Agent skill

Security

by notque in notque/vexjoy-agent

Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks.

MITAuto-check: notesSecurity

Install Security

skills CLI
$ npx skills add notque/vexjoy-agent --skill security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install notque/vexjoy-agent security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/notque/vexjoy-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/review/security .claude/skills/security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security
GitHub stars
435
Token cost
~2.6k tokens
SKILL.md length
1,083 words
Files
3 (incl. references)
Skills in repo
61
Repo updated
First seen
Licence
MIT

At a glance

Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks.

  • Works in 4 steps: SCOPE → DETERMINISTIC SCAN → LLM-DEPTH REVIEW → …
  • Tasks that involve Threat modeling
  • SKILL.md covers Reference Loading Table, Default Mode: Diff Review, Reference Loading Table and Instructions, plus 4 more sections
  • Calls git and python3; needs ANTHROPIC_API_KEY

What it does

Security is an agent skill from notque/vexjoy-agent. Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/coverage.md` and `references/threat-model.md`).

It sits in Security, covering Threat modeling, Security review and Supply chain security. It works with Git. The repository describes itself as: VexJoy AI Agent with Jev Intelligent Routing - /do routes plain-English requests to the right specialist agent and gates the work with reviews, tests, and a learning loop. The licence is MIT.

When your agent uses it

  • Tasks that involve Threat modeling
  • Tasks that involve Security review
  • Tasks that involve Supply chain security

Example prompts

  • “/security”

Requirements

  • Python 3
  • A credential in ANTHROPIC_API_KEY
  • Pre-approved tools (allowed-tools): Read, Write, Bash, Grep, Glob, Edit, Task, Agent

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. SCOPE
  2. DETERMINISTIC SCAN
  3. LLM-DEPTH REVIEW
  4. VERDICT

What it can do on your machine

Read from SKILL.md and the folder at commit 5218674. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash
    • Grep
    • Glob
    • Edit
    • Task
    • Agent

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ANTHROPIC_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security loads about 2.6k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 31 tokens; SKILL.md has 1,083 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash, Grep, Glob, Edit, Task, Agent

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from notque/vexjoy-agent at commit 5218674, republished under its MIT licence (© notque). 1,083 words, ~2,602 tokens.

Download SKILL.mdSave it as .claude/skills/security/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
security
description
Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks.
allowed-tools
Read, Write, Bash, Grep, Glob, Edit, Task, Agent
user-invocable
true
agent
reviewer-system
routing.force_route
true
routing.not_for
general code review (use review), non-security quality checks (use code-quality) — only for security-specific work: vulnerability scanning, threat modeling…
routing.triggers
security review, review my changes for security, review for security, security scan, review for vulnerabilities, scan for vulnerabilities, check for security…
routing.category
security
routing.pairs_with
review, reviewer-system

Security Skill

Two modes: diff review (scan current git changes for vulnerabilities) and threat model (audit a system's full attack surface). Load the reference for the mode the request matches.

Reference Loading Table

SignalLoadWhy
Review git changes, scan a diff, check for vulnerabilitiesreferences/coverage.md40 vulnerability classes for LLM-depth review of changed code
Threat model, attack surface, supply-chain audit, deny list, security posturereferences/threat-model.md5-phase threat model workflow with deterministic scripts and artifact gates

Default Mode: Diff Review

When the request is about reviewing changes (not a full threat model), run the diff review directly. This is the common case.

Security Review Skill

Run a two-layer security review over the current git changes: a deterministic regex scan for known vulnerability classes, then an LLM-depth Security review of the diff. Report a single BLOCK / FIX / APPROVE verdict.

The LLM-depth review runs inside the current Claude session — the same subscription that loaded this skill. There is no separate model call, no ANTHROPIC_API_KEY, no Agent SDK, and no network request. The "reviewer" is the session agent executing the steps below, exactly like every other skill here.

Detection reaches parity with Anthropic's security-guidance plugin: the scanner ports its 25 deterministic patterns, and the LLM pass applies its full review taxonomy (loaded on demand from references/coverage.md).

