from an AI agent over MCP — read a project's status, records, CDE, KPI and model-quality checks; run standards-compliance, schedule-risk, embodied-carbon, permit-…

    122 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Ship Release

    ibuilder/massing

    The Massing release discipline — how to ship a verified, CI-green version-numbered release direct to main.

    122 GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check passed
  • Verify Frontend

    ibuilder/massing

    How to verify Massing web/viewer UI changes LIVE — full verification works; two historic "stalls" are fixed and neither was the geometry loader.

    122 GitHub stars~1k tokensUpdated 2 days ago
    Auto-check passed
  • Master Builder

    ibuilder/massing

    Reason like a master builder — one mind holding an entire built-asset project from raw land through design, construction, handover, operations, and disposition, anywhere in the world.

    122 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Security Monitoring

What does Security Monitoring do?

How to monitor and fix security issues in Massing — CodeQL alerts, dependency audits, secret scanning, and ReDoS/XXE fixes. Security Monitoring is an agent skill from ibuilder/massing. How to monitor and fix security issues in Massing — CodeQL alerts, dependency audits, secret scanning, and ReDoS/XXE fixes.

When should I use Security Monitoring?

Security Monitoring fits situations like: tasks that involve Static analysis and SAST; tasks that involve Secrets management.

How do I install Security Monitoring in Claude Code?

Run `npx skills add ibuilder/massing --skill security-monitoring -a claude-code`. Or copy the skill folder (.claude/skills/security-monitoring in ibuilder/massing) into .claude/skills/security-monitoring in your project. Claude Code loads it when a task matches its description.

How do I install Security Monitoring in Codex?

Run `npx skills add ibuilder/massing --skill security-monitoring -a codex`. Or copy the skill folder (.claude/skills/security-monitoring in ibuilder/massing) into .agents/skills/security-monitoring in your project. Codex loads it when a task matches its description.

Can I use Security Monitoring in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ibuilder/massing --skill security-monitoring -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-monitoring, .gemini/skills/security-monitoring, .github/skills/security-monitoring and .opencode/skills/security-monitoring in your project.

What does Security Monitoring need to run?

Going by SKILL.md and its folder, Security Monitoring needs the command-line tools its instructions call (gh, python, npm and git). Our summary lists: Python 3.

Does Security Monitoring access the network?

SKILL.md contains no URLs. Its commands use gh, npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Monitoring safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Monitoring use?

Security Monitoring is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Monitoring use?

About 1.7k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Monitoring?

Skills that share tags, products or a category with Security Monitoring: Triage Codeql (netdata/netdata, 81k stars), Sast Hardcodedsecrets (utkusen/sast-skills, 1.3k stars), Implementing GitHub Advanced Security For Code Scanning (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Aeon Vuln Scanner (BankrBot/skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Monitoring?

ibuilder (a GitHub user) maintains it in ibuilder/massing, which has 122 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 9, 2026.

Source: ibuilder/massing on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.