Agent skill

Security Devsecops

by Mindrally in Mindrally/skills

DevSecOps, secure software development lifecycle (SSDLC), and application security (AppSec) practices covering secret handling, input validation, dependency hygiene, authentication/authorization…

Apache-2.0Auto-check: notesDevOps & Cloud

Install Security Devsecops

skills CLI
$ npx skills add Mindrally/skills --skill security-devsecops -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Mindrally/skills security-devsecops --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Mindrally/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security-devsecops .claude/skills/security-devsecops && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-devsecops
GitHub stars
267
Token cost
~2.2k tokens
SKILL.md length
991 words
Files
1
Skills in repo
34
Repo updated
First seen
Licence
Apache-2.0

At a glance

DevSecOps, secure software development lifecycle (SSDLC), and application security (AppSec) practices covering secret handling, input validation, dependency hygiene, authentication/authorization…

  • Works in 7 steps: Identify trust boundaries — Note every… → Validate and sanitize at the boundary —… → Use existing security primitives — Reach… → …
  • Writing code that handles credentials
  • SKILL.md covers Workflow for Adding a New…, General Security Principles, Secret Handling and Database Security, plus 6 more sections
  • Calls npm and trivy; needs API_KEY

What it does

Security Devsecops is an agent skill from Mindrally/skills. DevSecOps, secure software development lifecycle (SSDLC), and application security (AppSec) practices covering secret handling, input validation, dependency hygiene, authentication/authorization, and CI/CD security tooling (SAST, SCA, DAST, secret scanning, IaC scanning). Use when writing code that handles credentials, user input, database queries, or authentication, when setting up a CI/CD pipeline, or when reviewing code or infrastructure for security issues.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Secrets management, Static analysis and SAST and CI/CD. The repository describes itself as: 255+ Claude Code skills converted from Cursor rules. Expert coding guidelines for every major framework and language. The licence is Apache-2.0.

When your agent uses it

  • Writing code that handles credentials
  • Database queries
  • Setting up a CI/CD pipeline
  • Infrastructure for security issues

Example prompts

  • “/security-devsecops”

Requirements

  • Python 3
  • Node.js
  • A credential in API_KEY

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Identify trust boundaries — Note every place the new code accepts input from a user, another service, or a file, and every place it emits…
  2. Validate and sanitize at the boundary — Validate all untrusted input on entry; escape output for its destination context (HTML, JS, SQL…
  3. Use existing security primitives — Reach for the project's established auth framework, ORM, and secret-management approach rather than…
  4. Keep secrets out of code and logs — Read credentials from environment variables or a secrets vault; confirm nothing sensitive reaches logs…
  5. Run local security checks before pushing — Lint, SAST, and secret-scanning tools where available (gitleaks, semgrep, npm audit, pip-audit…
  6. Let CI gates run — SAST, SCA, secret scanning, and IaC scanning should run on every PR; treat a failure as a blocker, not a suggestion to…
  7. Document the security-relevant decision — Note in the PR description any auth/authz change, new dependency, or deviation from a…

What it can do on your machine

Read from SKILL.md and the folder at commit 9718410. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • trivy

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Devsecops loads about 2.2k tokens when it runs. Until then it costs about 121 tokens; SKILL.md has 991 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~121
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:23
    - Never commit `.env` files, secret config files, or unrecognized tokens to source control. Add them to `.gitignore` bef

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Mindrally/skills at commit 9718410, republished under its Apache-2.0 licence (© Mindrally). 991 words, ~2,200 tokens.

Download SKILL.mdSave it as .claude/skills/security-devsecops/SKILL.md (or your agent's skills folder).
name
security-devsecops
description
DevSecOps, secure software development lifecycle (SSDLC), and application security (AppSec) practices covering secret handling, input validation, dependency hygiene, authentication/authorization, and CI/CD security tooling (SAST, SCA, DAST, secret scanning, IaC scanning). Use when writing code that handles credentials, user input, database queries, or authentication, when setting up a CI/CD pipeline, or when reviewing code or infrastructure for security issues.

