Agent skill

Secure Code Guidance

by nightly-labs in nightly-labs/openbot

Review or write Python, JavaScript, TypeScript, or Go code using secure defaults.

Custom licenceAuto-check passedSecurity

Install Secure Code Guidance

skills CLI
$ npx skills add nightly-labs/openbot --skill secure-code-guidance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nightly-labs/openbot secure-code-guidance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nightly-labs/openbot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/marketplace/production-catalog/skills/secure-code-guidance .claude/skills/secure-code-guidance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secure-code-guidance
GitHub stars
453
Token cost
~369 tokens
SKILL.md length
146 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
Custom licence

At a glance

Review or write Python, JavaScript, TypeScript, or Go code using secure defaults.

  • Tasks that involve Security review
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Secure Code Guidance is an agent skill from nightly-labs/openbot. Review or write Python, JavaScript, TypeScript, or Go code using secure defaults. Use only for explicit security guidance, security reviews, or secure implementation requests, not ordinary code review.

Its SKILL.md is about 370 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review. It works with TypeScript, JavaScript and Python. The repository describes itself as: A local-first desktop workspace for persistent AI teammates. Run Codex, Claude, and Grok with dedicated workspaces, task queues, file sharing, browser control, and agent-to-agent…

When your agent uses it

  • Tasks that involve Security review

Example prompts

  • “/secure-code-guidance”

What it can do on your machine

Read from SKILL.md and the folder at commit c6ffd01. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secure Code Guidance loads about 369 tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 146 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~369

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 146 words (~369 tokens).

“Ground the work in the repository before giving security advice. Identify the languages, frameworks, exposed entry points, trust boundaries, and existing project rules that apply.”

— opening of SKILL.md by nightly-labs, Custom licence
name
secure-code-guidance

Read the full SKILL.md on GitHub

Files

Just SKILL.md in marketplace/production-catalog/skills/secure-code-guidance of nightly-labs/openbot.

Open the folder on GitHubat commit c6ffd01

Compare with similar skills

Secure Code Guidance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secure Code Guidance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secure Code Guidance this skillnightly-labs/openbot453—~369Automated safety check: PassCustom licence
Openai Security Best Practicestrailofbits/skills-curated5129 repos~2.2kAutomated safety check: NotesCC-BY-SA-4.0
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Supercov Securitysupercorp-ai/supercov1501 repos~236Automated safety check: PassMIT
Security Analysismicrosoft/haste107—~1kAutomated safety check: PassMIT

Similar skills

  • Openai Security Best Practices

    trailofbits/skills-curated

    Official

    Perform language and framework specific security best-practice reviews and suggest improvements.

    512 GitHub starsUsed in 9 repos~2.2k tokens
    SecurityAuto-check: notes
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated today
    SecurityAuto-check: notes
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Supercov Security

    supercorp-ai/supercov

    Scans a repository's source for security vulnerabilities with the supercov CLI, pointing to the line of each finding and mapping it to CWE classes.

    150 GitHub starsUsed in 1 repo~236 tokens
    Testing & QAAuto-check passed
  • Security Analysis

    microsoft/haste

    Official

    Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste.

    107 GitHub stars~1k tokensUpdated today
    SecurityAuto-check passed
  • Myrqen

    stijnswapped/Myrqen

    Run an authorized, local-first application security assessment on the current project using this agent's own reasoning.

    137 GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from nightly-labs/openbot

All 14 skills in this repo
  • Biome Anti Slop

    nightly-labs/openbot

    Install and configure vendored Biome anti-slop GritQL rules in a local TypeScript or JavaScript repository.

    453 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Release Upgrade Safety

    nightly-labs/openbot

    Audit a pending OpenBot release for upgrade and data-loss hazards before the version is bumped or tagged.

    453 GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Babysit

    nightly-labs/openbot

    Babysit a pull request through the NorbiAI review loop until no valid issue remains.

    453 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Openbot Export

    nightly-labs/openbot

    Export the user's Grok Bot agents into one .zip file that OpenBot imports, with instructions, avatars, skills, routines, memories, group chats, and optional workspace files.

    453 GitHub stars~2.4k tokensUpdated today
    Auto-check: notes
  • Ship

    nightly-labs/openbot

    Ship the current branch to main. An agent skill from nightly-labs/openbot.

    453 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Smoke

    nightly-labs/openbot

    Start one or more local OpenBot dev instances and smoke test the features that the current changes or a pull request add.

    453 GitHub stars~1.6k tokensUpdated today
    Auto-check: notes

Questions about Secure Code Guidance

What does Secure Code Guidance do?

Review or write Python, JavaScript, TypeScript, or Go code using secure defaults. Secure Code Guidance is an agent skill from nightly-labs/openbot. Review or write Python, JavaScript, TypeScript, or Go code using secure defaults.

When should I use Secure Code Guidance?

Secure Code Guidance fits situations like: tasks that involve Security review.

How do I install Secure Code Guidance in Claude Code?

Run `npx skills add nightly-labs/openbot --skill secure-code-guidance -a claude-code`. Or copy the skill folder (marketplace/production-catalog/skills/secure-code-guidance in nightly-labs/openbot) into .claude/skills/secure-code-guidance in your project. Claude Code loads it when a task matches its description.

How do I install Secure Code Guidance in Codex?

Run `npx skills add nightly-labs/openbot --skill secure-code-guidance -a codex`. Or copy the skill folder (marketplace/production-catalog/skills/secure-code-guidance in nightly-labs/openbot) into .agents/skills/secure-code-guidance in your project. Codex loads it when a task matches its description.

Can I use Secure Code Guidance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nightly-labs/openbot --skill secure-code-guidance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secure-code-guidance, .gemini/skills/secure-code-guidance, .github/skills/secure-code-guidance and .opencode/skills/secure-code-guidance in your project.

What does Secure Code Guidance need to run?

SKILL.md names no scripts, command-line tools or credentials: Secure Code Guidance is instructions for the agent only.

Does Secure Code Guidance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Secure Code Guidance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Secure Code Guidance use?

Secure Code Guidance has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Secure Code Guidance use?

About 369 tokens (SKILL.md is roughly 1.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secure Code Guidance?

Skills that share tags, products or a category with Secure Code Guidance: Openai Security Best Practices (trailofbits/skills-curated, 512 stars), CodeQL Security Scan (trailofbits/skills, 7.4k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars) and Supercov Security (supercorp-ai/supercov, 150 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secure Code Guidance?

nightly-labs (a GitHub organization) maintains it in nightly-labs/openbot, which has 453 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 7, 2026.

Source: nightly-labs/openbot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.