Agent skill

Performing Serverless Function Security Review

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables…

Apache-2.0Auto-check passedBackend & APIs

Install Performing Serverless Function Security Review

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-serverless-function-security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-serverless-function-security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-serverless-function-security-review .claude/skills/performing-serverless-function-security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-serverless-function-security-review
GitHub stars
34k
Token cost
~3.1k tokens
SKILL.md length
606 words
Files
4 (incl. scripts, references)
Skills in repo
639
Repo updated
First seen
Licence
Apache-2.0

At a glance

Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables…

  • Works in 6 steps: Enumerate All Serverless Functions and… → Audit Execution Role Permissions → Check Environment Variables for Secrets → …
  • Tasks that involve Serverless
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls aws, az and python3; needs DB_PASSWORD and API_KEY

What it does

Performing Serverless Function Security Review is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Backend & APIs, covering Serverless and Security review. It works with AWS Lambda, Google Cloud and Azure Functions. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Serverless
  • Tasks that involve Security review

Example prompts

  • “/performing-serverless-function-security-review”

Requirements

  • Python 3
  • Node.js
  • A credential in API_KEY
  • A credential in STRIPE_SECRET_KEY

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Enumerate All Serverless Functions and Configurations
  2. Audit Execution Role Permissions
  3. Check Environment Variables for Secrets
  4. Review Function Triggers and Access Controls
  5. Analyze Function Code for Security Vulnerabilities
  6. Run Automated Serverless Security Scanning

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • aws
    • az
    • python3
    • gcloud
    • pip
    • npm
    • eslint

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, az, gcloud, pip and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DB_PASSWORD
    • API_KEY
    • STRIPE_SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Serverless Function Security Review loads about 3.1k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 74 tokens; SKILL.md has 606 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 606 words, ~3,123 tokens.

Download SKILL.mdSave it as .claude/skills/performing-serverless-function-security-review/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
performing-serverless-function-security-review
description
Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections.
domain
cybersecurity
subdomain
cloud-security
tags
cloud-security, serverless, lambda, azure-functions, cloud-functions, security-review
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.IR-01, ID.AM-08, GV.SC-06, DE.CM-01
mitre_attack
T1078.004, T1530, T1537, T1580, T1055

Performing Serverless Function Security Review

When to Use

  • When auditing serverless applications before production deployment
  • When investigating potential data exposure through function environment variables or logs
  • When assessing the blast radius of a compromised serverless function execution role
  • When compliance reviews require documentation of serverless security controls
  • When building secure-by-default templates for serverless deployments

Do not use for container or VM security assessments (use container scanning tools), for API security testing (use DAST tools on the API Gateway layer), or for real-time serverless threat detection (use AWS Lambda Extensions with security agents).

Prerequisites

  • AWS CLI, Azure CLI, and gcloud CLI configured with appropriate permissions
  • Access to read function configurations, policies, and execution roles
  • Prowler or Checkov for automated serverless security scanning
  • SAM CLI or Serverless Framework for local function analysis
  • CloudTrail, Azure Monitor, or Cloud Audit Logs enabled for function invocation monitoring

Workflow

Step 1: Enumerate All Serverless Functions and Configurations

List all functions across cloud providers with their runtime, memory, timeout, and network settings.

bash
# AWS Lambda: List all functions with key security attributes
aws lambda list-functions \
  --query 'Functions[*].[FunctionName,Runtime,MemorySize,Timeout,Role,VpcConfig.VpcId,Layers[*].Arn]' \
  --output table

# Check for functions using deprecated runtimes
aws lambda list-functions \
  --query 'Functions[?Runtime==`python3.7` || Runtime==`nodejs14.x` || Runtime==`dotnetcore3.1`].[FunctionName,Runtime]' \
  --output table

# Azure Functions: List all function apps
az functionapp list \
  --query "[].{Name:name, Runtime:siteConfig.linuxFxVersion, ResourceGroup:resourceGroup, HttpsOnly:httpsOnly}" \
  -o table

# GCP Cloud Functions: List all functions
gcloud functions list \
  --format="table(name, runtime, status, httpsTrigger.url, serviceAccountEmail, vpcConnector)"
Step 2: Audit Execution Role Permissions

Review IAM roles attached to functions for overly permissive policies.

bash
# AWS: Check each Lambda function's execution role
for func in $(aws lambda list-functions --query 'Functions[*].FunctionName' --output text); do
  role_arn=$(aws lambda get-function-configuration --function-name "$func" --query 'Role' --output text)
  role_name=$(echo "$role_arn" | awk -F'/' '{print $NF}')
  echo "=== $func -> $role_name ==="

