Agent skill

Common Security

by macalbert in macalbert/envilder

Security guardrails for Envilder (CLI, GitHub Action, SDKs, CDK, website).

MITAuto-check: notesDevOps & Cloud

Install Common Security

skills CLI
$ npx skills add macalbert/envilder --skill common-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install macalbert/envilder common-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/macalbert/envilder.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/common-security .claude/skills/common-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
common-security
GitHub stars
138
Token cost
~1.6k tokens
SKILL.md length
729 words
Files
1
Skills in repo
30
Repo updated
First seen
Licence
MIT

At a glance

Security guardrails for Envilder (CLI, GitHub Action, SDKs, CDK, website).

  • Works in 7 steps: Secret Handling → Credential Hygiene in CI/CD → Input Validation → …
  • Reviewing code for security
  • SKILL.md covers When to Use, 1. Secret Handling, 2. Credential Hygiene in CI/CD and 3. Input Validation, plus 5 more sections
  • Calls pnpm; needs AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY

What it does

Common Security is an agent skill from macalbert/envilder. Security guardrails for Envilder (CLI, GitHub Action, SDKs, CDK, website). Covers secret handling, credential hygiene, supply chain safety, input validation, and CI/CD security. Use when reviewing code for security, handling secrets, validating CLI input, or reviewing GitHub Actions workflows.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering CI/CD and Supply chain security. It works with GitHub Actions, Amazon Web Services and Azure Key Vault. The repository describes itself as: One secret mapping for local dev, CI/CD, and runtime. Envilder resolves cloud secrets from your own vaults without SaaS middlemen, duplicated config, or .env drift. The licence is MIT.

When your agent uses it

  • Reviewing code for security
  • Handling secrets
  • Validating CLI input
  • Reviewing GitHub Actions workflows

Example prompts

  • “/common-security”

Requirements

  • Python 3
  • A credential in AWS_SECRET_ACCESS_KEY
  • A credential in LOCALSTACK_AUTH_TOKEN

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Secret Handling
  2. Credential Hygiene in CI/CD
  3. Input Validation
  4. Supply Chain Security
  5. SDK-Specific Security
  6. Website Security
  7. Testing Security

What it can do on your machine

Read from SKILL.md and the folder at commit b6a0327. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AWS_ACCESS_KEY_ID
    • AWS_SECRET_ACCESS_KEY
    • LOCALSTACK_AUTH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Common Security loads about 1.6k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 729 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:41
    rofile → SSM (via `envilder.json`) | In `.env` files committed to Git |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from macalbert/envilder at commit b6a0327, republished under its MIT licence (© macalbert). 729 words, ~1,595 tokens.

Download SKILL.mdSave it as .claude/skills/common-security/SKILL.md (or your agent's skills folder).
name
common-security
description
Security guardrails for Envilder (CLI, GitHub Action, SDKs, CDK, website). Covers secret handling, credential hygiene, supply chain safety, input validation, and CI/CD security. Use when reviewing code for security, handling secrets, validating CLI input, or reviewing GitHub Actions workflows.
user-invocable
false

Security Skill

Security guardrails adapted to the Envilder project: a CLI + GitHub Action + multi-runtime SDK platform that manages secrets from AWS SSM and Azure Key Vault.

When to Use

  • Reviewing code that handles secrets or cloud credentials
  • Adding new CLI options or GHA inputs that accept external data
  • Reviewing GitHub Actions workflows for credential safety
  • Adding new infrastructure (CDK stacks)
  • Reviewing SDK code that interacts with cloud provider APIs
  • Modifying the website (Astro) with user-visible content

1. Secret Handling

Never Expose Secrets in Output
  • CLI/GHA: Use EnvironmentVariable.maskedValue (shows last 3 chars) for logging
  • SDKs: Never log resolved secret values: log only the key name
  • Tests: Use envilder.json to resolve test tokens; never hardcode tokens
  • Website: No secrets: it's a static site
Storage Rules
ContextWhere secrets liveNever
ProductionAWS SSM Parameter Store (encrypted)In code, env vars, or config files
Production (Azure)Azure Key VaultIn code or checked-in files
CIGitHub Secrets → OIDC → SSMAs plaintext in workflow YAML
Local devAWS profile → SSM (via envilder.json)In .env files committed to Git
TestsTestContainers (LocalStack/Lowkey Vault)Real credentials in test code
Secretlint Enforcement

Secretlint runs on every pnpm lint invocation and scans all files for credential patterns (AWS keys, tokens, private keys). If Secretlint fails, the commit is blocked.

