Agent skill

Fireauto Secure Guide

by imgompanda in imgompanda/fireauto

"보안 점검", "security check", "security audit", "취약점 분석", "vulnerability scan", "보안 감사", "시크릿 노출", "API 보안", "인증 점검", "rate limit" 등 보안 관련 코드 리뷰나 취약점 감사 시 사용하세요.

MITAuto-check: notesSecurity

Install Fireauto Secure Guide

skills CLI
$ npx skills add imgompanda/fireauto --skill fireauto-secure-guide -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install imgompanda/fireauto fireauto-secure-guide --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/imgompanda/fireauto.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugin/skills/fireauto-secure-guide .claude/skills/fireauto-secure-guide && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fireauto-secure-guide
GitHub stars
140
Token cost
~371 tokens
SKILL.md length
159 words
Files
2 (incl. references)
Skills in repo
18
Repo updated
First seen
Licence
MIT

At a glance

"보안 점검", "security check", "security audit", "취약점 분석", "vulnerability scan", "보안 감사", "시크릿 노출", "API 보안", "인증 점검", "rate limit" 등 보안 관련 코드 리뷰나 취약점 감사 시 사용하세요.

  • Works in 8 steps: 환경변수/시크릿 노출 — .env 파일, 하드코딩된 키,… → 인증/인가 — 미인증 API, admin 클라이언트 남용, RLS 우회 → Rate Limiting — AI/비용 발생 엔드포인트 보호 → …
  • Tasks that involve Rate limiting
  • SKILL.md covers 감사 8개 카테고리, 심각도 분류, 핵심 검색 패턴 and 우선순위 산정, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Fireauto Secure Guide is an agent skill from imgompanda/fireauto. "보안 점검", "security check", "security audit", "취약점 분석", "vulnerability scan", "보안 감사", "시크릿 노출", "API 보안", "인증 점검", "rate limit" 등 보안 관련 코드 리뷰나 취약점 감사 시 사용하세요.

Its SKILL.md is about 370 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/patterns.md`).

It sits in Security, covering Rate limiting and Security review. The repository describes itself as: Claude Code 자동화 플러그인 — SEO, 보안, 팀 에이전트, PRD, 레딧 리서치를 커맨드 하나로. The licence is MIT.

When your agent uses it

  • Tasks that involve Rate limiting
  • Tasks that involve Security review

Example prompts

  • “security check”
  • “security audit”
  • “vulnerability scan”
  • “/fireauto-secure-guide”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. 환경변수/시크릿 노출 — .env 파일, 하드코딩된 키, NEXT_PUBLIC_ 오용
  2. 인증/인가 — 미인증 API, admin 클라이언트 남용, RLS 우회
  3. Rate Limiting — AI/비용 발생 엔드포인트 보호
  4. 파일 업로드 — MIME 검증, 크기 제한, 위험 파일 차단
  5. 스토리지 보안 — 퍼블릭 버킷, URL 추측
  6. Prompt Injection — 사용자 입력 직접 삽입
  7. 정보 노출 — 에러 상세, CSP 헤더
  8. 의존성 취약점 — npm audit, CVE

What it can do on your machine

Read from SKILL.md and the folder at commit 694d941. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fireauto Secure Guide loads about 371 tokens when it runs, and up to ~1k if it reads all its reference files. Until then it costs about 45 tokens; SKILL.md has 159 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~371
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:15
    1. **환경변수/시크릿 노출** — .env 파일, 하드코딩된 키, NEXT_PUBLIC_ 오용

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from imgompanda/fireauto at commit 694d941, republished under its MIT licence (© imgompanda). 159 words, ~371 tokens.

Download SKILL.mdSave it as .claude/skills/fireauto-secure-guide/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
fireauto-secure-guide
description
"보안 점검", "security check", "security audit", "취약점 분석", "vulnerability scan", "보안 감사", "시크릿 노출", "API 보안", "인증 점검", "rate limit" 등 보안 관련 코드 리뷰나 취약점 감사 시 사용하세요.

보안 감사 방법론

실제 SaaS 프로젝트에서 총 18개 취약점을 발견한 패턴을 기반으로 한 보안 감사 방법론.

