Agent skill

Blueprint Local Security

by receptron in receptron/mulmoterminal

Review the finished app against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report.

MITAuto-check: notesSecurity

Install Blueprint Local Security

skills CLI
$ npx skills add receptron/mulmoterminal --skill blueprint-local-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install receptron/mulmoterminal blueprint-local-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/receptron/mulmoterminal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/blueprints/local/skills/security .claude/skills/blueprint-local-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
blueprint-local-security
GitHub stars
237
Token cost
~1.5k tokens
SKILL.md length
901 words
Files
1
Skills in repo
31
Repo updated
First seen
Licence
MIT

At a glance

Review the finished app against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report.

  • Works in 4 steps: Context. Read .blueprint/spec.md (above… → Audit, category by category (the list… → Fix every HIGH and MEDIUM finding, and… → …
  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers Method, What to look at in this app…, What the check sends, and must… and The report, plus 1 more section
  • Calls yarn and git

What it does

Blueprint Local Security is an agent skill from receptron/mulmoterminal. Review the finished app against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities. The repository describes itself as: Run multiple Claude Code and Codex sessions in parallel — a browser terminal grid that shows which agent needs you. Local, tmux-backed, MIT. The licence is MIT.

When your agent uses it

  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/blueprint-local-security”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Context. Read .blueprint/spec.md (above all "必ず詰める点"), then all of server/, client/src/ and
  2. Audit, category by category (the list below). For each place input enters, trace it to where it is used.
  3. Fix every HIGH and MEDIUM finding, and add a test to test/security.test.ts that fails without the fix.
  4. Report in .blueprint/security-review.md (format below).

What it can do on your machine

Read from SKILL.md and the folder at commit b3f6ff0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • yarn
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use yarn and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Blueprint Local Security loads about 1.5k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 901 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:36
    secret random and in `.env`, with `.env` listed in `.gitignore` (add it if it is not; the check fails on an `.env` tha
  • NoteMentions a .env fileSKILL.md:55
    in `ALLOWED_HOSTS` (comma-separated, in `.env`) → **421**, on every path, `/` included.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from receptron/mulmoterminal at commit b3f6ff0, republished under its MIT licence (© receptron). 901 words, ~1,507 tokens.

Download SKILL.mdSave it as .claude/skills/blueprint-local-security/SKILL.md (or your agent's skills folder).
name
blueprint-local-security
description
Review the finished app against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report.

Security review

The app is built and runs. Before it is handed over, review it the way an attacker would read it, fix what is exploitable, and leave a report the person can read. The check does not take your word for it: it starts the built server and sends it the requests an attack would send.

Method

  1. Context. Read .blueprint/spec.md (above all "必ず詰める点"), then all of server/, client/src/ and package.json. Note who may do what, where input enters, and what is stored.
  2. Audit, category by category (the list below). For each place input enters, trace it to where it is used.
  3. Fix every HIGH and MEDIUM finding, and add a test to test/security.test.ts that fails without the fix.
  4. Report in .blueprint/security-review.md (format below).

Severity: HIGH is directly exploitable (read or change someone's data, bypass sign-in, run code). MEDIUM needs a specific condition but the impact is real. LOW is defence in depth. Report a finding only when you can state how it is exploited and you are at least 70% sure; a guess is not a finding. Do not report denial of service, rate limits, memory or CPU exhaustion, or missing validation on a field that cannot cause harm.

What to look at in this app (OWASP Top 10:2025)

  • A01 Broken Access Control — every /api route enforces the spec's sign-in and roles on the server; with accounts, a row is read or changed only by whoever may (no id-guessing into another person's data). DNS rebinding: listening on 127.0.0.1 is not enough, because a web page can point its own name at 127.0.0.1 and then call this API as a same-origin page. Refuse any request whose Host is not on the allow-list.
  • A02 Security Misconfiguration — security headers on every response; x-powered-by off; no permissive CORS; the default host stays 127.0.0.1.
  • A03 Software Supply Chain Failures — yarn audit --groups dependencies has no high or critical; the lockfile is kept; no dependency the app does not use.
  • A04 Cryptographic Failures — passwords as salted scrypt, compared with timingSafeEqual; the session secret random and in .env, with .env listed in .gitignore (add it if it is not; the check fails on an .env that is not ignored); cookies HttpOnly and SameSite=Lax.
  • A05 Injection — SQL only with placeholders; no shell command, file path or eval built from input; the screen never renders input as HTML (v-html only on text the app itself wrote).
  • A06 Insecure Design — the spec's rules (limits, states, who may change what) are enforced on the server, not only on the screen; a body size limit on the JSON parser.
  • A07 Authentication Failures — a new session id at sign-in; sign-out ends the session on the server; no default or shared password in the code.
  • A08 Software or Data Integrity Failures — nothing from a request is deserialised into code or used to pick a module; an uploaded file is checked for type and size.
  • A09 Security Logging and Alerting Failures — sign-in failures and changes to data are logged, without passwords, cookies or secrets.
  • A10 Mishandling of Exceptional Conditions — every error reaches one handler that answers JSON without a stack trace or a parser's message; a failed check refuses rather than lets through.
Show full SKILL.md (368 more words)Show less

What the check sends, and must get back

Put these in front of everything, in server/ (one small module, applied in the function that builds the app):

  • A request whose Host name (port ignored) is not localhost, 127.0.0.1, [::1], the HOST setting, or one listed in ALLOWED_HOSTS (comma-separated, in .env) → 421, on every path, / included.
  • A POST, PUT, PATCH or DELETE under /api whose Origin (or, without one, Referer) is not this server's own origin → 403, before routing and before sign-in. A request with neither header is a script, not a page: let it through to sign-in.
  • Every response: Content-Security-Policy with frame-ancestors 'none' (start from default-src 'self'; object-src 'none'), X-Content-Type-Options: nosniff, Referrer-Policy. No X-Powered-By.
  • A malformed JSON body → 400 with a short message; no stack, no SyntaxError text.

test/security.test.ts proves each of these against the app built on a temporary database, plus one test per finding you fixed. Keep the existing tests passing: a test that talks to the app sends an allowed Host.

