Agent skill

Security Gate Scanner

by telagod in telagod/code-abyss

Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks.

MITAuto-check: notesSecurity

SKILL.md written in Chinese; this summary is our English description.

Install Security Gate Scanner

skills CLI
$ npx skills add telagod/code-abyss --skill analyzing-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install telagod/code-abyss analyzing-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/telagod/code-abyss.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/analyzing-security .claude/skills/analyzing-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyzing-security
GitHub stars
244
Token cost
~552 tokens
SKILL.md length
122 words
Files
4 (incl. scripts, references)
Skills in repo
38
Repo updated
First seen
Licence
MIT

At a glance

Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks.

  • Works in 2 steps: 检查命中文本是否真为 sink(看上下文,不只是模式) → 若确认假阳,在 DESIGN.md 记录 + 行内注释(// nosec:…
  • Scanning a new module before it lands
  • SKILL.md covers 何时使用, 何时不使用, 解读输出 and 与其他 skill 联动, plus 2 more sections
  • Runs JavaScript scripts from its folder; calls node and npm

What it does

This skill runs a security gate over code with a bundled scanner, scripts/security_scanner.js, which flags dangerous patterns such as SQL and command injection, hardcoded secrets and cloud keys, private keys, XSS, unsafe deserialization, path traversal, SSRF, weak crypto, insecure randomness and leftover debug code. It runs for new modules, security-related changes, finished refactors and before commits that handle sensitive data or external input; documentation-only changes need no scan. The skill text is in Chinese.

Output carries a severity (critical, high, medium or low) and a category. Critical findings block delivery without exception, while high findings must be fixed or explicitly accepted with a note in DESIGN.md and a compensating control. Medium and low findings can stay when judged known and assessed, such as MD5 for hash buckets or random for jitter. Each rule has an exclude pattern for false positives, which are confirmed in context and recorded with an inline nosec comment. It does not replace dependency audits, runtime DAST or configuration audits. Scanner options include verbose and JSON output for CI.

When your agent uses it

  • Scanning a new module before it lands
  • Checking security-related changes or a finished refactor
  • Running a final scan before committing code that handles sensitive data or external input
  • Triaging scanner findings and recording accepted risks

Example prompts

  • “Run the security scanner on src/ and summarize the critical and high findings.”
  • “Scan my refactor for injection or hardcoded secrets before I commit.”
  • “One scanner hit looks like a false positive, so check the context and record it properly.”

Requirements

  • Node 18 or newer
  • Compatibility (from SKILL.md): node>=18
  • Pre-approved tools (allowed-tools): Bash, Read, Grep

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. 检查命中文本是否真为 sink(看上下文,不只是模式)
  2. 若确认假阳,在 DESIGN.md 记录 + 行内注释(// nosec: <规则 ID> <理由>)

What it can do on your machine

Read from SKILL.md and the folder at commit 2544577. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    node>=18

    From compatibility in the SKILL.md frontmatter.

Context cost

Security Gate Scanner loads about 552 tokens when it runs, and up to ~1.1k if it reads all its reference files. Until then it costs about 85 tokens; SKILL.md has 122 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~552
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from telagod/code-abyss at commit 2544577, republished under its MIT licence (© telagod). 122 words, ~552 tokens.

Download SKILL.mdSave it as .claude/skills/analyzing-security/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
analyzing-security
description
Scans code for security vulnerabilities, detects dangerous patterns, and ensures security decisions are documented. Use when running security scans, auditing code, or checking for OWASP issues, injection risks, or sensitive data leaks. Automatically triggered on new modules, security-related changes, or post-refactor.
allowed-tools
Bash, Read, Grep
compatibility
node>=18
user-invocable
false
argument-hint
<扫描路径>

安全校验关卡

判断先于执行:决定「是否做 / 选什么 / 如何取舍」(栈、方案、架构、权衡)前,先读领域判断内核 skills/_kernel/security/SKILL.md——它管 judgment,本秘典管 execution;冲突时以内核判断为准。

