CodeQL Security Scan
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks.
SKILL.md written in Chinese; this summary is our English description.
$ npx skills add telagod/code-abyss --skill analyzing-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install telagod/code-abyss analyzing-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/telagod/code-abyss.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/analyzing-security .claude/skills/analyzing-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "analyzing-security" agent skill from https://github.com/telagod/code-abyss/tree/main/skills/analyzing-security into .claude/skills/analyzing-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/telagod/code-abyss/tree/main/skills/analyzing-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add telagod/code-abyss --skill analyzing-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install telagod/code-abyss analyzing-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/telagod/code-abyss.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/analyzing-security .agents/skills/analyzing-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "analyzing-security" agent skill from https://github.com/telagod/code-abyss/tree/main/skills/analyzing-security into .agents/skills/analyzing-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add telagod/code-abyss --skill analyzing-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install telagod/code-abyss analyzing-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/telagod/code-abyss.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/analyzing-security .cursor/skills/analyzing-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "analyzing-security" agent skill from https://github.com/telagod/code-abyss/tree/main/skills/analyzing-security into .cursor/skills/analyzing-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/telagod/code-abyss.git --path skills/analyzing-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add telagod/code-abyss --skill analyzing-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install telagod/code-abyss analyzing-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/telagod/code-abyss.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/analyzing-security .gemini/skills/analyzing-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "analyzing-security" agent skill from https://github.com/telagod/code-abyss/tree/main/skills/analyzing-security into .gemini/skills/analyzing-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install telagod/code-abyss analyzing-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add telagod/code-abyss --skill analyzing-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/telagod/code-abyss.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/analyzing-security .github/skills/analyzing-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "analyzing-security" agent skill from https://github.com/telagod/code-abyss/tree/main/skills/analyzing-security into .github/skills/analyzing-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add telagod/code-abyss --skill analyzing-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install telagod/code-abyss analyzing-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/telagod/code-abyss.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/analyzing-security .opencode/skills/analyzing-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "analyzing-security" agent skill from https://github.com/telagod/code-abyss/tree/main/skills/analyzing-security into .opencode/skills/analyzing-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
analyzing-securityScans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks.
This skill runs a security gate over code with a bundled scanner, scripts/security_scanner.js, which flags dangerous patterns such as SQL and command injection, hardcoded secrets and cloud keys, private keys, XSS, unsafe deserialization, path traversal, SSRF, weak crypto, insecure randomness and leftover debug code. It runs for new modules, security-related changes, finished refactors and before commits that handle sensitive data or external input; documentation-only changes need no scan. The skill text is in Chinese.
Output carries a severity (critical, high, medium or low) and a category. Critical findings block delivery without exception, while high findings must be fixed or explicitly accepted with a note in DESIGN.md and a compensating control. Medium and low findings can stay when judged known and assessed, such as MD5 for hash buckets or random for jitter. Each rule has an exclude pattern for false positives, which are confirmed in context and recorded with an inline nosec comment. It does not replace dependency audits, runtime DAST or configuration audits. Scanner options include verbose and JSON output for CI.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 2544577. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadGrepFrom allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
nodenpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
node>=18
From compatibility in the SKILL.md frontmatter.
Security Gate Scanner loads about 552 tokens when it runs, and up to ~1.1k if it reads all its reference files. Until then it costs about 85 tokens; SKILL.md has 122 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, GrepAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from telagod/code-abyss at commit 2544577, republished under its MIT licence (© telagod). 122 words, ~552 tokens.
.claude/skills/analyzing-security/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.判断先于执行:决定「是否做 / 选什么 / 如何取舍」(栈、方案、架构、权衡)前,先读领域判断内核
skills/_kernel/security/SKILL.md——它管 judgment,本秘典管 execution;冲突时以内核判断为准。
自动化扫描捕捉模式,但严重度判定与处置取决于上下文——sink、信任边界、补偿控制。
| 场景 | 必跑 | 理由 |
|---|---|---|
| 新模块落地 | ✅ | 引入新攻击面 |
| 安全相关变更 | ✅ | 直接触及威胁面 |
| 重构完成 | ✅ | 防止重构引入退化 |
| 提交前(含敏感数据/外部输入处理) | ✅ | 最后一道闸 |
| 攻防任务交付 | ✅ | 验收前自检 |
| 仅文档/样式改动 | ❌ | 无攻击面变化 |
npm audit、pip-audit,不是模式扫描)严重度(critical / high / medium / low)+ 类别(注入 / 敏感信息 / XSS / 反序列化 / 路径遍历 / SSRF / 弱加密 / 不安全随机 / 调试残留)。
random 用于非安全场景(如 jitter)→ 可接受每条规则均有 excludePattern,若仍误报:
// nosec: <规则 ID> <理由>)pentest.md)node scripts/security_scanner.js <路径> # 默认全扫
node scripts/security_scanner.js <路径> -v # 详细,含命中代码片段
node scripts/security_scanner.js <路径> --json # 机读格式,供 CI
node scripts/security_scanner.js <路径> --exclude vendor,dist完整规则矩阵、危险模式速查、误报豁免清单详见 references/rules.md。
Critical/High 必修后方可交付。安全决策须于 DESIGN.md 记录:威胁模型、信任边界、已知风险、补偿控制。
© telagod, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/analyzing-security of telagod/code-abyss.
