A skill your agent uses when working on security-sensitive code to catch secrets, eval(), innerHTML, and other dangerous patterns before they're written.

MITAuto-check passed

Install Security Watch

skills CLI
$ npx skills add proffesor-for-testing/agentic-qe --skill security-watch -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install proffesor-for-testing/agentic-qe security-watch --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/proffesor-for-testing/agentic-qe.git skills-src && mkdir -p .claude/skills && cp -r skills-src/assets/skills/security-watch .claude/skills/security-watch && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-watch
GitHub stars
494
Token cost
~657 tokens
SKILL.md length
120 words
Files
2 (incl. scripts)
Skills in repo
95
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when working on security-sensitive code to catch secrets, eval(), innerHTML, and other dangerous patterns before they're written.

  • Working on security-sensitive code to catch secrets
  • SKILL.md covers What It Does, Activation, Hook Configuration and Detection Patterns, plus 1 more section
  • Runs Shell scripts from its folder
  • Other dangerous patterns before theyre written

What it does

Security Watch is an agent skill from proffesor-for-testing/agentic-qe. Use when working on security-sensitive code to catch secrets, eval(), innerHTML, and other dangerous patterns before they're written. Activate with /security-watch for real-time security scanning.

Its SKILL.md is about 660 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/scan-security.sh`).

The repository describes itself as: Agentic QE Fleet is an open-source AI-powered QA/QE platform designed for use with Coding Agents (works best with Claude Code) featuring specialized agents and skills to support… The licence is MIT.

When your agent uses it

  • Working on security-sensitive code to catch secrets
  • Other dangerous patterns before theyre written

Example prompts

  • “/security-watch”

Requirements

  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit 829d030. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Watch loads about 657 tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 120 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~657

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from proffesor-for-testing/agentic-qe at commit 829d030, republished under its MIT licence (© proffesor-for-testing). 120 words, ~657 tokens.

Download SKILL.mdSave it as .claude/skills/security-watch/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
security-watch
description
Use when working on security-sensitive code to catch secrets, eval(), innerHTML, and other dangerous patterns before they're written. Activate with /security-watch for real-time security scanning.
user-invocable
true

Security Watch Mode

When activated, scans every file write for common security anti-patterns and blocks dangerous code from being committed.

What It Does

Flags or blocks writes containing:

  • Secrets: API keys, passwords, tokens, private keys in source code
  • Dangerous functions: eval(), Function(), innerHTML, dangerouslySetInnerHTML
  • Injection vectors: Unsanitized template literals in SQL/shell commands
  • Insecure config: http:// URLs, disabled TLS verification, * CORS origins

Activation

/security-watch

Hook Configuration

json
{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Write|Edit",
        "hook": ".claude/skills/security-watch/scripts/scan-security.sh"
      }
    ]
  }
}

Detection Patterns

bash
#!/bin/bash
# scan-security.sh
CONTENT="$1"
ISSUES=0

# Secrets detection
SECRET_PATTERNS=(
  'AKIA[0-9A-Z]{16}'                    # AWS Access Key
  'sk-[a-zA-Z0-9]{48}'                  # OpenAI API Key
  'ghp_[a-zA-Z0-9]{36}'                 # GitHub Personal Token
  'password\s*[:=]\s*["\x27][^"\x27]+'  # Hardcoded passwords
  'BEGIN (RSA |EC )?PRIVATE KEY'         # Private keys
  'sk_live_[a-zA-Z0-9]+'                # Stripe secret key
)

for pattern in "${SECRET_PATTERNS[@]}"; do
  if echo "$CONTENT" | grep -qP "$pattern"; then
    echo "BLOCKED: Potential secret detected matching pattern: $pattern"
    ISSUES=$((ISSUES + 1))
  fi
done

# Dangerous functions
DANGER_PATTERNS=(
  '\beval\s*\('
  '\bFunction\s*\('
  '\.innerHTML\s*='
  'dangerouslySetInnerHTML'
  'child_process.*exec\('
  '\$\{.*\}.*(?:SELECT|INSERT|UPDATE|DELETE)'
)

for pattern in "${DANGER_PATTERNS[@]}"; do
  if echo "$CONTENT" | grep -qP "$pattern"; then
    echo "WARNING: Dangerous pattern detected: $pattern"
    ISSUES=$((ISSUES + 1))
  fi
done

if [ $ISSUES -gt 0 ]; then
  echo "Found $ISSUES security issues. Review before proceeding."
  exit 1
fi

Gotchas

  • False positives on test fixtures that intentionally contain patterns like eval() — use // security-watch:ignore comment
  • Base64-encoded secrets won't be caught — this scans for plaintext patterns only
  • Template literal injection detection has false positives on safe string interpolation — review warnings carefully
  • This is a first line of defense, not a replacement for proper security review

© proffesor-for-testing, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in assets/skills/security-watch of proffesor-for-testing/agentic-qe.

