Agent skill

Securing Systems

by telagod in telagod/code-abyss

Security engineering router for penetration testing, code auditing, red/blue/purple team operations, threat intelligence, and vulnerability research.

MITAuto-check passedSecurity

Install Securing Systems

skills CLI
$ npx skills add telagod/code-abyss --skill securing-systems -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install telagod/code-abyss securing-systems --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/telagod/code-abyss.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/securing-systems .claude/skills/securing-systems && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
securing-systems
GitHub stars
244
Token cost
~581 tokens
SKILL.md length
120 words
Files
8 (incl. references)
Skills in repo
38
Repo updated
First seen
Licence
MIT

At a glance

Security engineering router for penetration testing, code auditing, red/blue/purple team operations, threat intelligence, and vulnerability research.

  • Tasks that involve Security operations
  • SKILL.md covers 路由, 执行链, 输出约束 and 优先级
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Supply chain security

What it does

Securing Systems is an agent skill from telagod/code-abyss. Security engineering router for penetration testing, code auditing, red/blue/purple team operations, threat intelligence, and vulnerability research. For specialized application security, cloud security, detection engineering, or security architecture, route to dedicated skills (defending-applications, securing-cloud-and-supply-chain, detecting-and-responding, architecting-security).

Its SKILL.md is about 580 tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/authorization-tiers.md`, `references/blue-team.md` and `references/code-audit.md`).

It sits in Security, covering Security operations, Supply chain security and OSINT. The repository describes itself as: Give your AI coding agent a personality. Composable persona + style + skills for Claude Code, Codex, Gemini CLI & OpenClaw. Ships Tech Persona Card v1.0 spec. The licence is MIT.

When your agent uses it

  • Tasks that involve Security operations
  • Tasks that involve Supply chain security
  • Tasks that involve OSINT

Example prompts

  • “/securing-systems”

What it can do on your machine

Read from SKILL.md and the folder at commit 2544577. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Securing Systems loads about 581 tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 101 tokens; SKILL.md has 120 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~101
When it runs · the whole SKILL.md, loaded when a task matches
~581
With references · SKILL.md plus every file in references/, read only if the agent opens them
~16k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from telagod/code-abyss at commit 2544577, republished under its MIT licence (© telagod). 120 words, ~581 tokens.

Download SKILL.mdSave it as .claude/skills/securing-systems/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
securing-systems
description
Security engineering router for penetration testing, code auditing, red/blue/purple team operations, threat intelligence, and vulnerability research. For specialized application security, cloud security, detection engineering, or security architecture, route to dedicated skills (defending-applications, securing-cloud-and-supply-chain, detecting-and-responding, architecting-security).
user-invocable
false

攻防秘典

判断先于执行:决定「是否做 / 选什么 / 如何取舍」(栈、方案、架构、权衡)前,先读领域判断内核 skills/_kernel/security/SKILL.md——它管 judgment,本秘典管 execution;冲突时以内核判断为准。

安全工程总路由:通用攻防视角与红队 / 蓝队 / 紫队实战知识。 专域工作(应用安全防御、云原生加固、检测工程、安全架构)走专门 skill。 信级:项目文件 > 标准库 > 训练记忆(标 [unverified])

路由

攻防基础(本 skill 内)
意图秘典核心
渗透测试pentestWeb/API/内网、OWASP、BOLA、JWT、GraphQL
代码审计code-audit危险函数、污点追踪、Source→Sink
红队攻击red-teamPoC、C2、横移、免杀、供应链
蓝队防御blue-team检测、SOC、IR、取证、密钥轮换
威胁情报threat-intelOSINT、威胁狩猎、ATT&CK 建模
漏洞研究vuln-research逆向、Exploit、Fuzzing、PWN
执行模式 / CTF 沙箱authorization-tiersT1/T2/T3、CTF 目标默认沙箱
专域路由(其他 skill)
意图走 skill适用
应用层防御(XSS / SQLi / OAuth / LLM AppSec)defending-applications写代码 / 修 CVE / 鉴权设计
云原生 + 供应链加固securing-cloud-and-supply-chainK8s / CI/CD / SLSA / 云 IAM
检测工程 + 蓝紫队detecting-and-respondingSigma / EDR / IR / 威胁狩猎
安全架构 + 合规 + 身份architecting-security威胁建模 / 零信任 / SOC2/PCI

执行链

攻:侦察 → 武器化 → 投递 → 利用 → 安装 → C2 → 行动
守:预防 → 检测 → 响应 → 恢复
紫队:ATT&CK → 红攻 → 蓝检 → 缺口 → 闭环

输出约束

  • 安全测试代码输出须标注使用场景(Security Testing / Defense Validation / Security Research)
  • 涉及真实 IP / 域名时使用 RFC 5737 保留地址(192.0.2.0/24、198.51.100.0/24)或 example.com
  • 凭证、密钥、Token 一律使用占位符(<REDACTED>、<TARGET-TOKEN>)
  • 每个攻击技术附带检测 / 缓解建议,攻防一体呈现

优先级

场景排序
攻击模拟效果 > 精准 > 控制
防御响应正确 > 覆盖 > 速度
紧急事件速度 > 正确 > 简洁

© telagod, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in skills/securing-systems of telagod/code-abyss.

