Agent skill

Security Pipeline

by sangrokjung in sangrokjung/claude-forge

A skill your agent uses when security verification is needed - pre-commit security checks, vulnerability scanning, STRIDE threat analysis.

MITAuto-check: notesSecurity

Install Security Pipeline

skills CLI
$ npx skills add sangrokjung/claude-forge --skill security-pipeline -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sangrokjung/claude-forge security-pipeline --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sangrokjung/claude-forge.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-pipeline .claude/skills/security-pipeline && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-pipeline
GitHub stars
852
Token cost
~1k tokens
SKILL.md length
411 words
Files
1
Skills in repo
24
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when security verification is needed - pre-commit security checks, vulnerability scanning, STRIDE threat analysis.

  • Security verification is needed - pre-commit security checks
  • SKILL.md covers Overview, Trigger Conditions, CWE Scanning Rules and Auto-Fix Rules, plus 2 more sections
  • Needs API_KEY
  • Vulnerability scanning

What it does

Security Pipeline is an agent skill from sangrokjung/claude-forge. Use when security verification is needed - pre-commit security checks, vulnerability scanning, STRIDE threat analysis. Integrates with /handoff-verify --security and /commit-push-pr. CWE Top 25 based.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Threat modeling, Vulnerability scanning and Web application vulnerabilities. The repository describes itself as: oh-my-zsh for Claude Code — 16 agents, 35 commands, 32 skills, 21 safety hooks in one install. v4.0 adds an adversarial review loop: a second agent that never sees the first… The licence is MIT.

When your agent uses it

  • Security verification is needed - pre-commit security checks
  • Vulnerability scanning
  • STRIDE threat analysis

Example prompts

  • “/security-pipeline”

Requirements

  • A credential in API_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 34d881d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Pipeline loads about 1k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 411 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:34
    | `**/.env*` | Credential Scan | 환경변수 파일 |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sangrokjung/claude-forge at commit 34d881d, republished under its MIT licence (© sangrokjung). 411 words, ~1,011 tokens.

Download SKILL.mdSave it as .claude/skills/security-pipeline/SKILL.md (or your agent's skills folder).
name
security-pipeline
description
Use when security verification is needed - pre-commit security checks, vulnerability scanning, STRIDE threat analysis. Integrates with /handoff-verify --security and /commit-push-pr. CWE Top 25 based.
version
2.0.0

Overview

보안 파이프라인 스킬은 코드 변경 시 자동으로 CWE Top 25 기반 보안 검증을 수행한다. /handoff-verify --security, /commit-push-pr 실행 시 통합 동작한다. 보안 체크리스트 참조: ~/.claude/skills/_reference/security-checklist.md

effort:max가 항상 강제 적용된다. 보안 검증은 축약하지 않는다.


Trigger Conditions

파일 패턴 기반 자동 트리거

다음 패턴을 포함하는 파일이 변경되면 보안 파이프라인이 자동으로 실행된다:

패턴트리거 수준설명
**/auth/**Full Scan인증 관련 모듈
**/payment/**Full Scan결제 처리 모듈
**/api/**CWE ScanAPI 엔드포인트
**/middleware/**CWE Scan미들웨어
**/session*CWE Scan세션 관리
**/token*CWE Scan토큰 처리
**/crypto*CWE Scan암호화 로직
**/admin/**Full + STRIDE관리자 기능
**/upload*CWE Scan파일 업로드
**/.env*Credential Scan환경변수 파일
**/config/secret*Credential Scan시크릿 설정
커밋 기반 자동 트리거

/commit-push-pr 실행 시 staged 파일 목록에서 위 패턴이 감지되면, 커밋 전 보안 파이프라인이 자동으로 실행된다.


