Agent skill

Pipeline Security Gates

by revfactory in revfactory/harness-100

CI/CD pipeline security gate design guide. An agent skill from revfactory/harness-100.

Apache-2.0Auto-check passedSecurity

Install Pipeline Security Gates

skills CLI
$ npx skills add revfactory/harness-100 --skill pipeline-security-gates -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install revfactory/harness-100 pipeline-security-gates --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/revfactory/harness-100.git skills-src && mkdir -p .claude/skills && cp -r skills-src/en/20-cicd-pipeline/.claude/skills/pipeline-security-gates .claude/skills/pipeline-security-gates && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pipeline-security-gates
GitHub stars
1.3k
Token cost
~1.5k tokens
SKILL.md length
416 words
Files
1
Skills in repo
464
Repo updated
First seen
Licence
Apache-2.0

At a glance

CI/CD pipeline security gate design guide. An agent skill from revfactory/harness-100.

  • Integrating pipeline security involving security gates
  • SKILL.md covers Target Agent, Security Scan Types & Tool…, Gate Placement Strategy and Vulnerability Severity…, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Container scanning

What it does

Pipeline Security Gates is an agent skill from revfactory/harness-100. CI/CD pipeline security gate design guide. An extension skill for security-scanner that provides scan tool selection for SAST/DAST/SCA/container scanning/secret detection, gate placement strategies, threshold configuration, and vulnerability classification criteria. Use when integrating pipeline security involving 'security gates', 'SAST', 'DAST', 'SCA', 'container scanning', 'secret detection', 'vulnerability thresholds', etc. Note: actual scan execution and vulnerability remediation are outside the scope of…

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Static analysis and SAST, CI/CD and Vulnerability scanning. It works with Trivy and GitHub. The licence is Apache-2.0.

When your agent uses it

  • Integrating pipeline security involving security gates
  • Container scanning
  • Secret detection
  • Vulnerability thresholds

Example prompts

  • “security gates”
  • “container scanning”
  • “secret detection”
  • “/pipeline-security-gates”

Requirements

  • Python 3
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 8e8d35c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pipeline Security Gates loads about 1.5k tokens when it runs. Until then it costs about 138 tokens; SKILL.md has 416 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~138
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from revfactory/harness-100 at commit 8e8d35c, republished under its Apache-2.0 licence (© revfactory). 416 words, ~1,502 tokens.

Download SKILL.mdSave it as .claude/skills/pipeline-security-gates/SKILL.md (or your agent's skills folder).
name
pipeline-security-gates
description
CI/CD pipeline security gate design guide. An extension skill for security-scanner that provides scan tool selection for SAST/DAST/SCA/container scanning/secret detection, gate placement strategies, threshold configuration, and vulnerability classification criteria. Use when integrating pipeline security involving 'security gates', 'SAST', 'DAST', 'SCA', 'container scanning', 'secret detection', 'vulnerability thresholds', etc. Note: actual scan execution and vulnerability remediation are outside the scope of this skill.

Pipeline Security Gates — CI/CD Security Gate Design Guide

A reference of scan tool selection, gate placement, and threshold configuration used by the security-scanner agent when designing pipeline security.

Target Agent

security-scanner — Directly applies the security gate patterns and tool selection from this skill to pipeline security design.