Open the folder on GitHubat commit 2544577
Security Gate Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Gate Scanner this skilltelagod/code-abyss | 244 | — | ~552 | Automated safety check: Notes | MIT | |
| CodeQL Security Scantrailofbits/skills | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Security Scanericrisco/rsc-harness | 156 | — | ~2.8k | Automated safety check: Notes | MIT | |
| Zeroization Audittrailofbits/skills | 7.4k | 4 repos | ~5.9k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Kedro Security Reviewkedro-org/kedro | 11k | — | ~3.3k | Automated safety check: Pass | Custom licence | |
| Security Audit Scannerruvnet/ruflo | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT |
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
ericrisco/rsc-harness
A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…
trailofbits/skills
Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis.
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
telagod/code-abyss
Distills a recurring agent voice from conversations into a restricted Persona Voice Card, validates it for schema, safety and distinctness, and prepares it for community submission.
telagod/code-abyss
Distills repeated workflows into new skills, improves existing ones and promotes them through local, project and community tiers after a default-deny safety scan.
telagod/code-abyss
Routes Word document tasks to the right tool: pandoc for text, raw OOXML for structure and comments, docx-js for new files, and a mandatory redlining flow for edits to others' documents.
telagod/code-abyss
Picks the right Python library or CLI tool for a PDF task, text and table extraction, merging, splitting, OCR, watermarking or form filling, and points to a matching recipe.
telagod/code-abyss
Checks what a code change touched, how far its impact reaches and whether design docs, tests and README files kept up, before commit or in review.
telagod/code-abyss
Checks cyclomatic complexity, function and file length, parameter count, nesting depth and naming conventions against fixed thresholds, with a bundled Node.js script and hotspot integration.
Categories
Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks. js, which flags dangerous patterns such as SQL and command injection, hardcoded secrets and cloud keys, private keys, XSS, unsafe deserialization, path traversal, SSRF, weak crypto, insecure randomness and leftover debug code. It runs for new modules, security-related changes, finished refactors and before commits that handle sensitive data or external input; documentation-only changes need no scan.
Security Gate Scanner fits situations like: scanning a new module before it lands; checking security-related changes or a finished refactor; running a final scan before committing code that handles sensitive data or external input; triaging scanner findings and recording accepted risks.
Run `npx skills add telagod/code-abyss --skill analyzing-security -a claude-code`. Or copy the skill folder (skills/analyzing-security in telagod/code-abyss) into .claude/skills/analyzing-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add telagod/code-abyss --skill analyzing-security -a codex`. Or copy the skill folder (skills/analyzing-security in telagod/code-abyss) into .agents/skills/analyzing-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add telagod/code-abyss --skill analyzing-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-security, .gemini/skills/analyzing-security, .github/skills/analyzing-security and .opencode/skills/analyzing-security in your project.
Going by SKILL.md and its folder, Security Gate Scanner needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node and npm). Our summary lists: Node 18 or newer. Its frontmatter pre-approves these tools: Bash, Read, Grep. Compatibility (from SKILL.md): node>=18.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Security Gate Scanner is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 552 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 588 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Security Gate Scanner: CodeQL Security Scan (trailofbits/skills, 7.4k stars), Security Scan (ericrisco/rsc-harness, 156 stars), Zeroization Audit (trailofbits/skills, 7.4k stars) and Kedro Security Review (kedro-org/kedro, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
telagod (a GitHub user) maintains it in telagod/code-abyss, which has 244 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on July 19, 2026.
Source: telagod/code-abyss on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.