Agent skill

Kedro Plugins Security Review

by kedro-org in kedro-org/kedro-plugins

Run a security scan on the kedro-plugins codebase or a pull request.

Apache-2.0Auto-check passedSecurity

Install Kedro Plugins Security Review

skills CLI
$ npx skills add kedro-org/kedro-plugins --skill kedro-plugins-security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kedro-org/kedro-plugins kedro-plugins-security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kedro-org/kedro-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/kedro-plugins-security-review .claude/skills/kedro-plugins-security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kedro-plugins-security-review
GitHub stars
119
Token cost
~3.1k tokens
SKILL.md length
1,128 words
Files
3
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run a security scan on the kedro-plugins codebase or a pull request.

  • Works in 8 steps: Resolve runtime → Resolve temporary working directory → Resolve scan target → …
  • The user says things like run security scan on the full codebase
  • SKILL.md covers References, Defaults, Runtime note and Delivery modes, plus 4 more sections
  • Calls gh, uv and bash

What it does

Kedro Plugins Security Review is an agent skill from kedro-org/kedro-plugins. Run a security scan on the kedro-plugins codebase or a pull request. This skill runs Semgrep with dataset-specific rules, triages findings against the dataset trust model, audits nosec suppressions, and produces one final report. Use when the user says things like "run security scan on the full codebase" or "run security scan on this PR". Produce one final report only, in chat by default or posted to GitHub when explicitly asked.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `reference.md` and `rules/kedro-plugins-security-patterns.yml`).

It sits in Security, covering Security review and Static analysis and SAST. It works with Semgrep and GitHub. The repository describes itself as: First-party plugins maintained by the Kedro team. The licence is Apache-2.0.

When your agent uses it

  • The user says things like run security scan on the full codebase
  • Run security scan on this PR

Example prompts

  • “run security scan on the full codebase”
  • “run security scan on this PR”
  • “/kedro-plugins-security-review”

Requirements

  • Python 3
  • Docker

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Resolve runtime
  2. Resolve temporary working directory
  3. Resolve scan target
  4. Run Semgrep
  5. Read findings
  6. Triage against the dataset trust model
  7. Manual review checks (always run, even with zero Semgrep findings)
  8. Build the final report

What it can do on your machine

Read from SKILL.md and the folder at commit ff0b268. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • uv
    • bash
    • uvx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, uv and uvx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kedro Plugins Security Review loads about 3.1k tokens when it runs. Until then it costs about 116 tokens; SKILL.md has 1,128 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kedro-org/kedro-plugins at commit ff0b268, republished under its Apache-2.0 licence (© kedro-org). 1,128 words, ~3,142 tokens.

Download SKILL.mdSave it as .claude/skills/kedro-plugins-security-review/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
kedro-plugins-security-review
description
Run a security scan on the kedro-plugins codebase or a pull request. This skill runs Semgrep with dataset-specific rules, triages findings against the dataset trust model, audits nosec suppressions, and produces one final report. Use when the user says things like "run security scan on the full codebase" or "run security scan on this PR". Produce one final report only, in chat by default or posted to GitHub when explicitly asked.

Security Scan

Before scanning, decide two things:

  1. Target source — full codebase or PR (see ## Mode selection)
  2. Delivery — chat (default) or post to GitHub (see ## Delivery modes)

Then run the numbered Workflow below:

  1. detect which Semgrep binary is available (see Defaults)
  2. create a temporary working directory with mktemp -d
  3. determine what to scan — full repo or changed files from the PR
  4. run Semgrep in parallel across all rulesets
  5. read and deduplicate findings
  6. triage and classify findings against the dataset trust model
  7. run manual review checks from reference.md
  8. emit one final report

References

Read these before triaging findings:

Defaults

  • Runtime:
    • semgrep
    • otherwise uvx --from semgrep semgrep
    • otherwise uv tool run --from semgrep semgrep
  • Rulesets:
    • p/security-audit
    • p/secrets
    • p/python
    • .agents/skills/kedro-plugins-security-review/rules/kedro-plugins-security-patterns.yml
  • Path exclusions (every Semgrep invocation). Note: this is a monorepo, so tests/, docs/, and features/ are nested under each plugin directory (e.g. kedro-datasets/tests/). Use glob patterns that match at any depth:
    • --exclude '**/tests/**'
    • --exclude '**/docs/**'
    • --exclude '**/features/**'
    • --exclude '.agents/'
    • --exclude 'tools/'
    • --exclude '**/kedro_datasets_benchmarks/**'
  • Temporary working directory:
    • create with mktemp -d
    • delete at the end unless the user explicitly asks to keep artifacts

Always use --metrics=off.

