Agent skill

Project Security

by johnku2011 in johnku2011/boilerplates-with-ai-skills

A skill your agent uses when reviewing security-sensitive code paths — check auth, secrets, input validation, dependency risk, and data exposure before shipping.

MITAuto-check passedBackend & APIs

Install Project Security

skills CLI
$ npx skills add johnku2011/boilerplates-with-ai-skills --skill project-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install johnku2011/boilerplates-with-ai-skills project-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/johnku2011/boilerplates-with-ai-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/shared/skills/project-security .claude/skills/project-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
project-security
GitHub stars
240
Token cost
~650 tokens
SKILL.md length
270 words
Files
2 (incl. references)
Skills in repo
18
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when reviewing security-sensitive code paths — check auth, secrets, input validation, dependency risk, and data exposure before shipping.

  • Works in 7 steps: Map trust boundaries — user input,… → Authentication & authorization — every… → Secrets — no keys/tokens in source,… → …
  • Reviewing security-sensitive code paths — check auth
  • SKILL.md covers Overview, When to Use, Process and Stack-Specific Checks, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Project Security is an agent skill from johnku2011/boilerplates-with-ai-skills. Use when reviewing security-sensitive code paths — check auth, secrets, input validation, dependency risk, and data exposure before shipping.

Its SKILL.md is about 650 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/stack-checks.md`). Compatibility notes: Application source under review

It sits in Backend & APIs. The licence is MIT.

When your agent uses it

  • Reviewing security-sensitive code paths — check auth
  • Input validation
  • Dependency risk
  • Data exposure before shipping

Example prompts

  • “/project-security”

Requirements

  • Compatibility (from SKILL.md): Application source under review
  • Pre-approved tools (allowed-tools): Read, Grep

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Map trust boundaries — user input, network, filesystem, subprocesses,
  2. Authentication & authorization — every new route/action must declare who
  3. Secrets — no keys/tokens in source, logs, client bundles, or error
  4. Input validation — validate query, body, headers, filenames, and IDs;
  5. Output encoding — prevent injection (HTML, SQL, shell, template).
  6. Dependencies — prefer existing libs; note new supply-chain surface.
  7. Data exposure — server-only data must not reach client, logs, or analytics.

What it can do on your machine

Read from SKILL.md and the folder at commit 475dc6a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Application source under review

    From compatibility in the SKILL.md frontmatter.

Context cost

Project Security loads about 650 tokens when it runs, and up to ~802 if it reads all its reference files. Until then it costs about 40 tokens; SKILL.md has 270 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~650
With references · SKILL.md plus every file in references/, read only if the agent opens them
~802

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from johnku2011/boilerplates-with-ai-skills at commit 475dc6a, republished under its MIT licence (© johnku2011). 270 words, ~650 tokens.

Download SKILL.mdSave it as .claude/skills/project-security/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
project-security
description
Use when reviewing security-sensitive code paths — check auth, secrets, input validation, dependency risk, and data exposure before shipping.
allowed-tools
Read, Grep
compatibility
Application source under review
license
MIT
metadata.suite
security

Project Security

Overview

Apply a practical security review to changes in this project. Focus on real exploitable issues, not generic checklists.

Core principle: Assume all external input is hostile. Assume secrets will leak unless kept server-side.

When to Use

  • New or changed HTTP routes, API handlers, or auth flows
  • File upload, subprocess, or shell execution
  • Environment variable or config changes
  • Dependency additions or version bumps
  • Anything touching user data, tokens, or payments

Process

  1. Map trust boundaries — user input, network, filesystem, subprocesses, third-party APIs, client vs server.
  2. Authentication & authorization — every new route/action must declare who can call it and what they can access.
  3. Secrets — no keys/tokens in source, logs, client bundles, or error responses; env vars on server only.
  4. Input validation — validate query, body, headers, filenames, and IDs; reject early with safe error messages.
  5. Output encoding — prevent injection (HTML, SQL, shell, template).
  6. Dependencies — prefer existing libs; note new supply-chain surface.
  7. Data exposure — server-only data must not reach client, logs, or analytics.

Stack-Specific Checks

When the stack matters, read references/stack-checks.md for web/API and mobile notes (progressive disclosure — load only if needed).

Severity Guide

SeverityExamples
BlockingMissing auth on privileged route, SQL/command injection, secret in client
HighWeak session handling, verbose errors leaking internals
MediumMissing rate limit, overly broad CORS
LowDefense-in-depth hardening, logging improvements

Output Format

## Blocking
- [scenario] Issue — exploit path — fix

## Hardening
- Non-blocking improvements

## Verdict
safe to ship | ship with fixes | do not ship

Anti-patterns

  • Rubber-stamping without checking auth on new endpoints.
  • Ignoring client-visible env vars or API responses that expose internals.
  • Security theater (extra complexity without reduced risk).
  • "We will add auth later" on production-bound code.

After Fixes

Re-check the diff. Run bwai scan-project if skills or agent config changed.

© johnku2011, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in shared/skills/project-security of johnku2011/boilerplates-with-ai-skills.