Security / DevSecOps

This skill covers secure coding practices, dependency and secret hygiene, authentication and authorization, and the security tooling that belongs in a secure software development lifecycle (SSDLC) — from local coding habits through CI/CD gates to production monitoring.

Workflow for Adding a New Feature Securely

  1. Identify trust boundaries — Note every place the new code accepts input from a user, another service, or a file, and every place it emits output (HTML, logs, another service).
  2. Validate and sanitize at the boundary — Validate all untrusted input on entry; escape output for its destination context (HTML, JS, SQL, shell).
  3. Use existing security primitives — Reach for the project's established auth framework, ORM, and secret-management approach rather than writing new ones.
  4. Keep secrets out of code and logs — Read credentials from environment variables or a secrets vault; confirm nothing sensitive reaches logs or error messages.
  5. Run local security checks before pushing — Lint, SAST, and secret-scanning tools where available (gitleaks, semgrep, npm audit, pip-audit, etc.).
  6. Let CI gates run — SAST, SCA, secret scanning, and IaC scanning should run on every PR; treat a failure as a blocker, not a suggestion to suppress.
  7. Document the security-relevant decision — Note in the PR description any auth/authz change, new dependency, or deviation from a default-secure pattern, so it's auditable later.

General Security Principles

  • Never hardcode secrets, credentials, or API keys in source code. Use environment variables or a secure vault (e.g. AWS Secrets Manager, HashiCorp Vault, Doppler) for sensitive data.
  • Never commit .env files, secret config files, or unrecognized tokens to source control. Add them to .gitignore before they're ever staged.
  • Never log sensitive data, secrets, or session tokens in application logs — redact or omit them at the point of logging, not after the fact.
  • Validate and sanitize all user input at the point it enters the system. Escape output appropriately for its context: HTML-encode for HTML, JS-encode for inline scripts, parameterize for SQL.
  • Avoid unsafe dynamic-execution functions such as exec, eval, Function(), pickle.loads on untrusted data, or shell interpolation of user input.
python
# Unsafe — string interpolation into a query
query = f"SELECT * FROM users WHERE email = '{email}'"
cursor.execute(query)

# Safe — parameterized query
cursor.execute("SELECT * FROM users WHERE email = %s", (email,))

Secret Handling

  • Load secrets from environment variables (process.env.API_KEY, os.environ["API_KEY"]) or a vault client, never as literals.
  • Rotate any credential that was ever committed to version control, even if the commit was later removed — history retains it.
  • Scan for accidentally committed secrets before merge, using tools like gitleaks, trufflehog, or the CI provider's built-in secret scanning.
  • Scope credentials narrowly: a CI deploy key should be able to deploy, not administer the whole cloud account.

Database Security

  • Use parameterized queries or an ORM for all database access. Never build queries via string concatenation or f-strings with user input.
  • Ensure database users have the least privilege required for their role (a reporting service should not have DROP TABLE rights).
  • Regularly review and update database access policies as team membership and service responsibilities change.

Dependency Management

  • Only add packages from verified, reputable sources — check download counts, maintenance activity, and known-CVE history before adding a new dependency.
  • Do not add new dependencies without explicit approval and a brief security review, especially for packages that will run with elevated privileges or process untrusted input.
  • Regularly update dependencies and scan for known vulnerabilities using Software Composition Analysis (SCA) tools such as npm audit, pip-audit, Dependabot, Snyk, or Trivy.
bash
# Node.js
npm audit --audit-level=high

# Python
pip-audit

# Container image
trivy image myapp:latest

Authentication & Authorization

  • Use established, audited authentication frameworks (e.g. Auth0, Passport, Devise, ASP.NET Identity) — never implement custom cryptographic authentication from scratch.
  • Store passwords using strong, salted, adaptive hashes: Argon2id or bcrypt, never MD5, SHA1, or unsalted SHA256.
  • Implement Role-Based Access Control (RBAC) — or attribute-based access control for finer granularity — for sensitive operations.
  • Enforce the principle of least privilege for both API endpoints and UI actions: check authorization on every request server-side, never trust a hidden UI element as an access control.
  • Re-check authorization on every request, even for actions previously permitted — session state and roles can change mid-session.
js
// Missing authorization check — any authenticated user can access any order
app.get("/orders/:id", requireAuth, async (req, res) => {
  const order = await Order.findById(req.params.id);
  res.json(order);
});

