Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

MITAuto-check passedSecurity

Install 007

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill 007 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills 007 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/007 .claude/skills/007 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
007
GitHub stars
47k
Used in
2 other repos
Token cost
~410 tokens
SKILL.md length
174 words
Files
16 (incl. scripts, references)
Skills in repo
1,354
Repo updated
First seen
Licence
MIT

At a glance

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

  • Tasks that involve Threat modeling
  • SKILL.md covers Detailed Guide, When to Use This Skill, Do Not Use This Skill When and Limitations
  • Runs Python scripts from its folder
  • Tasks that involve Security review

What it does

007 is an agent skill from sickn33/agentic-awesome-skills. Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

Its SKILL.md is about 410 tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files, including scripts and reference files (for example `references/ai-agent-security.md`, `references/api-security-patterns.md` and `references/detailed-guide.md`).

It sits in Security, covering Threat modeling, Security review and Web application vulnerabilities. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve Threat modeling
  • Tasks that involve Security review
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/007”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit ec02547. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 9 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

007 loads about 410 tokens when it runs, and up to ~23k if it reads all its reference files. Until then it costs about 42 tokens; SKILL.md has 174 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~410
With references · SKILL.md plus every file in references/, read only if the agent opens them
~23k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit ec02547, republished under its MIT licence (© sickn33). 174 words, ~410 tokens.

Download SKILL.mdSave it as .claude/skills/007/SKILL.md (or your agent's skills folder). This skill also uses 15 other files; get the full folder from GitHub.
name
007
description
Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
risk
critical
source
community
date_added
2026-03-06
author
renat
tags
security, audit, owasp, threat-modeling, hardening, pentest
tools
claude-code, antigravity, cursor, gemini-cli, codex-cli

007 — Licenca para Auditar

Detailed Guide

Read the detailed guide before executing this skill. It retains the complete procedure and reference material. Treat its safety, prerequisites, and validation requirements as mandatory. For focused work, load the relevant sections; for end-to-end work, read the guide completely.

When to Use This Skill

  • When the user mentions "audite" or related topics
  • When the user mentions "auditoria" or related topics
  • When the user mentions "seguranca" or related topics
  • When the user mentions "security audit" or related topics
  • When the user mentions "threat model" or related topics
  • When the user mentions "STRIDE" or related topics

Do Not Use This Skill When

  • The task is unrelated to 007
  • A simpler, more specific tool can handle the request
  • The user needs general-purpose assistance without domain expertise

Limitations

  • Use this skill only when the task clearly matches the scope described above.
  • Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
  • Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 15 other files (scripts, references) in skills/007 of sickn33/agentic-awesome-skills.

  • SKILL.md
  • references/ai-agent-security.md
  • references/api-security-patterns.md
  • references/detailed-guide.md
  • references/incident-playbooks.md
  • references/owasp-checklists.md
  • references/stride-pasta-guide.md
  • scripts/config.py
  • scripts/full_audit.py
  • scripts/quick_scan.py
  • scripts/requirements.txt
  • scripts/scanners/__init__.py
  • scripts/scanners/dependency_scanner.py
  • scripts/scanners/injection_scanner.py
  • scripts/scanners/secrets_scanner.py
  • scripts/score_calculator.py

Open the folder on GitHubat commit ec02547

Used in 2 other repositories

We found 11 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

007 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

007 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
007 this skillsickn33/agentic-awesome-skills47k2 repos~410Automated safety check: PassMIT
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
CybersecurityAgriciDaniel/claude-cybersecurity227—~11kAutomated safety check: WarnMIT
Securitygaragon/nanostack207—~3.7kAutomated safety check: NotesApache-2.0
Csono-session/pstack134—~12kAutomated safety check: NotesMIT
Security Auditfossasia/eventyay-interpretation1.6k—~1.3kAutomated safety check: PassApache-2.0

Similar skills

  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Cybersecurity

    AgriciDaniel/claude-cybersecurity

    Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.

    227 GitHub stars~11k tokensUpdated 5 mo ago
    SecurityAuto-check: warnings
  • Security

    garagon/nanostack

    Use before shipping to production. An agent skill from garagon/nanostack.

    207 GitHub stars~3.7k tokensUpdated 28 days ago
    SecurityAuto-check: notes
  • Cso

    no-session/pstack

    Chief Security Officer mode. An agent skill from no-session/pstack.

    134 GitHub stars~12k tokensUpdated 6 mo ago
    SecurityAuto-check: notes
  • Security Audit

    fossasia/eventyay-interpretation

    A skill your agent uses for security reviews of VoxBento code.

    1.6k GitHub stars~1.3k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Security And Hardening

    dzhalaevd/Donatello

    Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.

    135 GitHub stars~5.1k tokensUpdated 5 days ago
    SecurityAuto-check: notes

More from sickn33/agentic-awesome-skills

All 1,354 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed
  • Content Creator

    sickn33/agentic-awesome-skills

    Drafts and reviews audience-specific content from supplied brand examples, with local scripts for brand voice and SEO diagnostics, channel templates and a content calendar.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed

Categories

Questions about 007

What does 007 do?

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project. 007 is an agent skill from sickn33/agentic-awesome-skills. Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

When should I use 007?

007 fits situations like: tasks that involve Threat modeling; tasks that involve Security review; tasks that involve Web application vulnerabilities.

How do I install 007 in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill 007 -a claude-code`. Or copy the skill folder (skills/007 in sickn33/agentic-awesome-skills) into .claude/skills/007 in your project. Claude Code loads it when a task matches its description.

How do I install 007 in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill 007 -a codex`. Or copy the skill folder (skills/007 in sickn33/agentic-awesome-skills) into .agents/skills/007 in your project. Codex loads it when a task matches its description.

Can I use 007 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill 007 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/007, .gemini/skills/007, .github/skills/007 and .opencode/skills/007 in your project.

What does 007 need to run?

Going by SKILL.md and its folder, 007 needs Python for the scripts in its folder. Our summary lists: Python 3.

Does 007 access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is 007 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does 007 use?

007 is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does 007 use?

About 410 tokens (SKILL.md is roughly 1.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 23k tokens, read only when the agent opens those files.

What are the alternatives to 007?

Skills that share tags, products or a category with 007: Security Audit Scanner (ruvnet/ruflo, 74k stars), Cybersecurity (AgriciDaniel/claude-cybersecurity, 227 stars), Security (garagon/nanostack, 207 stars) and Cso (no-session/pstack, 134 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains 007?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,343 GitHub stars. The repository holds 1,354 skills in this directory. The repository was last updated on October 7, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.