  • SKILL.md
  • scripts/scan-security.sh

Open the folder on GitHubat commit 829d030

Compare with similar skills

Security Watch next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Watch compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Watch this skillproffesor-for-testing/agentic-qe494—~657Automated safety check: PassMIT
Openclaw Secret Scanning Maintaineropenclaw/openclaw392k—~2.5kAutomated safety check: PassMIT
Secret Scanninggithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT
Eval Harnessaffaan-m/ECC275k—~2.2kAutomated safety check: PassMIT
Secrets Managementdavila7/claude-code-templates32k12 repos~2kAutomated safety check: PassMIT
Evalalirezarezvani/claude-skills28k1 repos~618Automated safety check: PassMIT

Similar skills

  • Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.

    392k GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Secret Scanning

    github/awesome-copilot

    Official

    Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation.

    40k GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • Eval Harness

    affaan-m/ECC

    Eval-driven development (EDD) framework for AI coding sessions — define capability and regression evals before coding, grade with code-based, model-based, rule, or human graders, and track pass@k…

    275k GitHub stars~2.2k tokensUpdated 3 days ago
    AI & LLM EngineeringAuto-check passed
  • Secrets Management

    davila7/claude-code-templates

    Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.

    32k GitHub starsUsed in 12 repos~2k tokens
    DevOps & CloudAuto-check passed
  • Eval

    alirezarezvani/claude-skills

    Evaluate and rank agent results by metric or LLM judge for an AgentHub session.

    28k GitHub starsUsed in 1 repo~618 tokens
    AI & LLM EngineeringAuto-check passed
  • Secrets Vault Manager

    alirezarezvani/claude-skills

    A skill your agent uses when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret…

    28k GitHub starsUsed in 1 repo~3.6k tokens
    DevOps & CloudAuto-check: notes

More from proffesor-for-testing/agentic-qe

All 95 skills in this repo
  • Contract Testing

    proffesor-for-testing/agentic-qe

    Consumer-driven contract testing for microservices using Pact, schema validation, API versioning, and backward compatibility testing.

    494 GitHub stars~1.8k tokensUpdated 3 days ago
    Auto-check passed
  • Mutation Testing

    proffesor-for-testing/agentic-qe

    Test quality validation through mutation testing, assessing test suite effectiveness by introducing code mutations and measuring kill rate.

    494 GitHub stars~1.7k tokensUpdated 3 days ago
    Auto-check passed
  • Performance Testing

    proffesor-for-testing/agentic-qe

    Profiles application performance under load using k6, Artillery, or JMeter to measure latency, throughput, and error rates.

    494 GitHub stars~2.4k tokensUpdated 3 days ago
    Auto-check passed
  • Code Review Quality

    proffesor-for-testing/agentic-qe

    Conduct context-driven code reviews focusing on quality, testability, and maintainability.

    494 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Security Testing

    proffesor-for-testing/agentic-qe

    Scans for security vulnerabilities including XSS, SQL injection, CSRF, and auth flaws using OWASP Top 10 methodology.

    494 GitHub stars~2.7k tokensUpdated 3 days ago
    Auto-check: notes
  • Database Testing

    proffesor-for-testing/agentic-qe

    Database schema validation, data integrity testing, migration testing, transaction isolation, and query performance.

    494 GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed

Questions about Security Watch

What does Security Watch do?

A skill your agent uses when working on security-sensitive code to catch secrets, eval(), innerHTML, and other dangerous patterns before they're written. Security Watch is an agent skill from proffesor-for-testing/agentic-qe. Use when working on security-sensitive code to catch secrets, eval(), innerHTML, and other dangerous patterns before they're written.

When should I use Security Watch?

Security Watch fits situations like: working on security-sensitive code to catch secrets; other dangerous patterns before theyre written.

How do I install Security Watch in Claude Code?

Run `npx skills add proffesor-for-testing/agentic-qe --skill security-watch -a claude-code`. Or copy the skill folder (assets/skills/security-watch in proffesor-for-testing/agentic-qe) into .claude/skills/security-watch in your project. Claude Code loads it when a task matches its description.

How do I install Security Watch in Codex?

Run `npx skills add proffesor-for-testing/agentic-qe --skill security-watch -a codex`. Or copy the skill folder (assets/skills/security-watch in proffesor-for-testing/agentic-qe) into .agents/skills/security-watch in your project. Codex loads it when a task matches its description.

Can I use Security Watch in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add proffesor-for-testing/agentic-qe --skill security-watch -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-watch, .gemini/skills/security-watch, .github/skills/security-watch and .opencode/skills/security-watch in your project.

What does Security Watch need to run?

Going by SKILL.md and its folder, Security Watch needs a shell for the scripts in its folder. Our summary lists: A Bash shell.

Does Security Watch access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Watch safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Watch use?

Security Watch is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Watch use?

About 657 tokens (SKILL.md is roughly 2.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Watch?

Skills that share tags, products or a category with Security Watch: Openclaw Secret Scanning Maintainer (openclaw/openclaw, 392k stars), Secret Scanning (github/awesome-copilot, 40k stars), Eval Harness (affaan-m/ECC, 275k stars) and Secrets Management (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Watch?

proffesor-for-testing (a GitHub user) maintains it in proffesor-for-testing/agentic-qe, which has 494 GitHub stars. The repository holds 95 skills in this directory. The repository was last updated on October 4, 2026.

Source: proffesor-for-testing/agentic-qe on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.