Agent skill

Security Health Inline

by maslennikov-ig in maslennikov-ig/claude-code-orchestrator-kit

Inline orchestration workflow for security vulnerability detection and remediation with Beads integration.

Custom licenceAuto-check passedSecurity

Install Security Health Inline

skills CLI
$ npx skills add maslennikov-ig/claude-code-orchestrator-kit --skill security-health-inline -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install maslennikov-ig/claude-code-orchestrator-kit security-health-inline --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/maslennikov-ig/claude-code-orchestrator-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/security-health-inline .claude/skills/security-health-inline && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-health-inline
GitHub stars
260
Token cost
~2k tokens
SKILL.md length
393 words
Files
1
Skills in repo
29
Repo updated
First seen
Licence
Custom licence

At a glance

Inline orchestration workflow for security vulnerability detection and remediation with Beads integration.

  • Works in 7 steps: Pre-flight & Beads Init → Detection → Create Beads Issues → …
  • Tasks that involve Vulnerability scanning
  • SKILL.md covers Workflow Overview, Phase 1: Pre-flight & Beads Init, Phase 2: Detection and Phase 3: Create Beads Issues, plus 6 more sections
  • Calls pnpm and git

What it does

Security Health Inline is an agent skill from maslennikov-ig/claude-code-orchestrator-kit. Inline orchestration workflow for security vulnerability detection and remediation with Beads integration. Provides step-by-step phases for security-scanner detection, priority-based fixing with vulnerability-fixer, and verification cycles.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning. The repository describes itself as: 🎼 Turn Claude Code into a production powerhouse. 33+ AI agents automate bug fixing, security scanning, and dependency management. 19 slash commands, 6 MCP configs (600-5000…

When your agent uses it

  • Tasks that involve Vulnerability scanning

Example prompts

  • “/security-health-inline”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Pre-flight & Beads Init
  2. Detection
  3. Create Beads Issues
  4. Quality Gate (Pre-fix)
  5. Fixing Loop
  6. Verification
  7. Final Summary & Beads Complete

What it can do on your machine

Read from SKILL.md and the folder at commit 8c3b576. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Health Inline loads about 2k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 393 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 393 words (~1,986 tokens).

“You ARE the orchestrator. Execute this workflow directly without spawning a separate orchestrator agent.”

— opening of SKILL.md by maslennikov-ig, Custom licence
name
security-health-inline
version
3.0.0

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .claude/skills/security-health-inline of maslennikov-ig/claude-code-orchestrator-kit.

Open the folder on GitHubat commit 8c3b576

Compare with similar skills

Security Health Inline next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Health Inline compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Health Inline this skillmaslennikov-ig/claude-code-orchestrator-kit260—~2kAutomated safety check: PassCustom licence
Snapshotboostsecurityio/poutine523—~214Automated safety check: PassApache-2.0
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT
Cve Remediationrundeck/rundeck6.3k—~2.9kAutomated safety check: PassApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT

Similar skills

  • Snapshot

    boostsecurityio/poutine

    Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

    523 GitHub stars~214 tokensUpdated yesterday
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Cve Remediation

    rundeck/rundeck

    Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    190 GitHub stars~2.5k tokensUpdated 14 days ago
    SecurityAuto-check: notes

More from maslennikov-ig/claude-code-orchestrator-kit

All 29 skills in this repo
  • Senior Architect Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive software architecture skill for designing scalable, maintainable systems using ReactJS, NextJS, NodeJS, Express, React Native, Swift, Kotlin…

    260 GitHub starsUsed in 8 repos~1.2k tokens
    Auto-check: notes
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    Auto-check: notes
  • Senior Prompt Engineer

    maslennikov-ig/claude-code-orchestrator-kit

    Provides reference guides and Python scripts for prompt optimization, RAG evaluation, and agent orchestration when building or tuning LLM systems.

    260 GitHub starsUsed in 3 repos~1.4k tokens
    Auto-check passed
  • Priority Score Calculator

    maslennikov-ig/claude-code-orchestrator-kit

    Scores a bug, issue or task from severity, impact and likelihood on a 0-30 scale and maps the total to a P0 to P4 priority category with a suggested action.

    260 GitHub stars~1k tokensUpdated 7 mo ago
    Auto-check passed
  • Code Review with Beads Tasks

    maslennikov-ig/claude-code-orchestrator-kit

    Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.

    260 GitHub stars~2k tokensUpdated 7 mo ago
    Auto-check passed
  • Semantic Version Parser

    maslennikov-ig/claude-code-orchestrator-kit

    Extracts and validates semantic version strings from mixed text, parsing major, minor, patch, prerelease and build components with a fixed regular expression.

    260 GitHub stars~1k tokensUpdated 7 mo ago
    Auto-check passed

Questions about Security Health Inline

What does Security Health Inline do?

Inline orchestration workflow for security vulnerability detection and remediation with Beads integration. Security Health Inline is an agent skill from maslennikov-ig/claude-code-orchestrator-kit. Inline orchestration workflow for security vulnerability detection and remediation with Beads integration.

When should I use Security Health Inline?

Security Health Inline fits situations like: tasks that involve Vulnerability scanning.

How do I install Security Health Inline in Claude Code?

Run `npx skills add maslennikov-ig/claude-code-orchestrator-kit --skill security-health-inline -a claude-code`. Or copy the skill folder (.claude/skills/security-health-inline in maslennikov-ig/claude-code-orchestrator-kit) into .claude/skills/security-health-inline in your project. Claude Code loads it when a task matches its description.

How do I install Security Health Inline in Codex?

Run `npx skills add maslennikov-ig/claude-code-orchestrator-kit --skill security-health-inline -a codex`. Or copy the skill folder (.claude/skills/security-health-inline in maslennikov-ig/claude-code-orchestrator-kit) into .agents/skills/security-health-inline in your project. Codex loads it when a task matches its description.

Can I use Security Health Inline in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maslennikov-ig/claude-code-orchestrator-kit --skill security-health-inline -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-health-inline, .gemini/skills/security-health-inline, .github/skills/security-health-inline and .opencode/skills/security-health-inline in your project.

What does Security Health Inline need to run?

Going by SKILL.md and its folder, Security Health Inline needs the command-line tools its instructions call (pnpm and git).

Does Security Health Inline access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Health Inline safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Health Inline use?

Security Health Inline has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Security Health Inline use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Health Inline?

Skills that share tags, products or a category with Security Health Inline: Snapshot (boostsecurityio/poutine, 523 stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Shiro Attack CLI (SummerSec/ShiroAttack2, 2.6k stars) and Cve Remediation (rundeck/rundeck, 6.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Health Inline?

maslennikov-ig (a GitHub user) maintains it in maslennikov-ig/claude-code-orchestrator-kit, which has 260 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on March 5, 2026.

Source: maslennikov-ig/claude-code-orchestrator-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.