감사 8개 카테고리

  1. 환경변수/시크릿 노출 — .env 파일, 하드코딩된 키, NEXT_PUBLIC_ 오용
  2. 인증/인가 — 미인증 API, admin 클라이언트 남용, RLS 우회
  3. Rate Limiting — AI/비용 발생 엔드포인트 보호
  4. 파일 업로드 — MIME 검증, 크기 제한, 위험 파일 차단
  5. 스토리지 보안 — 퍼블릭 버킷, URL 추측
  6. Prompt Injection — 사용자 입력 직접 삽입
  7. 정보 노출 — 에러 상세, CSP 헤더
  8. 의존성 취약점 — npm audit, CVE

심각도 분류

심각도기준
CRITICAL즉시 조치. 데이터 유출, 인증 우회, 시크릿 노출
HIGH빠른 조치. 서비스 장애, 비용 발생 가능
MEDIUM계획적 조치. 특정 조건에서 악용 가능
LOW개선 권장. 보안 강화 목적

핵심 검색 패턴

시크릿 노출
"sk-", "sk_live", "sk_test"           → API 키
"password.*=", "secret.*=", "token.*=" → 하드코딩
"NEXT_PUBLIC_.*SERVICE"                → 서비스 키 클라이언트 노출
인증 누락
API 라우트에서 아래 패턴이 없으면 인증 미적용:
"getSession", "getUser", "auth()", "cookies()"
Rate Limit 누락
AI 호출: "openai", "anthropic", "claude", "gpt"
같은 파일에 "ratelimit"이 없으면 취약
Prompt Injection
content: `...${userInput}...`
→ 시스템 프롬프트와 사용자 메시지가 분리되어야 함

우선순위 산정

우선순위 = 심각도 점수 × 구현 용이성

  • 심각도: CRITICAL(4), HIGH(3), MEDIUM(2), LOW(1)
  • 구현 용이성: 쉬움(3), 보통(2), 어려움(1)

커맨드

/fireauto-secure 실행으로 전체 보안 감사를 시작한다.

추가 리소스

상세 검색 패턴과 수정 가이드: references/patterns.md

© imgompanda, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugin/skills/fireauto-secure-guide of imgompanda/fireauto.

  • SKILL.md
  • references/patterns.md

Open the folder on GitHubat commit 694d941

Compare with similar skills

Fireauto Secure Guide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fireauto Secure Guide compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fireauto Secure Guide this skillimgompanda/fireauto140—~371Automated safety check: NotesMIT
Convex Security Auditwaynesutton/builder-skills404—~2.6kAutomated safety check: PassApache-2.0
Security Reviewaffaan-m/ECC274k1 repos~3.2kAutomated safety check: NotesMIT
MCP Implementation Security Reviewgithub/awesome-copilot40k—~5.2kAutomated safety check: PassMIT
Better Auth Security Best PracticesEpicenterHQ/epicenter4.8k—~896Automated safety check: PassCustom licence
API Security ReviewOWASP/secure-agent-playbook186—~744Automated safety check: PassCC-BY-4.0

Similar skills

  • Convex Security Audit

    waynesutton/builder-skills

    Deep security review of a Convex app: authorization model, data access paths per table, HTTP action exposure, rate limiting, file storage access, scheduled function trust, and a written findings…

    404 GitHub stars~2.6k tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Security Review

    affaan-m/ECC

    Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın.

    274k GitHub starsUsed in 1 repo~3.2k tokens
    SecurityAuto-check: notes
  • Official

    Review the implementation source code of MCP (Model Context Protocol) servers, clients, and tool handlers against a security baseline — authentication, sessions, rate limiting, input-schema…

    40k GitHub stars~5.2k tokensUpdated today
    SecurityAuto-check passed
  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated today
    Backend & APIsAuto-check passed
  • API Security Review

    OWASP/secure-agent-playbook

    Comprehensive API security review against OWASP API Security Top 10 (2023).

    186 GitHub stars~744 tokensUpdated 12 days ago
    Backend & APIsAuto-check passed
  • Python Web App Security Audit

    aiskillstore/marketplace

    Run defensive pre-release security tests for Python web applications.

    430 GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check: notes

More from imgompanda/fireauto

All 18 skills in this repo
  • Fireauto UI Guide

    imgompanda/fireauto

    "DaisyUI", "daisyui", "UI 마이그레이션", "UI migration", "shadcn to daisyui", "테마 설정", "theme", "컴포넌트 변환", "DaisyUI 테마", "DaisyUI 컴포넌트" 등 DaisyUI 기반 UI 구축이나 shadcn/ui 마이그레이션 시 사용하세요.

    140 GitHub stars~578 tokensUpdated 6 mo ago
    Auto-check passed
  • Fireauto Lsp Guide

    imgompanda/fireauto

    "정의로 이동", "참조 찾기", "심볼 검색", "타입 확인", "호출 계층", "코드 찾기", "함수 찾기", "어디서 쓰이는지", "어디에 정의된", "구현체 찾기", "인터페이스 구현", "코드 추적", "코드 탐색" 등 코드 탐색이나 심볼 검색이 필요할 때 자동으로 LSP 도구를 우선 사용하세요.