Runtime note

If a uvx or uv tool run Semgrep command fails with a permissions error on a ~/.cache/uv path, ask the user for permission to run outside the sandbox (i.e. with full filesystem access) and then rerun the same command. Do not treat a cache permission failure as a real scan failure.

Later workflow steps that invoke Semgrep should refer back to this note instead of repeating it.

Delivery modes

Chat mode

Default mode. Show one final report in chat and do not expose intermediate scan output.

Post mode

Only use when the user explicitly asks to post, submit, or publish the scan result to GitHub.

Post mode is only valid in PR mode — it produces a GitHub PR review payload and there is no PR to attach it to in full-codebase mode. If a user asks to post a full-codebase scan, fall back to chat mode and tell the user why.

In post mode:

  • still do all scanning and triage locally first
  • construct one final GitHub review payload
  • post it after the review is complete

Do not post partial results or progress updates.

Mode selection

Full codebase mode

Use when the user asks to scan the repo, codebase, project, or current branch without narrowing to a PR.

Target:

  • kedro-datasets/ by default (this is where all dataset code lives)
  • if the user explicitly asks to scan a different plugin (e.g. kedro-docker), scan that directory instead — but note that the triage guidance and manual review checks are designed for dataset code and may not apply
PR mode

Use when the user asks to scan a PR or when the request names a PR number or URL.

Resolve the PR from:

  • the explicit PR number or URL if provided
  • otherwise the current branch via gh pr view

Then get the changed files:

bash
gh pr diff <number> --name-only

Only keep files that still exist in the working tree. Scan just those files.

If the PR has no scannable files, report that clearly and stop.

Workflow

1. Resolve runtime
bash
if command -v semgrep >/dev/null 2>&1; then
  ENGINE_LABEL="Semgrep OSS (host CLI)"
  SEMGREP_CMD=(semgrep)
elif command -v uvx >/dev/null 2>&1; then
  ENGINE_LABEL="Semgrep OSS (uvx)"
  SEMGREP_CMD=(uvx --from semgrep semgrep)
elif command -v uv >/dev/null 2>&1; then
  ENGINE_LABEL="Semgrep OSS (uv tool run)"
  SEMGREP_CMD=(uv tool run --from semgrep semgrep)
else
  echo "ERROR: neither semgrep, uvx, nor uv is available."
  exit 1
fi

SEMGREP_EXCLUDE=(
  --exclude '**/tests/**'
  --exclude '**/docs/**'
  --exclude '**/features/**'
  --exclude '.agents/'
  --exclude 'tools/'
  --exclude '**/kedro_datasets_benchmarks/**'
)

"${SEMGREP_CMD[@]}" --version

If the version check fails, apply the Runtime note above before treating the scan as failed.

2. Resolve temporary working directory

Check whether the user explicitly asked to keep artifacts before emitting the script below.

If NOT keeping artifacts:

bash
OUTPUT_DIR="$(mktemp -d "${TMPDIR:-/tmp}/kedro-plugins-security-review.XXXXXX")"
cleanup() {
  rm -rf "$OUTPUT_DIR"
}
trap cleanup EXIT
mkdir -p "$OUTPUT_DIR/raw"

If keeping artifacts (omit the trap entirely):

bash
OUTPUT_DIR="$(mktemp -d "${TMPDIR:-/tmp}/kedro-plugins-security-review.XXXXXX")"
mkdir -p "$OUTPUT_DIR/raw"

In that case, report $OUTPUT_DIR at the end of the scan so the user can inspect it.

3. Resolve scan target

For full codebase mode:

bash
SCAN_TARGETS=(kedro-datasets/)
TARGET_LABEL="kedro-datasets (full codebase)"

For PR mode:

bash
PR_NUMBER="<resolved-pr-number>"

# Apply the same path exclusions as full-codebase mode.
# Semgrep's --exclude only filters during directory walk, so explicit file
# arguments would otherwise bypass the exclusion list.
# This is a monorepo — excluded dirs are nested (e.g. kedro-datasets/tests/).
# Use contains-style matching, not prefix matching.

SCAN_TARGETS=()
while IFS= read -r path; do
  [ -f "$path" ] || continue
  skip=0
  for segment in /tests/ /docs/ /features/ /kedro_datasets_benchmarks/; do
    [[ "/$path" == *"$segment"* ]] && skip=1 && break
  done
  [[ "$path" == .agents/* ]] && skip=1
  [[ "$path" == tools/* ]] && skip=1
  (( skip == 0 )) && SCAN_TARGETS+=("$path")
done < <(gh pr diff "$PR_NUMBER" --name-only)
TARGET_LABEL="PR #$PR_NUMBER"

If SCAN_TARGETS is empty, stop and report that there are no scannable files (this also happens when a PR only touches excluded paths like tests/ or docs/).