// Correct — verify the resource belongs to the requester
app.get("/orders/:id", requireAuth, async (req, res) => {
  const order = await Order.findById(req.params.id);
  if (!order || order.userId !== req.user.id) {
    return res.status(404).end();
  }
  res.json(order);
});
Show full SKILL.md (353 more words)Show less

Secure SDLC Practices

Integrate these into the CI/CD pipeline, not as a manual pre-release checklist:

  • SAST (Static Application Security Testing) — scan source code for known-bad patterns on every PR (e.g. Semgrep, CodeQL, SonarQube).
  • SCA (Software Composition Analysis) — scan dependencies for known vulnerabilities and license issues (e.g. Snyk, Dependabot, OWASP Dependency-Check).
  • Secret scanning — scan every commit and PR diff for accidentally committed credentials before merge (e.g. Gitleaks, GitHub secret scanning, TruffleHog).
  • IaC scanning — scan Terraform/CloudFormation/Kubernetes manifests for misconfigurations before apply (e.g. Checkov, tfsec, Trivy config scan).
  • DAST (Dynamic Application Security Testing) — scan a running instance of the deployed application for exploitable behavior in the CD pipeline (e.g. OWASP ZAP, Burp Suite).
  • Policy as Code (PaC) — encode security and compliance policies as version-controlled, automatically enforced rules (e.g. OPA/Rego, Sentinel) rather than a document nobody rereads.

Monitoring & Feedback

  • Enable continuous vulnerability monitoring and alerting on both dependencies and running infrastructure.
  • Integrate Runtime Application Self-Protection (RASP) and a Web Application Firewall (WAF) where the deployment target and traffic profile warrant it.
  • Schedule regular vulnerability assessments and penetration tests, not just point-in-time audits before a big release.
  • Maintain a feedback loop: recurring vulnerability classes found in production or pentests should update linting rules, SAST policies, and code review checklists — not just get patched once.

Compliance & Documentation

  • Align controls with recognized industry standards: OWASP Top 10, OWASP ASVS, NIST SSDF, ISO 27001, as relevant to the project's regulatory context.
  • Document security controls and decisions as they're made (threat model notes, why an exception was granted, what compensating control offsets a known risk) so the reasoning is auditable later, not reconstructed from memory during an audit.

Common Vulnerability Classes to Watch For

ClassWatch for
Injection (SQL/NoSQL/command)String-built queries or shell commands with user input
Broken access controlMissing per-request authorization checks, IDOR via predictable IDs
Cryptographic failuresWeak hashes, hardcoded keys, missing TLS, custom crypto
Insecure deserializationpickle, unchecked JSON.parse into executable contexts, unsafe YAML loaders
Security misconfigurationDefault credentials, verbose error pages in production, permissive CORS
Vulnerable dependenciesOutdated packages with known CVEs, unpinned versions
Insufficient loggingNo audit trail for auth events, sensitive data logged in plaintext

© Mindrally, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in security-devsecops of Mindrally/skills.

Open the folder on GitHubat commit 9718410

Compare with similar skills

Security Devsecops next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Devsecops compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Devsecops this skillMindrally/skills267—~2.2kAutomated safety check: NotesApache-2.0
Sicurezza GitHubccplugins/awesome-claude-code-plugins967—~486Automated safety check: NotesApache-2.0
Admingrafana/skills278—~1.5kAutomated safety check: PassApache-2.0
Common Security StandardsHoangNguyen0403/agent-skills-standard570—~764Automated safety check: PassMIT
Azure Devtest LabsMicrosoftDocs/Agent-Skills775—~3.5kAutomated safety check: PassCC-BY-4.0
Tsh Managing SecretsTheSoftwareHouse/copilot-collections284—~877Automated safety check: NotesMIT

Similar skills

  • Sicurezza GitHub

    ccplugins/awesome-claude-code-plugins

    Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot.