自动化扫描捕捉模式,但严重度判定与处置取决于上下文——sink、信任边界、补偿控制。

何时使用

场景必跑理由
新模块落地✅引入新攻击面
安全相关变更✅直接触及威胁面
重构完成✅防止重构引入退化
提交前(含敏感数据/外部输入处理)✅最后一道闸
攻防任务交付✅验收前自检
仅文档/样式改动❌无攻击面变化

何时不使用

  • 依赖更新(用 SCA 工具如 npm audit、pip-audit,不是模式扫描)
  • 运行时漏洞(用 DAST,不是静态扫描)
  • 配置审计(用 CIS Benchmark 或专用工具)

解读输出

严重度(critical / high / medium / low)+ 类别(注入 / 敏感信息 / XSS / 反序列化 / 路径遍历 / SSRF / 弱加密 / 不安全随机 / 调试残留)。

必修
  • Critical(SQL 注入、命令注入、硬编码密钥、AWS Key、私钥)→ 阻断交付,无例外。
  • High(XSS、反序列化、路径遍历、SSRF)→ 修复或显式接受风险(需 DESIGN.md 留痕 + 补偿控制)。
上下文降级条件
  • Medium/Low 可在 DESIGN.md 标注「已知/已评估」后保留。判据:
    • 弱加密 MD5/SHA1 用于非安全场景(如 hash bucket)→ 可接受
    • random 用于非安全场景(如 jitter)→ 可接受
    • 调试残留在 dev-only 构建 → 可接受,prod 构建必须剔除
假阳处理

每条规则均有 excludePattern,若仍误报:

  1. 检查命中文本是否真为 sink(看上下文,不只是模式)
  2. 若确认假阳,在 DESIGN.md 记录 + 行内注释(// nosec: <规则 ID> <理由>)

与其他 skill 联动

  • 命中 critical/high → 同步触发 securing-systems 路由的对应秘典(如 SQL 注入查 pentest.md)
  • 新模块场景 → 与 verifying-modules 串行,先扫安全再校验文档
  • 变更场景 → 与 analyzing-changes 串行,先看变更范围再决定扫描深度

使用

bash
node scripts/security_scanner.js <路径>            # 默认全扫
node scripts/security_scanner.js <路径> -v         # 详细,含命中代码片段
node scripts/security_scanner.js <路径> --json     # 机读格式,供 CI
node scripts/security_scanner.js <路径> --exclude vendor,dist

完整规则矩阵、危险模式速查、误报豁免清单详见 references/rules.md。

收口

Critical/High 必修后方可交付。安全决策须于 DESIGN.md 记录:威胁模型、信任边界、已知风险、补偿控制。

© telagod, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/analyzing-security of telagod/code-abyss.

  • SKILL.md
  • agents/openai.yaml
  • references/rules.md
  • scripts/security_scanner.js

Open the folder on GitHubat commit 2544577

Compare with similar skills

Security Gate Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Gate Scanner compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Gate Scanner this skilltelagod/code-abyss244—~552Automated safety check: NotesMIT
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Security Scanericrisco/rsc-harness156—~2.8kAutomated safety check: NotesMIT
Zeroization Audittrailofbits/skills7.4k4 repos~5.9kAutomated safety check: NotesCC-BY-SA-4.0
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT

Similar skills

  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Security Scan

    ericrisco/rsc-harness

    A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

    156 GitHub stars~2.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Zeroization Audit

    trailofbits/skills

    Official

    Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis.

    7.4k GitHub starsUsed in 4 repos~5.9k tokens
    SecurityAuto-check: notes
  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated 5 days ago
    SecurityAuto-check passed

More from telagod/code-abyss

All 38 skills in this repo
  • Persona Voice Card Builder

    telagod/code-abyss

    Distills a recurring agent voice from conversations into a restricted Persona Voice Card, validates it for schema, safety and distinctness, and prepares it for community submission.