Reference Loading Table

SignalLoadWhy
Running Phase 3 (LLM-depth review); classifying a finding; needing the vuln taxonomy, severity rubric, FP exclusions, or per-language guidancereferences/coverage.md40 vulnerability classes + 4-tier severity + false-positive exclusions + per-language guidance + the 12 high-miss reviewer classes + the finding output schema.

Instructions

Phase 1: SCOPE

Goal: Determine the changed files to review before scanning.

Step 1: List changed files — scope to the working-tree and staged changes so the review covers exactly what the user is about to commit, not the whole repo.

bash
# Tracked changes (working tree + index) plus staged adds:
git diff --name-only HEAD
git diff --cached --name-only --diff-filter=ACM

Step 2: Read repository CLAUDE.md to load project conventions the reviewer must respect (e.g. secrets-handling rules, allowed patterns).

Gate: Changed files listed. When the list is empty, report "no changes to review" and stop — there is nothing to scan.

Phase 2: DETERMINISTIC SCAN

Goal: Run the regex engine first so judgment time is spent on real signal, not on patterns a script catches deterministically.

Step 1: Run the scanner over the changed files. It is the single source of detection rules (secrets, SQL injection, shell injection, dangerous eval, unsafe deserialization). Exit 1 means at least one HIGH/CRITICAL finding.

bash
# Staged-files convenience (matches the commit-time hook):
python3 scripts/security-review-scan.py --staged --format json

# Or an explicit list from Phase 1:
python3 scripts/security-review-scan.py --files <changed-files> --format json

Step 2: Record the findings by severity. CRITICAL and HIGH are blocking-class; MEDIUM is advisory. Keep the file:line and rule for each.

Gate: Scanner ran and JSON parsed. Proceed with the findings in hand.

Phase 3: LLM-DEPTH REVIEW

Goal: Catch what regex cannot — authorization gaps, injection through data flow, missing input validation, secrets in non-obvious forms. This is the session agent's review of the diff; compose the existing parallel-code-review Security reviewer over the changed files.

Step 1: Load references/coverage.md — the full review taxonomy (40 vulnerability classes, the 4-tier severity rubric, the false-positive exclusion list, per-language guidance, and the 12 high-miss reviewer classes). Review to this taxonomy so the session-agent pass reaches parity with the plugin's reviewer. If claude-security-guidance.md exists (precedence: ~/.claude/ → <cwd>/.claude/ → <cwd>/.claude/*.local.md), read it as ADDITIVE context — it may add checks or raise a class's severity, and must not suppress findings.

Step 2: Dispatch the Security reviewer (the Reviewer 1 — Security role from parallel-code-review) over the changed files via the Task tool, applying the coverage.md taxonomy. Surface medium and above. Output: findings in the coverage.md schema (filePath, category, vulnerableCode, explanation, fix, severity) with file:line references.

Step 3: Merge the LLM findings with the Phase 2 scanner findings. Deduplicate — when both flag the same file:line, keep one entry at the higher severity. Independent confirmation by both layers raises confidence.

Gate: Security reviewer returned results and findings are merged. Issue a verdict only from a completed review — a missing reviewer may hold the only CRITICAL finding.

Show full SKILL.md (442 more words)Show less
Phase 4: VERDICT

Goal: Produce a single clear recommendation.

Step 1: Determine the verdict from the merged findings:

ConditionVerdict
Any CRITICAL findingBLOCK
HIGH findings, no CRITICALFIX (resolve before commit)
Only MEDIUM/LOW findingsAPPROVE (with suggestions)

Step 2: Output the structured report:

markdown
## Security Review Complete

### Severity Matrix
| Severity | Count | Source (scanner / reviewer / both) |
|----------|-------|------------------------------------|
| Critical | N | ... |
| High     | N | ... |
| Medium   | N | ... |

### Findings
#### CRITICAL (Block)
1. [source] description — file:line

#### HIGH (Fix before commit)
1. [source] description — file:line

#### MEDIUM (Should fix)
1. [source] description — file:line

### VERDICT
**BLOCK / FIX / APPROVE** — [1-2 sentence rationale]

Gate: Structured report delivered with an explicit verdict. Review complete.