4. Run Semgrep

Set:

bash
LOCAL_RULESET="$(pwd)/.agents/skills/kedro-plugins-security-review/rules/kedro-plugins-security-patterns.yml"

Run these in parallel (each command includes "${SEMGREP_EXCLUDE[@]}"):

bash
(
  "${SEMGREP_CMD[@]}" scan --metrics=off \
    "${SEMGREP_EXCLUDE[@]}" \
    --config p/security-audit \
    --json --output "$OUTPUT_DIR/raw/security-audit.json" \
    "${SCAN_TARGETS[@]}"
) &

(
  "${SEMGREP_CMD[@]}" scan --metrics=off \
    "${SEMGREP_EXCLUDE[@]}" \
    --config p/secrets \
    --json --output "$OUTPUT_DIR/raw/secrets.json" \
    "${SCAN_TARGETS[@]}"
) &

(
  "${SEMGREP_CMD[@]}" scan --metrics=off \
    "${SEMGREP_EXCLUDE[@]}" \
    --include="*.py" --config p/python \
    --json --output "$OUTPUT_DIR/raw/python.json" \
    "${SCAN_TARGETS[@]}"
) &

(
  "${SEMGREP_CMD[@]}" scan --metrics=off \
    "${SEMGREP_EXCLUDE[@]}" \
    --include="*.py" \
    --config "$LOCAL_RULESET" \
    --json --output "$OUTPUT_DIR/raw/kedro-plugins-security-patterns.json" \
    "${SCAN_TARGETS[@]}"
) &

wait

If one or more rulesets fail, continue with the findings from the rulesets that did succeed. Do not abort the full scan. In the final report, include a "Scan errors" section that lists each failed ruleset and its error message so the user knows the scan was partial.

If a scan command fails, apply the Runtime note before marking that ruleset as failed.

Show full SKILL.md (429 more words)Show less
5. Read findings

Read all JSON files in $OUTPUT_DIR/raw/ directly. Deduplicate by (check_id, path, start.line) — if the same finding appears in more than one ruleset output, count it once.

6. Triage against the dataset trust model

For every unique finding:

  • open the flagged file and inspect the surrounding code
  • classify it using reference.md
  • include the Suggested next step from the matching bucket in reference.md

Use these buckets:

  • dataset_vulnerability
  • by_design_with_documentation
  • needs_manual_review
7. Manual review checks (always run, even with zero Semgrep findings)

After triaging Semgrep output, run the Manual review checks from reference.md against the scan target.

For each check:

  • Search the scanned files for the pattern described
  • If found and unmitigated, add it to the findings list with classification dataset_vulnerability or needs_manual_review
  • If not found, the check was clean — do not itemise it

When all checks are clean, report them as a single line in the final report rather than enumerating each one. Only expand a check when it actually flagged something.

This step exists because Semgrep only catches known patterns. These checks catch the class of issues that static analysis misses.

8. Build the final report

Do not stream intermediate findings to the user.

Accumulate findings during triage, then produce exactly one final report using the format below.

If post mode was requested, write a single review JSON payload and post it via:

bash
bash .agents/scripts/post_github_review.sh <review_json_file>

Delete the temporary review JSON file after posting.

Reporting

Keep the report short and decisive. The classification summary already carries the counts — do not repeat non-actionable findings as prose.

Always include:

  • mode used: full codebase or PR
  • target scanned
  • total Semgrep findings reviewed
  • counts by classification bucket
  • highest Semgrep severities present

Only itemise actionable findings in the Findings section:

  • Always: dataset_vulnerability, needs_manual_review

Do not itemise findings classified as by_design_with_documentation — they are reflected in the classification summary counts and that is sufficient.

If the Findings section has nothing actionable, replace it with a single line that names the non-actionable counts (e.g. "None actionable. 3 by-design findings on pre-existing lines.").

For each actionable finding, include:

  • file
  • line
  • rule id
  • Semgrep severity
  • classification
  • one-sentence reasoning
  • suggested next step (from reference.md for that bucket; for dataset_vulnerability, pick the ERROR or WARNING recommendation based on Semgrep severity)

If no findings are plausible dataset vulnerabilities, say so explicitly.

Output format

Chat mode

Return one final report in this shape:

markdown
## Kedro Datasets Security Scan
> Generated with `kedro-plugins-security-review`.

### Overview
- **Mode:** <full codebase | PR>
- **Target:** <repo root | PR #123>
- **Findings reviewed:** <count>
- **Highest Semgrep severities:** <list or "none">

### Classification summary
- **dataset_vulnerability:** <count>
- **needs_manual_review:** <count>
- **by_design_with_documentation:** <count>

### Findings
<For each actionable finding (dataset_vulnerability, needs_manual_review):>
- `path/to/file.py:L42` — `<classification>` — <rule id> — <reason> — <next step>

<If nothing actionable, replace the list with a single line, e.g.:>
None actionable. <count> by-design findings on pre-existing lines.