    244 GitHub stars~716 tokensUpdated 2 mo ago
    Auto-check: notes
  • Skill Cultivation Funnel

    telagod/code-abyss

    Distills repeated workflows into new skills, improves existing ones and promotes them through local, project and community tiers after a default-deny safety scan.

    244 GitHub stars~794 tokensUpdated 2 mo ago
    Auto-check: notes
  • DOCX Processing Toolkit

    telagod/code-abyss

    Routes Word document tasks to the right tool: pandoc for text, raw OOXML for structure and comments, docx-js for new files, and a mandatory redlining flow for edits to others' documents.

    244 GitHub stars~668 tokensUpdated 2 mo ago
    Auto-check: notes
  • PDF Processing Toolkit

    telagod/code-abyss

    Picks the right Python library or CLI tool for a PDF task, text and table extraction, merging, splitting, OCR, watermarking or form filling, and points to a matching recipe.

    244 GitHub stars~532 tokensUpdated 2 mo ago
    Auto-check: notes
  • Code Change Analysis Gate

    telagod/code-abyss

    Checks what a code change touched, how far its impact reaches and whether design docs, tests and README files kept up, before commit or in review.

    244 GitHub stars~532 tokensUpdated 2 mo ago
    Auto-check: notes
  • Code Quality Gate Checker

    telagod/code-abyss

    Checks cyclomatic complexity, function and file length, parameter count, nesting depth and naming conventions against fixed thresholds, with a bundled Node.js script and hotspot integration.

    244 GitHub stars~609 tokensUpdated 2 mo ago
    Auto-check: notes

Categories

Questions about Security Gate Scanner

What does Security Gate Scanner do?

Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks. js, which flags dangerous patterns such as SQL and command injection, hardcoded secrets and cloud keys, private keys, XSS, unsafe deserialization, path traversal, SSRF, weak crypto, insecure randomness and leftover debug code. It runs for new modules, security-related changes, finished refactors and before commits that handle sensitive data or external input; documentation-only changes need no scan.

When should I use Security Gate Scanner?

Security Gate Scanner fits situations like: scanning a new module before it lands; checking security-related changes or a finished refactor; running a final scan before committing code that handles sensitive data or external input; triaging scanner findings and recording accepted risks.

How do I install Security Gate Scanner in Claude Code?

Run `npx skills add telagod/code-abyss --skill analyzing-security -a claude-code`. Or copy the skill folder (skills/analyzing-security in telagod/code-abyss) into .claude/skills/analyzing-security in your project. Claude Code loads it when a task matches its description.

How do I install Security Gate Scanner in Codex?

Run `npx skills add telagod/code-abyss --skill analyzing-security -a codex`. Or copy the skill folder (skills/analyzing-security in telagod/code-abyss) into .agents/skills/analyzing-security in your project. Codex loads it when a task matches its description.

Can I use Security Gate Scanner in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add telagod/code-abyss --skill analyzing-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-security, .gemini/skills/analyzing-security, .github/skills/analyzing-security and .opencode/skills/analyzing-security in your project.

What does Security Gate Scanner need to run?

Going by SKILL.md and its folder, Security Gate Scanner needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node and npm). Our summary lists: Node 18 or newer. Its frontmatter pre-approves these tools: Bash, Read, Grep. Compatibility (from SKILL.md): node>=18.

Does Security Gate Scanner access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Gate Scanner safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Gate Scanner use?

Security Gate Scanner is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Gate Scanner use?

About 552 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 588 tokens, read only when the agent opens those files.

What are the alternatives to Security Gate Scanner?

Skills that share tags, products or a category with Security Gate Scanner: CodeQL Security Scan (trailofbits/skills, 7.4k stars), Security Scan (ericrisco/rsc-harness, 156 stars), Zeroization Audit (trailofbits/skills, 7.4k stars) and Kedro Security Review (kedro-org/kedro, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Gate Scanner?

telagod (a GitHub user) maintains it in telagod/code-abyss, which has 244 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on July 19, 2026.

Source: telagod/code-abyss on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.