2. Credential Hygiene in CI/CD

GitHub Actions OIDC
  • Always use aws-actions/configure-aws-credentials with role-to-assume
  • Never store AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY as GitHub Secrets
  • OIDC tokens are short-lived and scoped: no rotation needed
GitHub Action Inputs
  • GHA reads inputs from process.env.INPUT_*: validate before use
  • The map input (file path) must be validated to prevent path traversal
  • Never interpolate GHA inputs directly into shell commands
Workflow Permissions
  • Use minimal permissions: block in every workflow
  • contents: read for checkout, id-token: write for OIDC
  • Never use permissions: write-all

3. Input Validation

CLI
  • Commander validates option types: but validate semantic constraints:
    • --map path must exist and be a .json file
    • --provider must be one of aws | azure (case-insensitive)
    • --vault-url must be a valid HTTPS URL matching *.vault.azure.net
  • Never pass CLI arguments to shell commands unsanitized
  • Use custom domain errors (InvalidArgumentError): not generic exceptions
SDKs
  • Map file paths: validate existence before parsing
  • JSON parsing: handle malformed JSON gracefully (domain error, not stack trace)
  • Provider names: strict enum matching, reject unknown values
  • Cross-provider validation: profile + Azure → InvalidArgumentError
Website
  • Static site (Astro): no user input at runtime
  • Build-time i18n: translation keys are developer-controlled, not user-supplied

4. Supply Chain Security

Dependency Pinning
StackMechanismFile
TypeScriptpnpm-lock.yaml + catalog: versionspnpm-workspace.yaml
.NETCentral Package ManagementDirectory.Packages.props
Pythonuv.lock (deterministic)uv.lock
Show full SKILL.md (311 more words)Show less
Rules
  • Lock files must be committed: never .gitignore them
  • Dependabot (or Renovate) configured for automatic dependency updates
  • Review advisories on every dependency update PR
  • esbuild bundles GHA: verify the bundle is up to date (pnpm verify:gha)
  • Pin GitHub Actions to full commit SHA (not @v4 tags) in production workflows
CDK
  • Keep aws-cdk-lib up to date: security patches affect deployed infra
  • CDK synth output (cdk.out/) is .gitignored: never commit CloudFormation templates

5. SDK-Specific Security

AWS SSM Provider
  • Always use WithDecryption: true for SecureString parameters
  • Never log the decrypted parameter value
  • Credential chain: SDK default chain (env vars → profile → instance role)
  • If profile is specified, only use CredentialProfileStoreChain: don't mix
Azure Key Vault Provider
  • Use DefaultAzureCredential: never hardcode clientId/clientSecret
  • Vault URL validation: must match https://*.vault.azure.net
  • TLS certificate validation: enabled in production, only disabled in tests against Lowkey Vault (emulator)
Cross-Provider
  • EnvilderOptions overrides $config: validate that overrides don't introduce insecure combinations (e.g., disabling encryption)
  • Missing secrets → null/None (silent). Validation is opt-in via validateSecrets(): document this to users clearly

6. Website Security

  • Astro generates static HTML: no server-side injection possible
  • External links: use rel="noopener noreferrer" on target="_blank" links
  • No inline scripts or dangerouslySetInnerHTML equivalents
  • CSP headers configured at CDN/CloudFront level (via CDK)

7. Testing Security

  • Acceptance tests use emulators (LocalStack, Lowkey Vault): never real cloud endpoints
  • LOCALSTACK_AUTH_TOKEN resolved via Envilder itself (dogfooding): stored in SSM, never in code
  • Test cleanup: containers destroyed after test run (TestContainers lifecycle)
  • TLS disabled only for Lowkey Vault container tests (self-signed cert)

Quick Security Checklist

Before merging any PR, verify:

  • No secrets hardcoded in code, config, or test files
  • Secretlint passes (pnpm lint)
  • CLI/SDK input validated with domain errors (not generic exceptions)
  • Cloud credentials use OIDC (CI) or SDK default chain (runtime)
  • Secrets logged only via maskedValue (last 3 chars visible)
  • Lock files updated if dependencies changed
  • GHA workflows use minimal permissions:
  • No shell=True or unsanitized argument interpolation in scripts

© macalbert, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/common-security of macalbert/envilder.