Security Scan Types & Tool Matrix

Scan Type Overview
TypeFull NameTargetTimingCost
SASTStatic Application Security TestingSource codeCommit/PRLow
SCASoftware Composition AnalysisDependencies/librariesPre-buildLow
SecretSecret DetectionSensitive data in codeCommit/PRLow
ContainerContainer Image ScanningDocker imagesPost-buildMedium
DASTDynamic Application Security TestingRunning applicationStagingHigh
IaCInfrastructure as Code ScanningTerraform/K8sPRLow
LicenseLicense ComplianceOpen source licensesBuildLow
Tool Selection Guide
SAST (Static Analysis)
ToolLanguage SupportOpen SourceFeatures
Semgrep20+ languagesYesEasy custom rules, fast
CodeQL10+ languagesYes (GitHub)GitHub native, deep analysis
SonarQube25+ languagesPartialQuality + security integration
BanditPython onlyYesPython-specific
ESLint SecurityJS/TS onlyYesESLint plugin
SCA (Dependency Analysis)
ToolFeatures
DependabotGitHub native, automatic PRs
SnykLargest DB, automatic fix suggestions
OWASP Dependency-CheckOWASP official, open source
TrivyContainer + SCA integration
npm audit / pip-auditLanguage native
Secret Detection
ToolFeatures
GitleaksFull Git history scan, fast
TruffleHogEntropy + pattern based
detect-secretsDeveloped by Yelp, pre-commit hook
GitHub Secret ScanningGitHub native, partner patterns
Container Scanning
ToolFeatures
TrivyMost comprehensive, OS + app packages
GrypeAnchore open source, fast
Docker ScoutDocker official
Snyk ContainerIncludes fix guidance
Show full SKILL.md (167 more words)Show less
IaC Scanning
ToolTarget
tfsecTerraform
CheckovTerraform, K8s, CloudFormation
KICSMulti-IaC support
kubescapeKubernetes only

Gate Placement Strategy

Security Gates by Pipeline Stage
[1. Pre-Commit]
  ├── Secret Detection (Gitleaks pre-commit)
  └── Lint Security Rules

[2. PR/Commit]
  ├── SAST (Semgrep/CodeQL)
  ├── SCA (Dependabot/Snyk)
  ├── Secret Detection (full scan)
  ├── License Check
  └── IaC Scan (if applicable)

[3. Build]
  ├── Container Image Scan (Trivy)
  └── SBOM Generation (Software Bill of Materials)

[4. Staging]
  ├── DAST (optional)
  └── Integration Security Tests

[5. Production Deployment]
  └── Final Approval Gate (security report review)
Gate Block/Warn Policy
Scan TypeCriticalHighMediumLow
SASTBlockBlockWarnIgnore
SCA (CVE)BlockBlockWarnIgnore
SecretBlockBlockBlockWarn
ContainerBlockWarnIgnoreIgnore
IaCBlockWarnIgnoreIgnore
LicenseBlock (GPL)WarnIgnoreIgnore

Vulnerability Severity Classification

CVSS v3.1 Based
RatingCVSS ScoreSLA (Fix Deadline)Gate Action
Critical9.0-10.0Within 24 hoursBlock deployment
High7.0-8.9Within 7 daysBlock deployment
Medium4.0-6.9Within 30 daysWarn, allow deployment
Low0.1-3.9Within 90 daysInformational
Exception Handling (Suppression)
yaml
# .trivyignore or .semgrepignore example
# Reason and expiry date required

CVE-2024-12345  # No impact (unused feature). Expires: 2025-06-30
RULE-001        # False positive. Reviewer: @security-team

GitHub Actions Security Gate YAML Patterns

Semgrep (SAST)
yaml
semgrep:
  runs-on: ubuntu-latest
  steps:
    - uses: actions/checkout@v4
    - uses: returntocorp/semgrep-action@v1
      with:
        config: >-
          p/owasp-top-ten
          p/r2c-security-audit
Trivy (Container + SCA)
yaml
trivy:
  runs-on: ubuntu-latest
  steps:
    - uses: aquasecurity/trivy-action@master
      with:
        scan-type: 'image'
        image-ref: '${{ env.IMAGE }}'
        severity: 'CRITICAL,HIGH'
        exit-code: '1'
Gitleaks (Secret)
yaml
gitleaks:
  runs-on: ubuntu-latest
  steps:
    - uses: actions/checkout@v4
      with:
        fetch-depth: 0
    - uses: gitleaks/gitleaks-action@v2

SBOM (Software Bill of Materials)

SBOM Generation Tools
ToolFormatFeatures
SyftSPDX, CycloneDXAnchore, most comprehensive
TrivySPDX, CycloneDXIntegrated with scanning
docker sbomSPDXDocker official
SBOM Required Information
  • Package name, version, license
  • Dependency tree (direct/transitive)
  • Hash values (integrity verification)
  • Supplier information

© revfactory, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in en/20-cicd-pipeline/.claude/skills/pipeline-security-gates of revfactory/harness-100.