  # List attached policies
  aws iam list-attached-role-policies --role-name "$role_name" \
    --query 'AttachedPolicies[*].[PolicyName,PolicyArn]' --output table

  # Check for wildcard actions
  for policy_arn in $(aws iam list-attached-role-policies --role-name "$role_name" --query 'AttachedPolicies[*].PolicyArn' --output text); do
    version=$(aws iam get-policy --policy-arn "$policy_arn" --query 'Policy.DefaultVersionId' --output text)
    aws iam get-policy-version --policy-arn "$policy_arn" --version-id "$version" \
      --query 'PolicyVersion.Document' --output json | python3 -c "
import json, sys
doc = json.load(sys.stdin)
for stmt in doc.get('Statement', []):
    actions = stmt.get('Action', [])
    if isinstance(actions, str): actions = [actions]
    resources = stmt.get('Resource', [])
    if isinstance(resources, str): resources = [resources]
    if '*' in actions or any(a.endswith(':*') for a in actions):
        print(f'  WARNING: {stmt[\"Effect\"]} {actions} on {resources}')
" 2>/dev/null
  done
done
Step 3: Check Environment Variables for Secrets

Scan function environment variables for hardcoded credentials, API keys, and database connection strings.

bash
# AWS Lambda: Extract environment variables
for func in $(aws lambda list-functions --query 'Functions[*].FunctionName' --output text); do
  envvars=$(aws lambda get-function-configuration --function-name "$func" \
    --query 'Environment.Variables' --output json 2>/dev/null)
  if [ "$envvars" != "null" ] && [ -n "$envvars" ]; then
    echo "=== $func ==="
    echo "$envvars" | python3 -c "
import json, sys, re
vars = json.load(sys.stdin)
sensitive_patterns = [
    r'(?i)(password|secret|key|token|credential|api.?key)',
    r'(?i)(aws.?access|aws.?secret)',
    r'(?i)(database.?url|connection.?string|db.?pass)',
    r'AKIA[0-9A-Z]{16}'
]
for key, value in vars.items():
    for pattern in sensitive_patterns:
        if re.search(pattern, key) or re.search(pattern, str(value)):
            masked = value[:4] + '****' + value[-4:] if len(value) > 8 else '****'
            print(f'  SENSITIVE: {key} = {masked}')
            break
"
  fi
done

# Azure Functions: Check app settings
for app in $(az functionapp list --query "[].name" -o tsv); do
  rg=$(az functionapp show --name "$app" --query "resourceGroup" -o tsv)
  echo "=== $app ==="
  az functionapp config appsettings list \
    --name "$app" --resource-group "$rg" \
    --query "[?contains(name,'KEY') || contains(name,'SECRET') || contains(name,'PASSWORD')].{Name:name}" \
    -o table 2>/dev/null
done
Step 4: Review Function Triggers and Access Controls

Verify that function triggers have appropriate authentication and authorization.

bash
# AWS: Check for unauthenticated Lambda function URLs
aws lambda list-function-url-configs \
  --function-name FUNCTION_NAME \
  --query 'FunctionUrlConfigs[*].[FunctionUrl,AuthType,Cors]' --output table

# Check for resource-based policies allowing public invocation
for func in $(aws lambda list-functions --query 'Functions[*].FunctionName' --output text); do
  policy=$(aws lambda get-policy --function-name "$func" --query 'Policy' --output text 2>/dev/null)
  if [ -n "$policy" ]; then
    echo "$policy" | python3 -c "
import json, sys
doc = json.loads(sys.stdin.read())
for stmt in doc.get('Statement', []):
    principal = stmt.get('Principal', {})
    if principal == '*' or principal == {'AWS': '*'}:
        print(f'WARNING: $func has public invoke policy: {stmt.get(\"Sid\", \"unnamed\")}')" 2>/dev/null
  fi
done

# GCP: Check for unauthenticated Cloud Functions
gcloud functions list --format=json | python3 -c "
import json, sys
functions = json.load(sys.stdin)
for func in functions:
    name = func.get('name', '').split('/')[-1]
    trigger = func.get('httpsTrigger', {})
    if trigger and func.get('ingressSettings') == 'ALLOW_ALL':
        print(f'WARNING: {name} allows all ingress traffic')
"
Step 5: Analyze Function Code for Security Vulnerabilities

Review function code for common serverless security issues.

bash
# Download Lambda function code for review
aws lambda get-function --function-name FUNCTION_NAME \
  --query 'Code.Location' --output text | xargs curl -o function.zip
unzip function.zip -d function-code/

