Agent skill

Security Assessment

by rsmdt in rsmdt/the-startup

Vulnerability review, threat modeling, OWASP patterns, and secure coding assessment.

MITAuto-check passedSecurity

Install Security Assessment

skills CLI
$ npx skills add rsmdt/the-startup --skill security-assessment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rsmdt/the-startup security-assessment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rsmdt/the-startup.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/team/skills/quality/security-assessment .claude/skills/security-assessment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-assessment
GitHub stars
551
Token cost
~1.3k tokens
SKILL.md length
533 words
Files
4
Skills in repo
27
Repo updated
First seen
Licence
MIT

At a glance

Vulnerability review, threat modeling, OWASP patterns, and secure coding assessment.

  • Works in 5 steps: Gather Context → Model Threats → Review Code → …
  • Reviewing code security
  • SKILL.md covers Persona, Interface, Constraints and Reference Materials, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Assessment is an agent skill from rsmdt/the-startup. Vulnerability review, threat modeling, OWASP patterns, and secure coding assessment. Use when reviewing code security, designing secure systems, performing threat analysis, or validating security implementations.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `checklists/security-review-checklist.md`, `reference/owasp-patterns.md` and `reference/secure-coding.md`).

It sits in Security, covering Security review, Threat modeling and Web application vulnerabilities. The repository describes itself as: The Agentic Startup - A collection of Claude Code commands, skills, and agents. The licence is MIT.

When your agent uses it

  • Reviewing code security
  • Designing secure systems
  • Performing threat analysis
  • Validating security implementations

Example prompts

  • “/security-assessment”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Gather Context
  2. Model Threats
  3. Review Code
  4. Assess Infrastructure
  5. Report Findings

What it can do on your machine

Read from SKILL.md and the folder at commit 88d447c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Assessment loads about 1.3k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 533 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rsmdt/the-startup at commit 88d447c, republished under its MIT licence (© rsmdt). 533 words, ~1,251 tokens.

Download SKILL.mdSave it as .claude/skills/security-assessment/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
security-assessment
description
Vulnerability review, threat modeling, OWASP patterns, and secure coding assessment. Use when reviewing code security, designing secure systems, performing threat analysis, or validating security implementations.

Persona

Act as a security engineer who systematically evaluates code, architecture, and infrastructure for vulnerabilities using threat modeling frameworks and practical code review techniques to identify and recommend remediations.

Assessment Target: $ARGUMENTS

Interface

SecurityFinding { severity: CRITICAL | HIGH | MEDIUM | LOW | INFORMATIONAL category: string // STRIDE category or OWASP ID title: string location: string vulnerability: string impact: string remediation: string code_example?: string }

STRIDEThreat { category: Spoofing | Tampering | Repudiation | InformationDisclosure | DenialOfService | ElevationOfPrivilege threat: string questions: string[] mitigations: string[] }

State { target = $ARGUMENTS architecture = {} threats: STRIDEThreat[] findings: SecurityFinding[] focusAreas = [ "Authentication and session management", "Authorization checks", "Input handling", "Data exposure", "Cryptography usage", "Third-party integrations", "Error handling" ] }

Constraints

Always:

  • Apply STRIDE threat modeling to architecture before code-level review.
  • Every finding must include specific remediation steps.
  • Prioritize by risk: likelihood x impact.
  • Check all seven code review focus areas for every assessment.
  • Reference OWASP patterns for web application security.

Never:

  • Skip threat modeling and jump straight to code review.
  • Report vulnerabilities without remediation guidance.
  • Expose sensitive details (real credentials, internal paths) in findings.
  • Assume security controls work without verification.

Reference Materials

  • reference/owasp-patterns.md — A01-A10 review patterns with red flags for each category
  • reference/secure-coding.md — Input validation, output encoding, secrets management, error handling, infrastructure security
  • checklists/security-review-checklist.md — Comprehensive checklist covering threat modeling, auth, input validation, crypto, logging, API, infrastructure, dependencies, CI/CD

Workflow

1. Gather Context

Understand the system: architecture, data flows, trust boundaries, entry points. Identify sensitive data types (credentials, PII, financial). Map third-party integrations and their trust levels.

2. Model Threats

Apply STRIDE to each component and data flow:

Spoofing (Authentication) Can identities be faked? Token theft/forgery? Auth bypass paths? Mitigate with: MFA, secure token generation, session invalidation.

Tampering (Integrity) Can data be modified in transit or at rest? Config alteration? Mitigate with: input validation, cryptographic signatures, audit logs.

Repudiation (Non-repudiation) Can actions be denied? Are audit logs tamper-resistant? Mitigate with: comprehensive logging, immutable log storage, digital signatures.

Information Disclosure (Confidentiality) What sensitive data exists? Protected at rest and in transit? Error messages leaking? Mitigate with: encryption (TLS, AES), access controls, sanitized errors.

Denial of Service (Availability) What resources can be exhausted? Rate limits on expensive ops? Mitigate with: rate limiting, input size limits, resource quotas, timeouts.

Elevation of Privilege (Authorization) Can users access beyond their role? Consistent privilege checks? Mitigate with: least privilege, RBAC, authorization at every layer.

Show full SKILL.md (157 more words)Show less
3. Review Code

Read reference/owasp-patterns.md for systematic OWASP Top 10 review. Read reference/secure-coding.md for secure coding pattern verification.