Open the folder on GitHubat commit b6a0327

Compare with similar skills

Common Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Common Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Common Security this skillmacalbert/envilder138—~1.6kAutomated safety check: NotesMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2596 repos~1.1kAutomated safety check: NotesCustom licence
GitHub Actions Supply Chain Pinningasyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.0
Vibe CI Supply Chainmistralai/mistral-vibe5.1k—~1kAutomated safety check: PassApache-2.0
Managing Workflow Secretsbitwarden/ai-plugins154—~4kAutomated safety check: PassCustom licence
CI/CD Pipeline Principlesirahardianto/awesome-agv157—~2.7kAutomated safety check: NotesMIT

Similar skills

  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    259 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

    1.1k GitHub stars~1.9k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Vibe CI Supply Chain

    mistralai/mistral-vibe

    Official

    Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.

    5.1k GitHub stars~1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Managing Workflow Secrets

    bitwarden/ai-plugins

    Official

    Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…

    154 GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • CI/CD Pipeline Principles

    irahardianto/awesome-agv

    Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

    157 GitHub stars~2.7k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Devops Deploy

    sickn33/agentic-awesome-skills

    DevOps e deploy de aplicacoes — Docker, CI/CD com GitHub Actions, AWS Lambda, SAM, Terraform, infraestrutura como codigo e monitoramento.

    47k GitHub starsUsed in 2 repos~1.9k tokens
    DevOps & CloudAuto-check passed

More from macalbert/envilder

All 30 skills in this repo
  • Code Review Perspectives

    macalbert/envilder

    Five independent analysis perspectives for code review: correctness, architecture, security, conventions, and complexity.

    138 GitHub stars~1k tokensUpdated 2 days ago
    Auto-check passed
  • Index of Architecture Decision Records (ADRs) for cross-cutting technical decisions.

    138 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Common Git

    macalbert/envilder

    Git commit messages, PR workflow, and branching strategy using Conventional Commits and Semantic Versioning.

    138 GitHub stars~991 tokensUpdated 2 days ago
    Auto-check passed
  • Common Testing Conventions

    macalbert/envilder

    Mandatory testing conventions including the narrow diagnostic exception for testing test-only code, AAA pattern, test naming, and assertions across all stacks (.NET, TypeScript, Python).

    138 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check passed
  • Doc Maintenance

    macalbert/envilder

    Workflow for maintaining changelogs, READMEs, and documentation files.

    138 GitHub stars~904 tokensUpdated 2 days ago
    Auto-check passed
  • Doc Sync

    macalbert/envilder

    Audit and synchronize documentation across website, READMEs, and docs/.

    138 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Common Security

What does Common Security do?

Security guardrails for Envilder (CLI, GitHub Action, SDKs, CDK, website). Common Security is an agent skill from macalbert/envilder. Security guardrails for Envilder (CLI, GitHub Action, SDKs, CDK, website).

When should I use Common Security?

Common Security fits situations like: reviewing code for security; handling secrets; validating CLI input; reviewing GitHub Actions workflows.

How do I install Common Security in Claude Code?

Run `npx skills add macalbert/envilder --skill common-security -a claude-code`. Or copy the skill folder (.github/skills/common-security in macalbert/envilder) into .claude/skills/common-security in your project. Claude Code loads it when a task matches its description.

How do I install Common Security in Codex?

Run `npx skills add macalbert/envilder --skill common-security -a codex`. Or copy the skill folder (.github/skills/common-security in macalbert/envilder) into .agents/skills/common-security in your project. Codex loads it when a task matches its description.

Can I use Common Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add macalbert/envilder --skill common-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/common-security, .gemini/skills/common-security, .github/skills/common-security and .opencode/skills/common-security in your project.

What does Common Security need to run?

Going by SKILL.md and its folder, Common Security needs the command-line tools its instructions call (pnpm) and credentials named AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY and LOCALSTACK_AUTH_TOKEN. Our summary lists: Python 3; A credential in AWS_SECRET_ACCESS_KEY; A credential in LOCALSTACK_AUTH_TOKEN.

Does Common Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Common Security safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Common Security use?

Common Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Common Security use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Common Security?

Skills that share tags, products or a category with Common Security: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 259 stars), GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars), Vibe CI Supply Chain (mistralai/mistral-vibe, 5.1k stars) and Managing Workflow Secrets (bitwarden/ai-plugins, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Common Security?

macalbert (a GitHub user) maintains it in macalbert/envilder, which has 138 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 5, 2026.

Source: macalbert/envilder on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.