Security Analyzer
aiskillstore/marketplace
Comprehensive security vulnerability analysis for codebases and infrastructure.
Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.
$ npx skills add luongnv89/skills --skill security-setup -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install luongnv89/skills security-setup --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-setup .claude/skills/security-setup && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-setup" agent skill from https://github.com/luongnv89/skills/tree/main/skills/security-setup into .claude/skills/security-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-setup", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/luongnv89/skills/tree/main/skills/security-setupType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add luongnv89/skills --skill security-setup -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install luongnv89/skills security-setup --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security-setup .agents/skills/security-setup && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-setup" agent skill from https://github.com/luongnv89/skills/tree/main/skills/security-setup into .agents/skills/security-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-setup", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add luongnv89/skills --skill security-setup -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install luongnv89/skills security-setup --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security-setup .cursor/skills/security-setup && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-setup" agent skill from https://github.com/luongnv89/skills/tree/main/skills/security-setup into .cursor/skills/security-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-setup", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/luongnv89/skills.git --path skills/security-setup--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add luongnv89/skills --skill security-setup -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install luongnv89/skills security-setup --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security-setup .gemini/skills/security-setup && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-setup" agent skill from https://github.com/luongnv89/skills/tree/main/skills/security-setup into .gemini/skills/security-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-setup", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install luongnv89/skills security-setupInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add luongnv89/skills --skill security-setup -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security-setup .github/skills/security-setup && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-setup" agent skill from https://github.com/luongnv89/skills/tree/main/skills/security-setup into .github/skills/security-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-setup", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add luongnv89/skills --skill security-setup -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install luongnv89/skills security-setup --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security-setup .opencode/skills/security-setup && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-setup" agent skill from https://github.com/luongnv89/skills/tree/main/skills/security-setup into .opencode/skills/security-setup/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-setup", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-setupInstall local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.
Security Setup is an agent skill from luongnv89/skills. Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI. Use when hardening repos or adding security hooks. Don't use for incident response or cloud security reviews.
Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts and reference files (for example `docs/README.md`, `evals/evals.json` and `references/final-report.md`). Compatibility notes: Cross-platform (macOS, Linux, Windows). Requires git, Python 3.8+, and project write access. Uses pre-commit plus free local tools such as gitleaks, trivy…
It sits in Security, covering Security review, Static analysis and SAST and Cloud security. It works with Python and Git. The repository describes itself as: Supercharge your AI agents/bots with reusable skills. The licence is MIT.
2 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8f80262. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
gitpython3pythoncargotrivyFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cross-platform (macOS, Linux, Windows). Requires git, Python 3.8+, and project write access. Uses pre-commit plus free local tools such as gitleaks, trivy, semgrep, bandit, or cargo-audit when appropriate. Semgrep on Windows requires WSL2.
From compatibility in the SKILL.md frontmatter.
Security Setup loads about 4.5k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 66 tokens; SKILL.md has 1,938 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from luongnv89/skills at commit 8f80262, republished under its MIT licence (© luongnv89). 1,938 words, ~4,457 tokens.
.claude/skills/security-setup/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.Install a local-first security hardening stack for a project. Favor checks that run offline at hook time, produce machine-readable output, and give developers a clear summary before code leaves their machine.
<!-- Maintainer note — not runtime guidance: keep this orchestrator short for the
agent's context budget; detailed matrices, templates, and long verification
scenarios live in `references/`. Link, don't inline. -->
This skill may trigger automatically per its description, but it never writes
silently: Phase 1 always dry-runs the planned changes and waits for explicit
user confirmation before touching files, and Phase 2 (CI) only runs when the
user explicitly asks for it (e.g. --ci).
.pre-commit-config.yaml, scripts/, security/, SECURITY.md.--ci) GitHub Actions enabled on the repo.Check these before Phase 1:
git rev-parse --git-dir. If it exits non-zero, stop and end with a BLOCKED final report.python3 --version (python --version on Windows). If no interpreter answers, or the version is below 3.8, stop and end with a BLOCKED final report.SECURITY.md and the final report. Do not claim offline coverage for it.Before creating/updating/deleting files in an existing repository, sync the current branch with remote:
branch="$(git rev-parse --abbrev-ref HEAD)"
git fetch origin
git pull --rebase origin "$branch"If the working tree is not clean, stash first as a backup, sync, then restore:
git stash push -u -m "pre-sync" # backup local changes
branch="$(git rev-parse --abbrev-ref HEAD)"
git fetch origin && git pull --rebase origin "$branch"
git stash pop # rollback by restoring the backupIf origin is missing, pull is unavailable, or rebase/stash conflicts occur, stop
and ask the user before continuing. Never use --force rollback options without
confirmation.