For each focus area, trace data flow from entry to storage/output:

  1. Authentication and session management — token lifecycle, validation.
  2. Authorization checks — access control at all layers.
  3. Input handling — all user input paths, injection prevention.
  4. Data exposure — logs, errors, API responses.
  5. Cryptography usage — algorithm selection, key management.
  6. Third-party integrations — data sharing, auth mechanisms.
  7. Error handling — information leakage, fail-secure behavior.
4. Assess Infrastructure

Review infrastructure security per reference/secure-coding.md: Network segmentation, container security, secrets management, cloud IAM.

Read checklists/security-review-checklist.md for comprehensive validation.

5. Report Findings

Structure output:

  1. Summary — assessment scope, methodology applied.
  2. Threat model — STRIDE analysis results per component.
  3. Findings table — sorted by severity with OWASP/STRIDE category.
  4. Detailed findings — vulnerability, impact, remediation for each.
  5. Best practices — defense in depth, assume breach, automate security testing.
  6. Recommended next steps — prioritized remediation plan.

© rsmdt, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in plugins/team/skills/quality/security-assessment of rsmdt/the-startup.

  • SKILL.md
  • checklists/security-review-checklist.md
  • reference/owasp-patterns.md
  • reference/secure-coding.md

Open the folder on GitHubat commit 88d447c

Compare with similar skills

Security Assessment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Assessment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Assessment this skillrsmdt/the-startup551—~1.3kAutomated safety check: PassMIT
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Security And Hardeningdzhalaevd/Donatello135—~5.1kAutomated safety check: NotesApache-2.0
Security Scanericrisco/rsc-harness167—~2.8kAutomated safety check: NotesMIT
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
Security and Hardeningaddyosmani/agent-skills103k1 repos~4.4kAutomated safety check: NotesMIT

Similar skills

  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Security And Hardening

    dzhalaevd/Donatello

    Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.

    135 GitHub stars~5.1k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Security Scan

    ericrisco/rsc-harness

    A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

    167 GitHub stars~2.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Security and Hardening

    addyosmani/agent-skills

    Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

    103k GitHub starsUsed in 1 repo~4.4k tokens
    SecurityAuto-check: notes
  • Cybersecurity

    AgriciDaniel/claude-cybersecurity

    Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.

    227 GitHub stars~11k tokensUpdated 5 mo ago
    SecurityAuto-check: warnings

More from rsmdt/the-startup

All 27 skills in this repo
  • Analyze

    rsmdt/the-startup

    Deep-dive codebase analysis that explains how things actually work — business rules, architecture patterns, auth flows, data models, integrations, and performance hotspots.

    551 GitHub stars~1.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Implement

    rsmdt/the-startup

    Implementation entry point. An agent skill from rsmdt/the-startup.

    551 GitHub stars~1.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Implement Factory

    rsmdt/the-startup

    Factory loop orchestrator for multi-feature or multi-component implementation manifests.

    551 GitHub stars~3.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Agentic Patterns

    rsmdt/the-startup

    Context enrichment for agentic AI application development using LangChain, Vercel AI SDK, and assistant-ui.

    551 GitHub stars~501 tokensUpdated 2 mo ago
    Auto-check passed
  • API Contract Design

    rsmdt/the-startup

    REST and GraphQL API design patterns, OpenAPI/Swagger specifications, versioning strategies, and authentication patterns.

    551 GitHub stars~1.1k tokensUpdated 2 mo ago
    Auto-check passed
  • Architecture Selection

    rsmdt/the-startup

    System architecture patterns including monolith, microservices, event-driven, and serverless, with C4 modeling, scalability strategies, and technology selection criteria.

    551 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Security Assessment

What does Security Assessment do?

Vulnerability review, threat modeling, OWASP patterns, and secure coding assessment. Security Assessment is an agent skill from rsmdt/the-startup. Vulnerability review, threat modeling, OWASP patterns, and secure coding assessment.

When should I use Security Assessment?

Security Assessment fits situations like: reviewing code security; designing secure systems; performing threat analysis; validating security implementations.

How do I install Security Assessment in Claude Code?

Run `npx skills add rsmdt/the-startup --skill security-assessment -a claude-code`. Or copy the skill folder (plugins/team/skills/quality/security-assessment in rsmdt/the-startup) into .claude/skills/security-assessment in your project. Claude Code loads it when a task matches its description.

How do I install Security Assessment in Codex?

Run `npx skills add rsmdt/the-startup --skill security-assessment -a codex`. Or copy the skill folder (plugins/team/skills/quality/security-assessment in rsmdt/the-startup) into .agents/skills/security-assessment in your project. Codex loads it when a task matches its description.

Can I use Security Assessment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rsmdt/the-startup --skill security-assessment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-assessment, .gemini/skills/security-assessment, .github/skills/security-assessment and .opencode/skills/security-assessment in your project.

What does Security Assessment need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Assessment is instructions for the agent only.

Does Security Assessment access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Assessment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Assessment use?

Security Assessment is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Assessment use?

About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Assessment?

Skills that share tags, products or a category with Security Assessment: Security Audit Scanner (ruvnet/ruflo, 74k stars), Security And Hardening (dzhalaevd/Donatello, 135 stars), Security Scan (ericrisco/rsc-harness, 167 stars) and Security And Hardening (penpot/penpot, 61k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Assessment?

rsmdt (a GitHub user) maintains it in rsmdt/the-startup, which has 551 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on August 3, 2026.

Source: rsmdt/the-startup on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.