    967 GitHub stars~486 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Admin

    grafana/skills

    Official

    Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning.

    278 GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Common Security Standards

    HoangNguyen0403/agent-skills-standard

    Enforce universal security protocols for safe, resilient software.

    570 GitHub stars~764 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Azure Devtest Labs

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure DevTest Labs development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations…

    775 GitHub stars~3.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Tsh Managing Secrets

    TheSoftwareHouse/copilot-collections

    Secrets management patterns for cloud and Kubernetes environments.

    284 GitHub stars~877 tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Moai Ref Secops

    modu-ai/moai-adk

    DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning…

    1.2k GitHub stars~2.6k tokensUpdated today
    SecurityAuto-check passed

More from Mindrally/skills

All 34 skills in this repo
  • Analytics Data Analysis

    Mindrally/skills

    Best practices for analytics, data analysis, and visualization using Python, pandas, matplotlib, seaborn, and Jupyter notebooks.

    267 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Best practices for AutoML and hyperparameter search with Optuna, Ray Tune, and PyCaret, covering search-space design, validation splits, and leakage prevention.

    267 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Blender Python Addon

    Mindrally/skills

    Best practices for writing Blender Python add-ons using the bpy API, covering operators, panels, properties, registration, and API-safe scripting.

    267 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Expert guidelines for Chrome extension development with Manifest V3, covering security, performance, and best practices.

    267 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Clean Code

    Mindrally/skills

    Clean, maintainable, human-readable code principles combined with anti-over-engineering discipline: naming, single responsibility, DRY, and scoping changes to exactly what was requested.

    267 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Design Systems

    Mindrally/skills

    Comprehensive design system guidelines for building consistent, accessible, and scalable component libraries.

    267 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Security Devsecops

What does Security Devsecops do?

DevSecOps, secure software development lifecycle (SSDLC), and application security (AppSec) practices covering secret handling, input validation, dependency hygiene, authentication/authorization…. Security Devsecops is an agent skill from Mindrally/skills. DevSecOps, secure software development lifecycle (SSDLC), and application security (AppSec) practices covering secret handling, input validation, dependency hygiene, authentication/authorization, and CI/CD security tooling (SAST, SCA, DAST, secret scanning, IaC scanning).

When should I use Security Devsecops?

Security Devsecops fits situations like: writing code that handles credentials; database queries; setting up a CI/CD pipeline; infrastructure for security issues.

How do I install Security Devsecops in Claude Code?

Run `npx skills add Mindrally/skills --skill security-devsecops -a claude-code`. Or copy the skill folder (security-devsecops in Mindrally/skills) into .claude/skills/security-devsecops in your project. Claude Code loads it when a task matches its description.

How do I install Security Devsecops in Codex?

Run `npx skills add Mindrally/skills --skill security-devsecops -a codex`. Or copy the skill folder (security-devsecops in Mindrally/skills) into .agents/skills/security-devsecops in your project. Codex loads it when a task matches its description.

Can I use Security Devsecops in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Mindrally/skills --skill security-devsecops -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-devsecops, .gemini/skills/security-devsecops, .github/skills/security-devsecops and .opencode/skills/security-devsecops in your project.

What does Security Devsecops need to run?

Going by SKILL.md and its folder, Security Devsecops needs the command-line tools its instructions call (npm and trivy) and credentials named API_KEY. Our summary lists: Python 3; Node.js; A credential in API_KEY.

Does Security Devsecops access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Devsecops safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Devsecops use?

Security Devsecops is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Devsecops use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Devsecops?

Skills that share tags, products or a category with Security Devsecops: Sicurezza GitHub (ccplugins/awesome-claude-code-plugins, 967 stars), Admin (grafana/skills, 278 stars), Common Security Standards (HoangNguyen0403/agent-skills-standard, 570 stars) and Azure Devtest Labs (MicrosoftDocs/Agent-Skills, 775 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Devsecops?

Mindrally (a GitHub organization) maintains it in Mindrally/skills, which has 267 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on September 3, 2026.

Source: Mindrally/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.