CWE Scanning Rules

Critical (커밋 차단)
CWE IDRuleGrep Pattern
CWE-89SQL Injectionquery\(.*\$\{, query\(.*\+
CWE-79XSSinnerHTML, dangerouslySetInnerHTML, v-html
CWE-78OS Command Injectionexec\(.*\$\{, spawn\(.*req\.
CWE-77Command InjectionTemplate string in shell command
CWE-798Hardcoded CredentialsapiKey\s*=\s*['"], secret\s*=\s*['"]
High (경고, 커밋 허용)
CWE IDRuleGrep Pattern
CWE-22Path Traversal\.\.\/ with user input
CWE-352CSRFPOST handler without csrf check
CWE-287Improper AuthRoute without auth middleware
CWE-862Missing AuthzHandler without role/permission check
CWE-502Unsafe Deserializationeval\(, new Function\(
CWE-918SSRFfetch\(.*req\., axios.*req\.
CWE-434Unrestricted UploadUpload without validation
CWE-269Privilege EscalationRole change without verification
Medium (정보 제공)
CWE IDRuleGrep Pattern
CWE-200Info Disclosureconsole\.log.*password|token|secret
CWE-20Input ValidationEndpoint without schema validation
CWE-327Broken Cryptomd5\(, sha1\(, Math\.random\(\)
CWE-276Incorrect Permsorigin:\s*['"]?\*, 0o?777

Show full SKILL.md (153 more words)Show less

Auto-Fix Rules

자동 수정은 사용자 승인 후 적용한다. 신뢰도가 High인 항목만 자동 수정 대상이다.

Parameterized Queries (CWE-89)
Before: db.query(`SELECT * FROM users WHERE id = '${id}'`)
After:  db.query('SELECT * FROM users WHERE id = $1', [id])
Environment Variables (CWE-798)
Before: const apiKey = 'sk-proj-abc123'
After:  const apiKey = process.env.API_KEY
+ .env.example에 API_KEY= 추가
Safe DOM Manipulation (CWE-79)
Before: element.innerHTML = userInput
After:  element.textContent = userInput
Remove Sensitive Logs (CWE-200)
Before: console.log('Token:', token)
After:  // (line removed)
Secure Hash (CWE-327)
Before: const hash = md5(data)
After:  const hash = crypto.createHash('sha256').update(data).digest('hex')

Integration Points

/handoff-verify (v6)

/handoff-verify 커맨드의 검증 단계에서 보안 검사가 포함된다. verify-agent가 민감 파일 변경을 감지하면 이 스킬을 자동 호출한다.

/commit-push-pr

커밋 전 자동 보안 게이트로 동작한다:

  • Critical 발견 시: 커밋 차단 (BLOCKED)
  • High 발견 시: 경고 표시 후 사용자 확인 (WARN)
  • Medium 이하만 존재: 통과 (PASS)
/security-review (통합됨)

이전 security-review 스킬의 OWASP 체크리스트는 _reference/security-checklist.md로 전환. 전체 보안 리뷰 시 이 스킬의 CWE Top 25 매핑 + STRIDE + 의존성 검사가 수행되며, 체크리스트 참조 파일을 함께 로드한다.


effort:max Enforcement

이 스킬은 항상 effort:max로 실행된다. 보안 검증에서 분석 깊이를 줄이는 것은 허용하지 않는다.

적용 범위:

  • CWE 패턴 매칭 시 false positive 최소화를 위한 컨텍스트 분석
  • STRIDE 분류 시 전체 데이터 흐름 추적
  • 자동 수정 제안 시 사이드 이펙트 검증
  • 의존성 검사 시 transitive dependency 포함

© sangrokjung, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security-pipeline of sangrokjung/claude-forge.

Open the folder on GitHubat commit 34d881d

Compare with similar skills

Security Pipeline next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Pipeline compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Pipeline this skillsangrokjung/claude-forge852—~1kAutomated safety check: NotesMIT
Security Audit Scannerruvnet/ruflo74k1 repos~823Automated safety check: PassMIT
Vulnerability ScannerxenitV1/Antigravity-Workflows1307 repos~1.8kAutomated safety check: NotesMIT
Golang Securityunxed/f42432 repos~3.6kAutomated safety check: PassMIT
Security Auditoraiskillstore/marketplace4336 repos~2.6kAutomated safety check: PassNone
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0

Similar skills

  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 1 repo~823 tokens
    SecurityAuto-check passed
  • Vulnerability Scanner

    xenitV1/Antigravity-Workflows

    Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows.