Work in two gated phases:
--ci, create a free-tier
GitHub Actions workflow that runs the same local runner on pull requests.Do not create CI files until Phase 1 is installed and passing.
Inspect the repo before choosing tools. The runner and skill instructions work on macOS, Linux, and Windows; pick the matching shell snippet.
macOS / Linux (bash, zsh):
ls -la package.json package-lock.json pnpm-lock.yaml yarn.lock pyproject.toml requirements.txt Cargo.toml Cargo.lock go.mod pom.xml build.gradle 2>/dev/null
ls -la .pre-commit-config.yaml SECURITY.md .github/workflows/security.yml 2>/dev/null
command -v gitleaks trivy semgrep detect-secrets bandit cargo-audit pre-commit 2>/dev/nullWindows PowerShell:
Get-ChildItem -Force -ErrorAction SilentlyContinue package.json,package-lock.json,pnpm-lock.yaml,yarn.lock,pyproject.toml,requirements.txt,Cargo.toml,Cargo.lock,go.mod,pom.xml,build.gradle
Get-ChildItem -Force -ErrorAction SilentlyContinue .pre-commit-config.yaml,SECURITY.md,.github\workflows\security.yml
foreach ($t in 'gitleaks','trivy','semgrep','detect-secrets','bandit','cargo-audit','pre-commit') { Get-Command $t -ErrorAction SilentlyContinue }Identify:
Use references/tool-selection.md for the tool matrix and install commands.
Choose the smallest useful set:
gitleaks; use detect-secrets when it already exists in
a Python-heavy repo.trivy fs --skip-db-update for offline hook runtime;
add cargo-audit only for Rust repos that already use Cargo.semgrep with local rules under security/.
Add language-native scanners only when the language is present (bandit for
Python, gosec for Go, cargo clippy/cargo audit for Rust).When the repo uses package managers, recommend Socket Firewall as a lightweight
local guardrail for day-to-day dependency installs. This does not replace lockfile
scanning with trivy/cargo-audit; it shifts risk left by making risky installs
harder before a new dependency reaches the repo.
For macOS/Linux users on zsh or bash, suggest adding these aliases to the
developer shell profile:
alias npm="sfw npm"
alias yarn="sfw yarn"
alias pnpm="sfw pnpm"
alias pip="sfw pip"
alias uv="sfw uv"
alias cargo="sfw cargo"Only include aliases for package managers the project actually uses, and document
the guardrail in SECURITY.md as optional local developer setup. If Socket
Firewall is not installed, print the official install instructions or link to
the official docs; do not add failing hooks that require sfw.
The hook must not call cloud services at runtime. If a scanner needs a local
database, warm that database during setup and run with offline flags in the hook.
If offline dependency scanning cannot be configured for an ecosystem, document the
gap in SECURITY.md and do not pretend the criterion is satisfied.
Pre-commit must be fast on small commits without losing coverage. Each check declares its own relevance rule — never a global "skip on .md only" filter.
Trigger semantics in security/security-tools.json:
| Trigger | Behavior |
|---|---|
"always": true | Always run. Use for secret scanners — secrets land in .md, .json, .env.example, Dockerfile, anywhere. |
"paths": [globs] | Run only when at least one staged file matches a glob. Use for lockfile-driven (trivy, cargo-audit) or language-driven (semgrep, bandit) checks. |
| (omitted) | Runner falls back to the per-tool defaults baked into scripts/security_check.py for the recognized tool name. |
A repo-wide trip_all_paths list (default: .pre-commit-config.yaml, security/**,
.github/workflows/**, Dockerfile*, .dockerignore, scripts/security_check.py)
forces every applicable check to run when any of those files is staged. This
catches workflow-injection edits, hook-tampering, and Dockerfile RCE that would
otherwise slip past purely category-based scoping.
CI runs full scans (--all). Scoping only applies on developer commits; the CI
mirror is the safety net.
Mandatory invariant: secret scanning runs on every commit. Do not move gitleaks (or its replacement) into a path-restricted trigger.
Dry-run the changes before writing any file:
new or exists.exists target, show the diff between the current file and the planned content..pre-commit-config.yaml and SECURITY.md explicitly when they exist: overwriting either one is destructive.BLOCKED final report. If the user declines some files, write only the confirmed ones and record each declined file for the final report.exists target, copy it to <path>.bak so the user can roll back.Create or update these files:
.pre-commit-config.yaml - merge a local security-check hook into existing
config; do not overwrite user hooks.scripts/security_check.py - copy from scripts/security_check.py in this
skill, then adjust tool config if needed.security/semgrep-rules.yml - local Semgrep rules so runtime scans are offline.security/security-tools.json - selected tools and command overrides.SECURITY.md - summary of selected tools, why they were chosen, and how to run
or bypass checks.Use references/templates.md for starter snippets.