### Manual review checks
<If all clean, one line:>
All clean (load_args passthrough, docstring accuracy, risk documentation, security suppression comments).

<Otherwise, only list the checks that flagged something, with reasoning.>

### Conclusion
- <short conclusion, or "No plausible dataset vulnerabilities found.">
Post mode

Write one GitHub review payload:

json
{
  "event": "COMMENT",
  "body": "## Kedro Datasets Security Scan\n...(final summary report)...",
  "comments": [
    {
      "path": "file.py",
      "line": 42,
      "side": "RIGHT",
      "body": "**dataset_vulnerability:** <reason>\n\nRule: `<rule id>`\nSeverity: `<severity>`\nNext step: <next step>"
    }
  ]
}

Use inline comments only for actionable findings tied to changed PR lines:

  • dataset_vulnerability
  • needs_manual_review

Do not post inline comments for by_design_with_documentation. Put the full summary in body, following the same conciseness rules as chat mode.

© kedro-org, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in .agents/skills/kedro-plugins-security-review of kedro-org/kedro-plugins.

  • SKILL.md
  • reference.md
  • rules/kedro-plugins-security-patterns.yml

Open the folder on GitHubat commit ff0b268

Compare with similar skills

Kedro Plugins Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kedro Plugins Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kedro Plugins Security Review this skillkedro-org/kedro-plugins119—~3.1kAutomated safety check: PassApache-2.0
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence
Semgrep Security Scantrailofbits/skills7.5k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
SkepticRaoFoundation/subtensor391—~660Automated safety check: PassApache-2.0
Agentic GitHub Actions Auditortrailofbits/skills7.5k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.5k GitHub stars~3.7k tokensUpdated today
    SecurityAuto-check: notes
  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated 3 days ago
    SecurityAuto-check: notes
  • Skeptic

    RaoFoundation/subtensor

    Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

    391 GitHub stars~660 tokensUpdated today
    SecurityAuto-check passed
  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.5k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • Security Reviewer

    Jeffallan/claude-skills

    Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

    12k GitHub stars~1.3k tokensUpdated 7 days ago
    SecurityAuto-check passed

Works with

Categories

Questions about Kedro Plugins Security Review

What does Kedro Plugins Security Review do?

Run a security scan on the kedro-plugins codebase or a pull request. Kedro Plugins Security Review is an agent skill from kedro-org/kedro-plugins. Run a security scan on the kedro-plugins codebase or a pull request.

When should I use Kedro Plugins Security Review?

Kedro Plugins Security Review fits situations like: the user says things like run security scan on the full codebase; run security scan on this PR.

How do I install Kedro Plugins Security Review in Claude Code?

Run `npx skills add kedro-org/kedro-plugins --skill kedro-plugins-security-review -a claude-code`. Or copy the skill folder (.agents/skills/kedro-plugins-security-review in kedro-org/kedro-plugins) into .claude/skills/kedro-plugins-security-review in your project. Claude Code loads it when a task matches its description.

How do I install Kedro Plugins Security Review in Codex?

Run `npx skills add kedro-org/kedro-plugins --skill kedro-plugins-security-review -a codex`. Or copy the skill folder (.agents/skills/kedro-plugins-security-review in kedro-org/kedro-plugins) into .agents/skills/kedro-plugins-security-review in your project. Codex loads it when a task matches its description.

Can I use Kedro Plugins Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kedro-org/kedro-plugins --skill kedro-plugins-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kedro-plugins-security-review, .gemini/skills/kedro-plugins-security-review, .github/skills/kedro-plugins-security-review and .opencode/skills/kedro-plugins-security-review in your project.

What does Kedro Plugins Security Review need to run?

Going by SKILL.md and its folder, Kedro Plugins Security Review needs the command-line tools its instructions call (gh, uv, bash and uvx). Our summary lists: Python 3; Docker.

Does Kedro Plugins Security Review access the network?

SKILL.md contains no URLs. Its commands use gh, uv and uvx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Kedro Plugins Security Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kedro Plugins Security Review use?

Kedro Plugins Security Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kedro Plugins Security Review use?

About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kedro Plugins Security Review?

Skills that share tags, products or a category with Kedro Plugins Security Review: Kedro Security Review (kedro-org/kedro, 11k stars), Semgrep Security Scan (trailofbits/skills, 7.5k stars), Pyspector Security Audit (ParzivalHack/PySpector, 151 stars) and Skeptic (RaoFoundation/subtensor, 391 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kedro Plugins Security Review?

kedro-org (a GitHub organization) maintains it in kedro-org/kedro-plugins, which has 119 GitHub stars. The repository was last updated on October 8, 2026.

Source: kedro-org/kedro-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.