    140 GitHub stars~456 tokensUpdated 6 mo ago
    Auto-check passed
  • Fireauto Project Guide

    imgompanda/fireauto

    프로젝트 생성, 마일스톤 관리, 태스크 추적이 필요할 때 사용하세요. An agent skill from imgompanda/fireauto.

    140 GitHub stars~674 tokensUpdated 6 mo ago
    Auto-check passed
  • Fireauto Team Guide

    imgompanda/fireauto

    "팀 에이전트", "team agent", "병렬 작업", "parallel work", "워크스트림", "workstream", "여러 에이전트", "동시에 작업", "에이전트 팀", "에이전트 간 대화", "team chat", "컴퍼니", "company model" 등 멀티 에이전트 병렬 작업이나 에이전트 간 협업 시 사용하세요.

    140 GitHub stars~456 tokensUpdated 6 mo ago
    Auto-check passed
  • Fireauto Research Guide

    imgompanda/fireauto

    "레딧 리서치", "reddit research", "수요조사", "시장조사", "리드 스코어링", "lead scoring", "market research", "레딧에서 고객 찾기", "레딧 데이터 수집", "reddit lead generation" 등 레딧 기반 시장 조사나 고객 발굴 시 사용하세요.

    140 GitHub stars~524 tokensUpdated 6 mo ago
    Auto-check passed
  • Fireauto SEO Guide

    imgompanda/fireauto

    "SEO 감사", "SEO audit", "기술 SEO", "technical SEO", "구조화 데이터", "schema markup", "JSON-LD", "robots.txt", "sitemap", "메타 태그", "검색엔진 최적화", "pSEO", "Rich Results", "Core Web Vitals" 등 SEO 관련 최적화나 감사 시…

    140 GitHub stars~450 tokensUpdated 6 mo ago
    Auto-check passed

Categories

Questions about Fireauto Secure Guide

What does Fireauto Secure Guide do?

"보안 점검", "security check", "security audit", "취약점 분석", "vulnerability scan", "보안 감사", "시크릿 노출", "API 보안", "인증 점검", "rate limit" 등 보안 관련 코드 리뷰나 취약점 감사 시 사용하세요. Fireauto Secure Guide is an agent skill from imgompanda/fireauto. "보안 점검", "security check", "security audit", "취약점 분석", "vulnerability scan", "보안 감사", "시크릿 노출", "API 보안", "인증 점검", "rate limit" 등 보안 관련 코드 리뷰나 취약점 감사 시 사용하세요.

When should I use Fireauto Secure Guide?

Fireauto Secure Guide fits situations like: tasks that involve Rate limiting; tasks that involve Security review.

How do I install Fireauto Secure Guide in Claude Code?

Run `npx skills add imgompanda/fireauto --skill fireauto-secure-guide -a claude-code`. Or copy the skill folder (plugin/skills/fireauto-secure-guide in imgompanda/fireauto) into .claude/skills/fireauto-secure-guide in your project. Claude Code loads it when a task matches its description.

How do I install Fireauto Secure Guide in Codex?

Run `npx skills add imgompanda/fireauto --skill fireauto-secure-guide -a codex`. Or copy the skill folder (plugin/skills/fireauto-secure-guide in imgompanda/fireauto) into .agents/skills/fireauto-secure-guide in your project. Codex loads it when a task matches its description.

Can I use Fireauto Secure Guide in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add imgompanda/fireauto --skill fireauto-secure-guide -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fireauto-secure-guide, .gemini/skills/fireauto-secure-guide, .github/skills/fireauto-secure-guide and .opencode/skills/fireauto-secure-guide in your project.

What does Fireauto Secure Guide need to run?

SKILL.md names no scripts, command-line tools or credentials: Fireauto Secure Guide is instructions for the agent only.

Does Fireauto Secure Guide access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Fireauto Secure Guide safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Fireauto Secure Guide use?

Fireauto Secure Guide is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fireauto Secure Guide use?

About 371 tokens (SKILL.md is roughly 1.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 668 tokens, read only when the agent opens those files.

What are the alternatives to Fireauto Secure Guide?

Skills that share tags, products or a category with Fireauto Secure Guide: Convex Security Audit (waynesutton/builder-skills, 404 stars), Security Review (affaan-m/ECC, 274k stars), MCP Implementation Security Review (github/awesome-copilot, 40k stars) and Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fireauto Secure Guide?

imgompanda (a GitHub user) maintains it in imgompanda/fireauto, which has 140 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on April 9, 2026.

Source: imgompanda/fireauto on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.