  • SKILL.md
  • references/stack-checks.md

Open the folder on GitHubat commit 475dc6a

Compare with similar skills

Project Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Project Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Project Security this skilljohnku2011/boilerplates-with-ai-skills240—~650Automated safety check: PassMIT
Security Reviewdoorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT
Ton Vulnerability Scannertrailofbits/skills7.4k—~3.8kAutomated safety check: PassCC-BY-SA-4.0
Sast JWTutkusen/sast-skills1.3k—~6kAutomated safety check: PassMIT
Implementing Device Posture Assessment In Zero Trustmukul975/Anthropic-Cybersecurity-Skills34k—~4.1kAutomated safety check: PassApache-2.0
Audit Reconccashwell/evm-cortex131—~1.5kAutomated safety check: PassMIT

Similar skills

  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Ton Vulnerability Scanner

    trailofbits/skills

    Official

    Scans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks.

    7.4k GitHub stars~3.8k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Sast JWT

    utkusen/sast-skills

    Detect insecure JWT (JSON Web Token) implementations in a codebase using a two-phase approach: first map all JWT issuance and verification sites to understand the token lifecycle and signing…

    1.3k GitHub stars~6k tokensUpdated 6 mo ago
    Backend & APIsAuto-check passed
  • Implementing Device Posture Assessment In Zero Trust

    mukul975/Anthropic-Cybersecurity-Skills

    Implements device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies that…

    34k GitHub stars~4.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Audit Recon

    ccashwell/evm-cortex

    A skill your agent uses when performing initial audit reconnaissance.

    131 GitHub stars~1.5k tokensUpdated 7 days ago
    Backend & APIsAuto-check passed
  • Hunt Auth Bypass

    sickn33/agentic-awesome-skills

    Hunting skill for auth bypass vulnerabilities. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 1 repo~6.6k tokens
    Backend & APIsAuto-check passed

More from johnku2011/boilerplates-with-ai-skills

All 18 skills in this repo
  • Code Review

    johnku2011/boilerplates-with-ai-skills

    A skill your agent uses when reviewing a diff or pull request — check correctness, tests, readability, security, and server/client boundaries before approving.

    240 GitHub stars~708 tokensUpdated 1 mo ago
    Auto-check passed
  • Python API Design

    johnku2011/boilerplates-with-ai-skills

    A skill your agent uses when adding or changing FastAPI routes, dependencies, or tests in this Python service — keep endpoints typed, validated, and covered by pytest.

    240 GitHub stars~449 tokensUpdated 1 mo ago
    Auto-check passed
  • Bwai Advisor

    johnku2011/boilerplates-with-ai-skills

    Use before scaffolding a bwai project — runs the full startup-goal workflow then recommends the right boilerplate and outputs the exact bwai new command to run.

    240 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Deploy Vercel

    johnku2011/boilerplates-with-ai-skills

    A skill your agent uses when deploying or configuring this project on Vercel — env vars, build settings, serverless limits, and production checks for Next.js or Express.

    240 GitHub stars~660 tokensUpdated 1 mo ago
    Auto-check: notes
  • Express API Design

    johnku2011/boilerplates-with-ai-skills

    A skill your agent uses when adding or changing routes, middleware, or error handling in this Express.js API, to keep endpoints consistent, validated, and testable.

    240 GitHub stars~575 tokensUpdated 1 mo ago
    Auto-check passed
  • Nextjs App Router

    johnku2011/boilerplates-with-ai-skills

    A skill your agent uses when adding pages, layouts, route handlers, or data fetching in this Next.js App Router project, to follow server-first conventions correctly.

    240 GitHub stars~587 tokensUpdated 1 mo ago
    Auto-check passed

Questions about Project Security

What does Project Security do?

A skill your agent uses when reviewing security-sensitive code paths — check auth, secrets, input validation, dependency risk, and data exposure before shipping. Project Security is an agent skill from johnku2011/boilerplates-with-ai-skills. Use when reviewing security-sensitive code paths — check auth, secrets, input validation, dependency risk, and data exposure before shipping.

When should I use Project Security?

Project Security fits situations like: reviewing security-sensitive code paths — check auth; input validation; dependency risk; data exposure before shipping.

How do I install Project Security in Claude Code?

Run `npx skills add johnku2011/boilerplates-with-ai-skills --skill project-security -a claude-code`. Or copy the skill folder (shared/skills/project-security in johnku2011/boilerplates-with-ai-skills) into .claude/skills/project-security in your project. Claude Code loads it when a task matches its description.

How do I install Project Security in Codex?

Run `npx skills add johnku2011/boilerplates-with-ai-skills --skill project-security -a codex`. Or copy the skill folder (shared/skills/project-security in johnku2011/boilerplates-with-ai-skills) into .agents/skills/project-security in your project. Codex loads it when a task matches its description.

Can I use Project Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add johnku2011/boilerplates-with-ai-skills --skill project-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/project-security, .gemini/skills/project-security, .github/skills/project-security and .opencode/skills/project-security in your project.

What does Project Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Project Security is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep. Compatibility (from SKILL.md): Application source under review.

Does Project Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Project Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Project Security use?

Project Security is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Project Security use?

About 650 tokens (SKILL.md is roughly 2.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 152 tokens, read only when the agent opens those files.

What are the alternatives to Project Security?

Skills that share tags, products or a category with Project Security: Security Review (doorkeeper-gem/doorkeeper, 5.5k stars), Ton Vulnerability Scanner (trailofbits/skills, 7.4k stars), Sast JWT (utkusen/sast-skills, 1.3k stars) and Implementing Device Posture Assessment In Zero Trust (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Project Security?

johnku2011 (a GitHub user) maintains it in johnku2011/boilerplates-with-ai-skills, which has 240 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on August 24, 2026.

Source: johnku2011/boilerplates-with-ai-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.