Never add a silent bypass. Bypass cannot be performed through git commit
because pre-commit redirects hook stdin to /dev/null, so the runner's
TTY check refuses --force from inside the hook. The approved bypass is a
two-step, explicit override:
Run the runner directly with --force and type YES at the prompt:
# macOS / Linux
SECURITY_CHECK_ARGS=--force python3 scripts/security_check.py# Windows PowerShell
$env:SECURITY_CHECK_ARGS = "--force"; python scripts\security_check.py; Remove-Item Env:SECURITY_CHECK_ARGS:: Windows cmd.exe
set SECURITY_CHECK_ARGS=--force && python scripts\security_check.py && set SECURITY_CHECK_ARGS=The runner prints the prompt:
Type YES to override security checks and force-push:It accepts only the literal string YES. Any other input, EOF, or a
non-TTY context exits non-zero and refuses the bypass.
After the override is recorded in the report, commit with
git commit --no-verify. Document the bypass in SECURITY.md (date,
reason, link to the recorded report) so the override is auditable.
Do not add --force to the pre-commit hook entry, and do not wrap
git commit in a script that opens /dev/tty for the hook — both routes
hide the bypass from review.
Run the local checks after writing files. Use python3 on macOS/Linux and
python on Windows (the Python launcher routes to the active interpreter).
Verification uses --all so every configured check runs regardless of what
happens to be staged.
First run pre-commit --version. If it exits non-zero, print the install
commands below, run only the security_check.py command, skip
pre-commit run, and end with a PARTIAL final report that names the
missing pre-commit:
python3 -m pip install pre-commit # use `python` on Windows
pre-commit installIf it exits 0, run both verification commands and record each exit code:
# macOS / Linux
python3 scripts/security_check.py --all --no-fail-on-missing-tools
pre-commit run security-check --all-files# Windows PowerShell
python scripts\security_check.py --all --no-fail-on-missing-tools
pre-commit run security-check --all-filesWhen run from a pre-commit hook with no flags, the runner inspects
git diff --cached and scopes checks to the staged file set per the trigger
table in §2. --all overrides this for verification or one-off full scans;
--staged-only errors if no staged files are found (useful for guarded
hooks).
Exit codes: 0 means no failing finding (or an accepted bypass), 1 means
at least one fail_on finding, and 2 means the runner could not run (an
invalid security-tools.json, --staged-only with nothing staged, or an
unwritable report path); its stderr message names the input and the fix.
A successful first run prints a summary to stdout and exits 0. See "Report Requirements" below for the exact shape and content of that summary.
Assert: a clean run exits 0, both report paths exist, and
security-report.json parses as valid JSON with a top-level summary
object. Any HIGH or CRITICAL finding exits non-zero unless the bypass
in §"4. Bypass Policy" was completed.
--ci)Only run this phase when the user asks for CI/CD, for example
/security-setup --ci.
Preconditions:
python3 scripts/security_check.py --all --no-fail-on-missing-tools exits 0 locally.pre-commit-config.yaml contains the security-check hookIf any precondition fails, do not create the workflow; record CI not created
and the failing precondition for the final report.
Otherwise create .github/workflows/security.yml using references/templates.md.
If that file already exists, apply the Step 3 dry-run steps to it first
(diff, confirm, .bak backup). Keep the workflow free-tier friendly:
pull_request and push to the default branch.python3 scripts/security_check.py --all (CI always full-scans).The local runner must print a concise report with:
The default exit behavior is strict: any HIGH or CRITICAL finding exits
non-zero.
A successful full run looks like this (exact counts vary):
Security Check Summary
======================
Mode: full
Checks run: 3 of 3 (skipped: 0)
Findings: 1
Severity: HIGH=1
Categories: dependencies=1
JSON report: security/security-report.json
Markdown report: security/security-report.md
Top findings:
- HIGH [dependencies/trivy] CVE-XXXX-XXXX in <pkg> (<lockfile>)
Hint: Upgrade to <version>.A scoped run on a docs-only commit looks like:
Mode: staged
Staged files: 2
Checks run: 1 of 3 (skipped: 2)
Skipped: trivy, semgrepSkipped checks are recorded in both reports with their scope reason — they are not silent.
A completed setup passes when:
.pre-commit-config.yaml contains a local security-check hook.scripts/security_check.py exists and prints the required summary.--force requires the exact YES confirmation before bypassing failures.SECURITY.md documents selected tools, omissions, run commands, and CI
status.--ci creates .github/workflows/security.yml only after Phase 1 passes.references/verification-scenarios.md.references/final-report.md:
the status is on the first line, verified checks are separated from
assumptions, each claim cites a command or file, and the next decision is
named. Human understanding stays unconfirmed until the user gives feedback.security/security-tools.json and document
per-package coverage.references/tool-selection.md for each missing selected tool, and install it
only after the user confirms. A category whose tool stays missing is listed
in the final report; never skip it silently.After each phase, report:
◆ Security Setup ([phase] - [context])
................................................................