# Scan with Bandit (Python) or ESLint security plugin (Node.js)
# Python functions
pip install bandit
bandit -r function-code/ -f json -o bandit-results.json

# Node.js functions
npm install -g eslint @microsoft/eslint-plugin-sdl
eslint --ext .js function-code/

# Check for common serverless vulnerabilities:
# 1. SQL injection in database queries
# 2. Command injection via os.system or subprocess
# 3. Insecure deserialization
# 4. Event data injection (untrusted event parameters)
# 5. Excessive function permissions
grep -rn "os.system\|subprocess\|eval(\|exec(" function-code/ || echo "No obvious injection patterns"
grep -rn "pickle.loads\|yaml.load\b" function-code/ || echo "No deserialization risks"
Step 6: Run Automated Serverless Security Scanning

Execute Checkov and Prowler for automated compliance checks on serverless resources.

bash
# Checkov scan for serverless frameworks
checkov -d ./serverless-project/ \
  --framework serverless \
  --output json > checkov-serverless.json

# Prowler Lambda-specific checks
prowler aws \
  --checks lambda_function_no_secrets_in_variables \
           lambda_function_url_auth_type \
           lambda_function_using_supported_runtimes \
           lambda_function_not_publicly_accessible \
  -M json-ocsf \
  -o ./prowler-lambda/

Key Concepts

TermDefinition
Execution RoleIAM role assumed by a serverless function during execution that defines what AWS/cloud resources the function can access
Event InjectionServerless-specific attack where untrusted data in the event trigger payload is used unsafely in function logic
Function URLDirect HTTP(S) endpoint for invoking Lambda functions without API Gateway, which may be configured without authentication
Cold StartInitial function execution that includes container provisioning, during which security agents and extensions must initialize
Resource-Based PolicyPolicy attached to the function itself that defines who can invoke it, separate from the execution role
Secrets Manager IntegrationPattern of retrieving sensitive configuration from a secrets management service rather than storing in environment variables
Show full SKILL.md (239 more words)Show less

Tools & Systems

  • AWS Lambda: Primary serverless compute platform with execution roles, layers, and resource policies
  • Checkov: Static analysis tool for infrastructure-as-code with serverless-specific security policies
  • Prowler: Cloud security tool with Lambda-specific checks for permissions, public access, and runtime versions
  • Bandit: Python static analysis tool for detecting security issues in function source code
  • OWASP Serverless Top 10: Security risk framework specific to serverless architectures

Common Scenarios

Scenario: Lambda Function with Admin Role Leaking Secrets via Environment Variables

Context: A security review discovers a Lambda function with AdministratorAccess execution role and database credentials stored in plaintext environment variables visible in CloudWatch logs.

Approach:

  1. Enumerate the function's execution role and discover AdministratorAccess managed policy
  2. Check environment variables and find DB_PASSWORD, API_KEY, and STRIPE_SECRET_KEY in plaintext
  3. Review CloudWatch logs and find credentials printed in debug log statements
  4. Create a scoped IAM policy granting only the specific DynamoDB and S3 actions needed
  5. Migrate secrets to AWS Secrets Manager and update function to retrieve at runtime
  6. Remove debug logging that outputs sensitive data
  7. Rotate all exposed credentials and enable Lambda function encryption with KMS

Pitfalls: Changing a function's execution role can break it if the new role is too restrictive. Test in a staging environment first. Environment variable changes trigger a new function version, so ensure aliases and triggers are updated. Secrets Manager calls add latency; cache secrets within the execution context to avoid per-invocation lookups.

Output Format

Serverless Function Security Review
=======================================
Account: 123456789012
Functions Reviewed: 34
Review Date: 2026-02-23

CRITICAL FINDINGS:
[SRVL-001] Overly Permissive Execution Role
  Function: payment-processor
  Role: AdministratorAccess (full AWS access)
  Required Permissions: DynamoDB:PutItem, S3:GetObject (2 actions)
  Remediation: Create scoped policy with only required permissions

[SRVL-002] Secrets in Environment Variables
  Function: payment-processor
  Variables: DB_PASSWORD, STRIPE_SECRET_KEY, API_KEY
  Risk: Visible in console, API, and CloudWatch logs
  Remediation: Migrate to Secrets Manager, remove from env vars

SUMMARY:
  Functions with admin roles:           3 / 34
  Functions with secrets in env vars:   8 / 34
  Functions with deprecated runtimes:   5 / 34
  Functions with public access:         2 / 34
  Functions without VPC:               28 / 34
  Functions with wildcard permissions: 12 / 34