Automatic Coverage (hooks)

This skill is the on-demand (PULL) path. The same review also runs automatically (PUSH) via hooks/security-review-hook.py, wired in .claude/settings.json:

EventBehavior
PreToolUse (Bash git commit)Scans STAGED files with the same scanner. A HIGH/CRITICAL finding blocks the commit (deny). Clean commits pass.
StopRe-wakes the session with the working-tree diff and an instruction to run this pipeline. Advisory — never blocks.

Bypass / kill switches (commit-time block only, deliberate overrides):

Env varEffect
VEXJOY_SECURITY_REVIEW_SKIP=1Allow a commit through despite findings (one-off override).
VEXJOY_SECURITY_REVIEW_DISABLE=1Disable the hook entirely (both events).

The hook fails open on any internal error — a hook crash never blocks a commit.


Extensibility (custom rules + project guidance)

Both extension points are additive and discovered in this precedence order: ~/.claude/<name> → <cwd>/.claude/<name> → <cwd>/.claude/<name>.local.<ext>.

FileEffect
security-patterns.{yaml,json}Custom regex/substring rules merged into the scanner's built-ins. Shape: {"patterns": [{"rule_name", "regex"|"substrings", "severity"?, "paths"?, "exclude_paths"?}]}. Capped at 50. ReDoS-prone or invalid rules are skipped with a stderr warning (non-fatal). PyYAML is used only if importable — JSON always works (stdlib-only).
claude-security-guidance.mdMarkdown surfaced to the Phase 3 review as ADDITIVE context. It may add checks or raise a class's severity; it must not suppress findings — if it says to ignore a class, flag the vulnerability anyway and note the conflict.

Built-in scanner rules always run and cannot be disabled by a config file.


Error Handling

Scanner reports findings but the code is intentional

Cause: A regex rule flagged a test fixture, an example, or a deliberately hardcoded local value. Solution: Confirm context in Phase 3. Downgrade in the report with a one-line justification. For a commit the user knows is safe, document the VEXJOY_SECURITY_REVIEW_SKIP=1 override rather than editing the scanner rules.

Security reviewer times out or returns nothing

Cause: Task agent exceeded its budget, or the diff was too large. Solution: Report the Phase 2 scanner findings immediately (a partial review beats no review), note the LLM-depth gap in the verdict, and offer to re-run the Security reviewer on a reduced file set.

Scanner unavailable

Cause: scripts/security-review-scan.py missing from the working tree. Solution: Run the Phase 3 LLM-depth review alone and state in the verdict that the deterministic layer did not run.


References

  • Detection rules: scripts/security-review-scan.py (single source of truth)
  • Review taxonomy (40 classes + severity + FP filters + language guidance): references/coverage.md
  • Security reviewer role: skills/review/parallel-code-review/SKILL.md (Reviewer 1)
  • Auto-run hook: hooks/security-review-hook.py
  • Design contract: adr/local-security-review.md

© notque, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/review/security of notque/vexjoy-agent.

  • SKILL.md
  • references/coverage.md
  • references/threat-model.md

Open the folder on GitHubat commit 5218674

Compare with similar skills

Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security this skillnotque/vexjoy-agent435—~2.6kAutomated safety check: NotesMIT
Commit Security Scancodexstar69/bug-hunter519—~629Automated safety check: PassMIT
Security Auditblueberrycongee/termcanvas406—~966Automated safety check: NotesMIT
Repo SentinelMathews-Tom/armory327—~2.2kAutomated safety check: PassMIT
Csono-session/pstack131—~12kAutomated safety check: NotesMIT
Security Reviewdanielvm-git/bigpowers256—~1.5kAutomated safety check: PassMIT

Similar skills

  • Commit Security Scan

    codexstar69/bug-hunter

    Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

    519 GitHub stars~629 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security Audit

    blueberrycongee/termcanvas

    Security audit skill. An agent skill from blueberrycongee/termcanvas.