Project detection: pass | fail - detail
Tool selection: pass | fail - detail
Local hook: pass | fail - detail
Security report: pass | fail - detail
CI mirror: pass | skipped | fail - detail
Criteria: N/M met
____________________________
Result: PASS | PARTIAL | FAILEnd every run, including a stop, with one final report in the shape
references/final-report.md defines. Read it before writing the report. The
four parts are required, in this order:
Result: — COMPLETE, PARTIAL — <reason>, or BLOCKED — <reason>, then one line on what changed.Evidence: — only commands that ran, with exit codes, and each file written with its .bak path.Uncertainty: — missing tools, offline gaps, declined files, and checks that did not run.Decision: — the approval the user must give, or No approval needed., then each remaining user action.references/tool-selection.md - offline-first tool matrix and install notesreferences/templates.md - target repo file templatesreferences/verification-scenarios.md - no-blindspot manual verification scenariosreferences/final-report.md - final report parts, status rules, and examplesscripts/security_check.py - reusable local security summary runnerevals/evals.json - trigger and behavior eval cases with final-report assertions© luongnv89, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (scripts, references) in skills/security-setup of luongnv89/skills.
Open the folder on GitHubat commit 8f80262
Security Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Setup this skillluongnv89/skills | 131 | — | ~4.5k | Automated safety check: Pass | MIT | |
| Security Analyzeraiskillstore/marketplace | 430 | — | ~1.2k | Automated safety check: Notes | None | |
| CodeQL Security Scantrailofbits/skills | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Kedro Security Reviewkedro-org/kedro | 11k | — | ~3.3k | Automated safety check: Pass | Custom licence | |
| Trailmark Graph Evolutiontrailofbits/skills | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Pyspector Security AuditParzivalHack/PySpector | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 |
aiskillstore/marketplace
Comprehensive security vulnerability analysis for codebases and infrastructure.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
ParzivalHack/PySpector
Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.
RaoFoundation/subtensor
Run the security-focused Skeptic persona on the local working tree's diff against a base branch.
luongnv89/skills
Review UI usability using Steve Krug's principles and produce a scannable report.
luongnv89/skills
Manage AI agent fleets in Herdr: tile root + sub-agents in one tab, start/prompt/wait/read/monitor via the herdr agent CLI, steer any pane; help lists every operation.
luongnv89/skills
Optimize Ollama configuration for the current machine's hardware.
luongnv89/skills
Generate sprint-based development tasks from a PRD. An agent skill from luongnv89/skills.
luongnv89/skills
Manage AI agents in tmux: spawn sessions, send messages, wait, capture replies, inspect fleets, and tear down safely.
luongnv89/skills
Review website/app UX for humans and AX for AI/search; produce an evidence-backed audit and improvement plan across usability, brand, access, speed, conversion and discoverability.
Categories
Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI. Security Setup is an agent skill from luongnv89/skills. Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.
Security Setup fits situations like: hardening repos; adding security hooks; incident response; cloud security reviews.
Run `npx skills add luongnv89/skills --skill security-setup -a claude-code`. Or copy the skill folder (skills/security-setup in luongnv89/skills) into .claude/skills/security-setup in your project. Claude Code loads it when a task matches its description.
Run `npx skills add luongnv89/skills --skill security-setup -a codex`. Or copy the skill folder (skills/security-setup in luongnv89/skills) into .agents/skills/security-setup in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add luongnv89/skills --skill security-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-setup, .gemini/skills/security-setup, .github/skills/security-setup and .opencode/skills/security-setup in your project.
Going by SKILL.md and its folder, Security Setup needs Python for the scripts in its folder and the command-line tools its instructions call (git, python3, python, cargo and trivy). Our summary lists: Python 3. Compatibility (from SKILL.md): Cross-platform (macOS, Linux, Windows). Requires git, Python 3.8+, and project write access. Uses pre-commit plus free local tools such as gitleaks, trivy, semgrep, bandit, or cargo-audit when appropriate. Semgrep on Windows requires WSL2..
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Security Setup is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Security Setup: Security Analyzer (aiskillstore/marketplace, 430 stars), CodeQL Security Scan (trailofbits/skills, 7.4k stars), Kedro Security Review (kedro-org/kedro, 11k stars) and Trailmark Graph Evolution (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
luongnv89 (a GitHub user) maintains it in luongnv89/skills, which has 131 GitHub stars. The repository holds 37 skills in this directory. The repository was last updated on October 7, 2026.
Source: luongnv89/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.