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/performing-serverless-function-security-review of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Serverless Function Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Serverless Function Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Serverless Function Security Review this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Serverless IntegrationsDataDog/dd-trace-js836—~1.1kAutomated safety check: PassCustom licence
Polylith Base CreationDavidVujic/python-polylith553—~757Automated safety check: PassMIT
Polylith Project ManagementDavidVujic/python-polylith553—~1.5kAutomated safety check: PassMIT
Google Cloud Solution N Tier Serverless Web Appgoogle/skills21k—~5.5kAutomated safety check: PassApache-2.0
Connecting Lambda To API Gatewayaws/agent-toolkit-for-aws2.8k—~422Automated safety check: PassApache-2.0

Similar skills

  • Serverless Integrations

    DataDog/dd-trace-js

    Official

    A skill your agent uses when adding, modifying, debugging, or reviewing dd-trace-js serverless platform integrations that create root invocation spans for AWS Lambda, Azure Functions, Google Cloud…

    836 GitHub stars~1.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Polylith Base Creation

    DavidVujic/python-polylith

    Create a Polylith base with poly create base — the entry point of a deployable application (HTTP API, CLI, message-queue consumer, AWS Lambda handler, GCP Cloud Function, scheduled job).

    553 GitHub stars~757 tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Polylith Project Management

    DavidVujic/python-polylith

    Create a deployable Polylith project with poly create project — a lightweight pyproject.toml under projects/<name/ that references bricks for deployment as a Docker image, wheel, AWS Lambda, GCP…

    553 GitHub stars~1.5k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Assists in designing and implementing secure n-tier serverless web applications and microservices on Google Cloud.

    21k GitHub stars~5.5k tokensUpdated today
    Backend & APIsAuto-check passed
  • Connecting Lambda To API Gateway

    aws/agent-toolkit-for-aws

    Official

    Connects an existing AWS Lambda function to Amazon API Gateway by creating a REST or HTTP API with resource/method setup, Lambda proxy integration, permissions, and deployment.

    2.8k GitHub stars~422 tokensUpdated today
    Backend & APIsAuto-check passed
  • AWS Serverless Eda

    zxkane/aws-skills

    AWS serverless and event-driven architecture expert based on Well-Architected Framework.

    367 GitHub starsUsed in 4 repos~3.2k tokens
    Backend & APIsAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 639 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Performing Serverless Function Security Review

What does Performing Serverless Function Security Review do?

Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables…. Performing Serverless Function Security Review is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections.

When should I use Performing Serverless Function Security Review?

Performing Serverless Function Security Review fits situations like: tasks that involve Serverless; tasks that involve Security review.

How do I install Performing Serverless Function Security Review in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-serverless-function-security-review -a claude-code`. Or copy the skill folder (skills/performing-serverless-function-security-review in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-serverless-function-security-review in your project. Claude Code loads it when a task matches its description.

How do I install Performing Serverless Function Security Review in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-serverless-function-security-review -a codex`. Or copy the skill folder (skills/performing-serverless-function-security-review in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-serverless-function-security-review in your project. Codex loads it when a task matches its description.

Can I use Performing Serverless Function Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-serverless-function-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-serverless-function-security-review, .gemini/skills/performing-serverless-function-security-review, .github/skills/performing-serverless-function-security-review and .opencode/skills/performing-serverless-function-security-review in your project.

What does Performing Serverless Function Security Review need to run?

Going by SKILL.md and its folder, Performing Serverless Function Security Review needs Python for the scripts in its folder, the command-line tools its instructions call (aws, az, python3, gcloud, pip and npm) and credentials named DB_PASSWORD, API_KEY and STRIPE_SECRET_KEY. Our summary lists: Python 3; Node.js; A credential in API_KEY; A credential in STRIPE_SECRET_KEY.

Does Performing Serverless Function Security Review access the network?

SKILL.md contains no URLs. Its commands use pip and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Performing Serverless Function Security Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Serverless Function Security Review use?

Performing Serverless Function Security Review is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Serverless Function Security Review use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 699 tokens, read only when the agent opens those files.

What are the alternatives to Performing Serverless Function Security Review?

Skills that share tags, products or a category with Performing Serverless Function Security Review: Serverless Integrations (DataDog/dd-trace-js, 836 stars), Polylith Base Creation (DavidVujic/python-polylith, 553 stars), Polylith Project Management (DavidVujic/python-polylith, 553 stars) and Google Cloud Solution N Tier Serverless Web App (google/skills, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Serverless Function Security Review?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,870 GitHub stars. The repository holds 639 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.