  • SKILL.md
  • references/authorization-tiers.md
  • references/blue-team.md
  • references/code-audit.md
  • references/pentest.md
  • references/red-team.md
  • references/threat-intel.md
  • references/vuln-research.md

Open the folder on GitHubat commit 2544577

Compare with similar skills

Securing Systems next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Securing Systems compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Securing Systems this skilltelagod/code-abyss244—~581Automated safety check: PassMIT
Metabigor OSINT Reconj3ssie/metabigor1.8k—~2.4kAutomated safety check: PassMIT
Gha Security Reviewgetsentry/skills1k3 repos~2.2kAutomated safety check: NotesApache-2.0
Attack Flowwiz-sec-public/SITF182—~3.1kAutomated safety check: PassCustom licence
External Recon PlaybookPentesterFlow/agent1.4k—~1.2kAutomated safety check: PassApache-2.0
Threat Intelligence OSINTzhaoxuya520/reverse-skill40k1 repos~1kAutomated safety check: PassMIT

Similar skills

  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.8k GitHub stars~2.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Gha Security Review

    getsentry/skills

    Official

    GitHub Actions security review for workflow exploitation vulnerabilities.

    1k GitHub starsUsed in 3 repos~2.2k tokens
    SecurityAuto-check: notes
  • Attack Flow

    wiz-sec-public/SITF

    Generate SITF-compliant attack flow JSON files from attack descriptions or incident reports.

    182 GitHub stars~3.1k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • External Recon Playbook

    PentesterFlow/agent

    Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology.

    1.4k GitHub stars~1.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Threat Intelligence OSINT

    zhaoxuya520/reverse-skill

    Enriches IOCs, campaigns, impersonation and scams from public sources, including bounded X search through Xquik, and checks each lead against independent evidence.

    40k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check passed
  • Security Reviewer

    AratKruglik/claude-laravel

    A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.

    155 GitHub starsUsed in 1 repo~1.1k tokens
    SecurityAuto-check: notes

More from telagod/code-abyss

All 38 skills in this repo
  • Security Gate Scanner

    telagod/code-abyss

    Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks.

    244 GitHub stars~552 tokensUpdated 2 mo ago
    Auto-check: notes
  • Persona Voice Card Builder

    telagod/code-abyss

    Distills a recurring agent voice from conversations into a restricted Persona Voice Card, validates it for schema, safety and distinctness, and prepares it for community submission.

    244 GitHub stars~716 tokensUpdated 2 mo ago
    Auto-check: notes
  • Skill Cultivation Funnel

    telagod/code-abyss

    Distills repeated workflows into new skills, improves existing ones and promotes them through local, project and community tiers after a default-deny safety scan.

    244 GitHub stars~794 tokensUpdated 2 mo ago
    Auto-check: notes
  • DOCX Processing Toolkit

    telagod/code-abyss

    Routes Word document tasks to the right tool: pandoc for text, raw OOXML for structure and comments, docx-js for new files, and a mandatory redlining flow for edits to others' documents.

    244 GitHub stars~668 tokensUpdated 2 mo ago
    Auto-check: notes
  • PDF Processing Toolkit

    telagod/code-abyss

    Picks the right Python library or CLI tool for a PDF task, text and table extraction, merging, splitting, OCR, watermarking or form filling, and points to a matching recipe.

    244 GitHub stars~532 tokensUpdated 2 mo ago
    Auto-check: notes
  • Code Change Analysis Gate

    telagod/code-abyss

    Checks what a code change touched, how far its impact reaches and whether design docs, tests and README files kept up, before commit or in review.

    244 GitHub stars~532 tokensUpdated 2 mo ago
    Auto-check: notes

Categories

Questions about Securing Systems

What does Securing Systems do?

Security engineering router for penetration testing, code auditing, red/blue/purple team operations, threat intelligence, and vulnerability research. Securing Systems is an agent skill from telagod/code-abyss. Security engineering router for penetration testing, code auditing, red/blue/purple team operations, threat intelligence, and vulnerability research.

When should I use Securing Systems?

Securing Systems fits situations like: tasks that involve Security operations; tasks that involve Supply chain security; tasks that involve OSINT.

How do I install Securing Systems in Claude Code?

Run `npx skills add telagod/code-abyss --skill securing-systems -a claude-code`. Or copy the skill folder (skills/securing-systems in telagod/code-abyss) into .claude/skills/securing-systems in your project. Claude Code loads it when a task matches its description.

How do I install Securing Systems in Codex?

Run `npx skills add telagod/code-abyss --skill securing-systems -a codex`. Or copy the skill folder (skills/securing-systems in telagod/code-abyss) into .agents/skills/securing-systems in your project. Codex loads it when a task matches its description.

Can I use Securing Systems in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add telagod/code-abyss --skill securing-systems -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/securing-systems, .gemini/skills/securing-systems, .github/skills/securing-systems and .opencode/skills/securing-systems in your project.

What does Securing Systems need to run?

SKILL.md names no scripts, command-line tools or credentials: Securing Systems is instructions for the agent only.

Does Securing Systems access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Securing Systems safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Securing Systems use?

Securing Systems is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Securing Systems use?

About 581 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16k tokens, read only when the agent opens those files.

What are the alternatives to Securing Systems?

Skills that share tags, products or a category with Securing Systems: Metabigor OSINT Recon (j3ssie/metabigor, 1.8k stars), Gha Security Review (getsentry/skills, 1k stars), Attack Flow (wiz-sec-public/SITF, 182 stars) and External Recon Playbook (PentesterFlow/agent, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Securing Systems?

telagod (a GitHub user) maintains it in telagod/code-abyss, which has 244 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on July 19, 2026.

Source: telagod/code-abyss on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.