Open the folder on GitHubat commit 8e8d35c

Compare with similar skills

Pipeline Security Gates next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pipeline Security Gates compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pipeline Security Gates this skillrevfactory/harness-1001.3k—~1.5kAutomated safety check: PassApache-2.0
Security Vulnerabilities Patcheraxelixlabs/axelix148—~4.2kAutomated safety check: PassLGPL-3.0
Agentic GitHub Actions Auditortrailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0
Openclaw CI Limitsopenclaw/openclaw392k—~14kAutomated safety check: PassMIT
Building Devsecops Pipeline With GitLab CImukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence

Similar skills

  • Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…

    148 GitHub stars~4.2k tokensUpdated today
    SecurityAuto-check passed
  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.4k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • Openclaw CI Limits

    openclaw/openclaw

    Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe…

    392k GitHub stars~14k tokensUpdated today
    SecurityAuto-check passed
  • Building Devsecops Pipeline With GitLab CI

    mukul975/Anthropic-Cybersecurity-Skills

    Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • DefectDojo Vulnerability Management

    AgentSecOps/SecOpsAgentKit

    Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

    220 GitHub stars~2.3k tokensUpdated 5 mo ago
    SecurityAuto-check passed

More from revfactory/harness-100

All 464 skills in this repo
  • Anti Bot Analyzer

    revfactory/harness-100

    A skill for analyzing website anti-bot defense mechanisms and developing legitimate evasion strategies.

    1.3k GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • API Error Design Patterns

    revfactory/harness-100

    Reference for designing how an API reports failures: structured error codes, response shapes, client-friendly messages, an error catalog and retry or fallback advice.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Arg Parser Generator

    revfactory/harness-100

    Methodology for systematically designing and generating CLI tool argument parser structures.

    1.3k GitHub stars~1.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Audience Segmentation

    revfactory/harness-100

    Audience segmentation skill used by the analyst and curator agents.

    1.3k GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Audio Storytelling

    revfactory/harness-100

    Audio storytelling skill used by the podcast scriptwriter and show note editor.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed

Works with

Questions about Pipeline Security Gates

What does Pipeline Security Gates do?

CI/CD pipeline security gate design guide. An agent skill from revfactory/harness-100. Pipeline Security Gates is an agent skill from revfactory/harness-100. CI/CD pipeline security gate design guide.

When should I use Pipeline Security Gates?

Pipeline Security Gates fits situations like: integrating pipeline security involving security gates; container scanning; secret detection; vulnerability thresholds.

How do I install Pipeline Security Gates in Claude Code?

Run `npx skills add revfactory/harness-100 --skill pipeline-security-gates -a claude-code`. Or copy the skill folder (en/20-cicd-pipeline/.claude/skills/pipeline-security-gates in revfactory/harness-100) into .claude/skills/pipeline-security-gates in your project. Claude Code loads it when a task matches its description.

How do I install Pipeline Security Gates in Codex?

Run `npx skills add revfactory/harness-100 --skill pipeline-security-gates -a codex`. Or copy the skill folder (en/20-cicd-pipeline/.claude/skills/pipeline-security-gates in revfactory/harness-100) into .agents/skills/pipeline-security-gates in your project. Codex loads it when a task matches its description.

Can I use Pipeline Security Gates in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add revfactory/harness-100 --skill pipeline-security-gates -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pipeline-security-gates, .gemini/skills/pipeline-security-gates, .github/skills/pipeline-security-gates and .opencode/skills/pipeline-security-gates in your project.

What does Pipeline Security Gates need to run?

SKILL.md names no scripts, command-line tools or credentials: Pipeline Security Gates is instructions for the agent only. Our summary lists: Python 3; Docker.

Does Pipeline Security Gates access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Pipeline Security Gates safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pipeline Security Gates use?

Pipeline Security Gates is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pipeline Security Gates use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pipeline Security Gates?

Skills that share tags, products or a category with Pipeline Security Gates: Security Vulnerabilities Patcher (axelixlabs/axelix, 148 stars), Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars), Openclaw CI Limits (openclaw/openclaw, 392k stars) and Building Devsecops Pipeline With GitLab CI (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pipeline Security Gates?

revfactory (a GitHub user) maintains it in revfactory/harness-100, which has 1,295 GitHub stars. The repository holds 464 skills in this directory. The repository was last updated on March 22, 2026.

Source: revfactory/harness-100 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.