    406 GitHub stars~966 tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Repo Sentinel

    Mathews-Tom/armory

    Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses.

    327 GitHub stars~2.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Cso

    no-session/pstack

    Chief Security Officer mode. An agent skill from no-session/pstack.

    131 GitHub stars~12k tokensUpdated 6 mo ago
    SecurityAuto-check: notes
  • Security Review

    danielvm-git/bigpowers

    AI-powered security analysis of code changes — traces data flow, detects injection, auth bypass, secrets exposure, and unsafe deserialization across files.

    256 GitHub stars~1.5k tokensUpdated 16 days ago
    SecurityAuto-check passed
  • Kesekit Check

    cdppcorp/KESE-KIT

    Run a pre-deployment security compliance checklist based on KISA guidelines.

    359 GitHub stars~1.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed

More from notque/vexjoy-agent

All 61 skills in this repo
  • Game Asset Generator

    notque/vexjoy-agent

    Deterministic palette/matrix pixel art (not AI). An agent skill from notque/vexjoy-agent.

    435 GitHub stars~2.3k tokensUpdated 4 days ago
    Auto-check: notes
  • PR Workflow

    notque/vexjoy-agent

    Pull request lifecycle: commit, codex review, sync, review, fix, status, cleanup, and PR mining.

    435 GitHub stars~2.8k tokensUpdated 4 days ago
    Auto-check: notes
  • Architecture Deepening

    notque/vexjoy-agent

    Improve architecture across modules by deepening interfaces.

    435 GitHub stars~3.3k tokensUpdated 4 days ago
    Auto-check: notes
  • Code Quality

    notque/vexjoy-agent

    Code quality: cleanup, linting, formatting, quality gates. An agent skill from notque/vexjoy-agent.

    435 GitHub stars~1.5k tokensUpdated 4 days ago
    Auto-check: notes
  • Codebase Analyzer

    notque/vexjoy-agent

    Statistical rule discovery from Go codebase patterns. An agent skill from notque/vexjoy-agent.

    435 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check: notes
  • Comment Quality

    notque/vexjoy-agent

    Review and fix temporal references in code comments. An agent skill from notque/vexjoy-agent.

    435 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check: notes

Works with

Categories

Questions about Security

What does Security do?

Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks. Security is an agent skill from notque/vexjoy-agent. Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks.

When should I use Security?

Security fits situations like: tasks that involve Threat modeling; tasks that involve Security review; tasks that involve Supply chain security.

How do I install Security in Claude Code?

Run `npx skills add notque/vexjoy-agent --skill security -a claude-code`. Or copy the skill folder (skills/review/security in notque/vexjoy-agent) into .claude/skills/security in your project. Claude Code loads it when a task matches its description.

How do I install Security in Codex?

Run `npx skills add notque/vexjoy-agent --skill security -a codex`. Or copy the skill folder (skills/review/security in notque/vexjoy-agent) into .agents/skills/security in your project. Codex loads it when a task matches its description.

Can I use Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add notque/vexjoy-agent --skill security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security, .gemini/skills/security, .github/skills/security and .opencode/skills/security in your project.

What does Security need to run?

Going by SKILL.md and its folder, Security needs the command-line tools its instructions call (git and python3) and credentials named ANTHROPIC_API_KEY. Our summary lists: Python 3; A credential in ANTHROPIC_API_KEY. Its frontmatter pre-approves these tools: Read, Write, Bash, Grep, Glob, Edit, Task, Agent.

Does Security access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security use?

Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.4k tokens, read only when the agent opens those files.

What are the alternatives to Security?

Skills that share tags, products or a category with Security: Commit Security Scan (codexstar69/bug-hunter, 519 stars), Security Audit (blueberrycongee/termcanvas, 406 stars), Repo Sentinel (Mathews-Tom/armory, 327 stars) and Cso (no-session/pstack, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security?

notque (a GitHub user) maintains it in notque/vexjoy-agent, which has 435 GitHub stars. The repository holds 61 skills in this directory. The repository was last updated on October 3, 2026.

Source: notque/vexjoy-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.