The report

.blueprint/security-review.md, in the spec's language. One section per category, its heading naming the id (## A01 … through ## A10 …), each with what you checked and every finding on a line of its own:

- HIGH fixed: <what was wrong, how it could be exploited> — <what changed, which test proves it>
- LOW accepted: <what, and why it is acceptable for this app>

The state is fixed, open or accepted. A HIGH or MEDIUM may not be open or accepted: fix it, or ask through the blueprint question tool if fixing it would change what the spec asks for. A category with nothing to report says what was checked and "指摘なし".

Done when the check passes: the report covers A01–A10 with nothing HIGH or MEDIUM left open, the tests pass, the audit is clean, and the running server refuses the rebound Host, the cross-origin change and the malformed body, and sends the headers.

Always

  • Read .blueprint/spec.md first. It is the agreed specification; do not widen it.
  • When you need a decision, ask it through the blueprint question tool and stop. Do not guess.
  • Do not run git init: a new repository loses the folder's trust and the next unattended step stops at Claude Code's trust prompt. The user adds git themselves after the build if they want it.
  • Say you are done by stopping; the executor runs the check. Do not claim success yourself.

© receptron, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in blueprints/local/skills/security of receptron/mulmoterminal.

Open the folder on GitHubat commit b3f6ff0

Compare with similar skills

Blueprint Local Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Blueprint Local Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Blueprint Local Security this skillreceptron/mulmoterminal237—~1.5kAutomated safety check: NotesMIT
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
Strix Code Vulnerability Scanusestrix/strix68k—~1.1kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone

Similar skills

  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    68k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

    68k GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed

More from receptron/mulmoterminal

All 31 skills in this repo
  • Mulmoterminal Bug Report

    receptron/mulmoterminal

    Help desk for "MulmoTerminal is broken". An agent skill from receptron/mulmoterminal.

    238 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Mulmoterminal Decisions

    receptron/mulmoterminal

    Check what this project's humans have already been asked, and how they answered, before asking them something similar.

    238 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Mulmoterminal Help

    receptron/mulmoterminal

    Help desk for questions about MulmoTerminal itself — what it can do, how a feature or a part of the screen works, how to set something up, what is new in this version or in the latest one.

    238 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Mulmoterminal Notify

    receptron/mulmoterminal

    Decide which moments MulmoTerminal beeps or pushes for, and what each one plays — soundKinds, sounds and pushKinds in ~/.mulmoterminal/config.json, plus a per-project sound / sounds in…

    238 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Mulmoterminal Theme

    receptron/mulmoterminal

    Build a colour scheme of your own for MulmoTerminal — one that joins Midnight, Nord, Daylight and Solarized in Settings' theme picker and can then be pinned per project.

    238 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Blueprint Ask Answer

    receptron/mulmoterminal

    Answer each question from the named documents only, quoting where the answer is written, or saying plainly that the documents do not say — changing nothing yet.

    238 GitHub stars~780 tokensUpdated today
    Auto-check passed

Categories

Questions about Blueprint Local Security

What does Blueprint Local Security do?

Review the finished app against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report. Blueprint Local Security is an agent skill from receptron/mulmoterminal. Review the finished app against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report.

When should I use Blueprint Local Security?

Blueprint Local Security fits situations like: tasks that involve Web application vulnerabilities.

How do I install Blueprint Local Security in Claude Code?

Run `npx skills add receptron/mulmoterminal --skill blueprint-local-security -a claude-code`. Or copy the skill folder (blueprints/local/skills/security in receptron/mulmoterminal) into .claude/skills/blueprint-local-security in your project. Claude Code loads it when a task matches its description.

How do I install Blueprint Local Security in Codex?

Run `npx skills add receptron/mulmoterminal --skill blueprint-local-security -a codex`. Or copy the skill folder (blueprints/local/skills/security in receptron/mulmoterminal) into .agents/skills/blueprint-local-security in your project. Codex loads it when a task matches its description.

Can I use Blueprint Local Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add receptron/mulmoterminal --skill blueprint-local-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/blueprint-local-security, .gemini/skills/blueprint-local-security, .github/skills/blueprint-local-security and .opencode/skills/blueprint-local-security in your project.

What does Blueprint Local Security need to run?

Going by SKILL.md and its folder, Blueprint Local Security needs the command-line tools its instructions call (yarn and git).

Does Blueprint Local Security access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Blueprint Local Security safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Blueprint Local Security use?

Blueprint Local Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Blueprint Local Security use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Blueprint Local Security?

Skills that share tags, products or a category with Blueprint Local Security: Security And Hardening (penpot/penpot, 61k stars), Security Auditor (eigent-ai/eigent, 15k stars), Security Review (jewbetcha/opentrace, 116 stars) and Strix Code Vulnerability Scan (usestrix/strix, 68k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Blueprint Local Security?

receptron (a GitHub organization) maintains it in receptron/mulmoterminal, which has 237 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 10, 2026.

Source: receptron/mulmoterminal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.