    130 GitHub starsUsed in 7 repos~1.8k tokens
    SecurityAuto-check: notes
  • Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

    243 GitHub starsUsed in 2 repos~3.6k tokens
    SecurityAuto-check passed
  • Security Auditor

    aiskillstore/marketplace

    Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.

    433 GitHub starsUsed in 6 repos~2.6k tokens
    SecurityAuto-check passed
  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes

More from sangrokjung/claude-forge

All 24 skills in this repo
  • Debugging Strategies

    sangrokjung/claude-forge

    Master systematic debugging techniques, profiling tools, and root cause analysis to efficiently track down bugs across any codebase or technology stack.

    852 GitHub starsUsed in 13 repos~3.1k tokens
    Auto-check passed
  • Dependency Upgrade

    sangrokjung/claude-forge

    Manage major dependency version upgrades with compatibility analysis, staged rollout, and comprehensive testing.

    852 GitHub starsUsed in 12 repos~2.3k tokens
    Auto-check passed
  • Skill Factory

    sangrokjung/claude-forge

    Analyze session work and automatically convert reusable patterns into Claude Code skills.

    852 GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Cc Dev Agent

    sangrokjung/claude-forge

    A skill your agent uses when starting Claude Code projects, writing CLAUDE.md/spec.md, dispatching subagents, or requesting Agent Teams parallel development.

    852 GitHub stars~771 tokensUpdated 1 mo ago
    Auto-check passed
  • Continuous Learning V2

    sangrokjung/claude-forge

    Instinct-based learning system that observes sessions via hooks, creates atomic instincts with confidence scoring, and evolves them into skills/commands/agents.

    852 GitHub starsUsed in 5 repos~1.8k tokens
    Auto-check passed
  • Harness Diet

    sangrokjung/claude-forge

    Measure and shrink the always-loaded context of a Claude Code harness (CLAUDE.md + rules without paths frontmatter) back under budget — migrate narrative to reference files, convert rules to…

    852 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Security Pipeline

What does Security Pipeline do?

A skill your agent uses when security verification is needed - pre-commit security checks, vulnerability scanning, STRIDE threat analysis. Security Pipeline is an agent skill from sangrokjung/claude-forge. Use when security verification is needed - pre-commit security checks, vulnerability scanning, STRIDE threat analysis.

When should I use Security Pipeline?

Security Pipeline fits situations like: security verification is needed - pre-commit security checks; vulnerability scanning; STRIDE threat analysis.

How do I install Security Pipeline in Claude Code?

Run `npx skills add sangrokjung/claude-forge --skill security-pipeline -a claude-code`. Or copy the skill folder (skills/security-pipeline in sangrokjung/claude-forge) into .claude/skills/security-pipeline in your project. Claude Code loads it when a task matches its description.

How do I install Security Pipeline in Codex?

Run `npx skills add sangrokjung/claude-forge --skill security-pipeline -a codex`. Or copy the skill folder (skills/security-pipeline in sangrokjung/claude-forge) into .agents/skills/security-pipeline in your project. Codex loads it when a task matches its description.

Can I use Security Pipeline in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sangrokjung/claude-forge --skill security-pipeline -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-pipeline, .gemini/skills/security-pipeline, .github/skills/security-pipeline and .opencode/skills/security-pipeline in your project.

What does Security Pipeline need to run?

Going by SKILL.md and its folder, Security Pipeline needs credentials named API_KEY. Our summary lists: A credential in API_KEY.

Does Security Pipeline access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Pipeline safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Pipeline use?

Security Pipeline is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Pipeline use?

About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Pipeline?

Skills that share tags, products or a category with Security Pipeline: Security Audit Scanner (ruvnet/ruflo, 74k stars), Vulnerability Scanner (xenitV1/Antigravity-Workflows, 130 stars), Golang Security (unxed/f4, 243 stars) and Security Auditor (aiskillstore/marketplace, 433 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Pipeline?

sangrokjung (a GitHub user) maintains it in sangrokjung/claude-forge, which has 852 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on September 3, 2026.

Source: sangrokjung/claude-forge on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.