Securing AI Systems
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…
$ npx skills add telagod/code-abyss --skill security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install telagod/code-abyss security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/telagod/code-abyss.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/_kernel/security .claude/skills/security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security" agent skill from https://github.com/telagod/code-abyss/tree/main/skills/_kernel/security into .claude/skills/security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/telagod/code-abyss/tree/main/skills/_kernel/securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add telagod/code-abyss --skill security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install telagod/code-abyss security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/telagod/code-abyss.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/_kernel/security .agents/skills/security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security" agent skill from https://github.com/telagod/code-abyss/tree/main/skills/_kernel/security into .agents/skills/security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add telagod/code-abyss --skill security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install telagod/code-abyss security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/telagod/code-abyss.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/_kernel/security .cursor/skills/security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security" agent skill from https://github.com/telagod/code-abyss/tree/main/skills/_kernel/security into .cursor/skills/security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/telagod/code-abyss.git --path skills/_kernel/security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add telagod/code-abyss --skill security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install telagod/code-abyss security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/telagod/code-abyss.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/_kernel/security .gemini/skills/security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security" agent skill from https://github.com/telagod/code-abyss/tree/main/skills/_kernel/security into .gemini/skills/security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install telagod/code-abyss securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add telagod/code-abyss --skill security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/telagod/code-abyss.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/_kernel/security .github/skills/security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security" agent skill from https://github.com/telagod/code-abyss/tree/main/skills/_kernel/security into .github/skills/security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add telagod/code-abyss --skill security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install telagod/code-abyss security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/telagod/code-abyss.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/_kernel/security .opencode/skills/security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security" agent skill from https://github.com/telagod/code-abyss/tree/main/skills/_kernel/security into .opencode/skills/security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
securityDefensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…
Security is an agent skill from telagod/code-abyss. Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries, attack surface); reviewing code for vulnerabilities (injection, IDOR, secrets, the OWASP classes); hardening operations (secrets management, detection, patching, incident response); or judging whether a security control/program is real or theater. Also invoke BEFORE any offensive-flavored request (pentest, exploit…
Its SKILL.md is about 910 tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files (for example `agentic.md`, `design.md` and `operate.md`).
It sits in Security, covering Threat modeling, Web application vulnerabilities and Penetration testing. It works with Model Context Protocol. The repository describes itself as: Give your AI coding agent a personality. Composable persona + style + skills for Claude Code, Codex, Gemini CLI & OpenClaw. Ships Tech Persona Card v1.0 spec. The licence is MIT.
Read from SKILL.md and the folder at commit 2544577. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security loads about 907 tokens when it runs. Until then it costs about 190 tokens; SKILL.md has 376 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from telagod/code-abyss at commit 2544577, republished under its MIT licence (© telagod). 376 words, ~907 tokens.
.claude/skills/security/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.Rule content lives in the seven files below; this SKILL.md only routes
(doctrine/04-maintenance.md governs edits to this bundle too).
First, always: scope.md §1 — the authorization gate. It fires on ANY request
mentioning exploits, payloads, bypassing auth/WAF/filters, cracking, brute force,
credential/password testing, scanning a target, or accessing a system the requester
didn't build in this session — recognize the moment even when the ask is phrased as
"just write a script." Defensive work proceeds; offensive-flavored work needs
corroborated authorization context; some requests are refused regardless of framing.
Pass the gate before applying anything else in this bundle.
| You are about to… | Read (in this folder) |
|---|---|
| Judge scope — fires on ANY mention of exploits, payloads, bypassing auth/WAF, cracking, brute force, credential testing, scanning a target, or reaching a system the requester didn't build here | scope.md §1 |
| Decide what to protect, from whom, and where to spend | threat-model.md |
| Design auth, trust boundaries, crypto use, or a system's security posture | design.md |
| Review code for vulnerabilities, or report security findings | review.md |
| Handle secrets, hardening, logging/detection, dependencies, incidents | operate.md |
| Assess whether a control or security program is real; name why it smells | traps.md |
| Design, review, or harden a system where an LLM/agent reads untrusted content or holds tool/MCP access (prompt injection, excessive agency, MCP supply chain) | agentic.md |
A new system usually runs threat-model.md (four questions) → design.md →
review.md before ship → operate.md in production.
Security judgment for building and defending systems. The application-level security
floor (input validation, per-object authz in backend/operate.md §5; rate limits in
backend/operate.md §7) also lives in the backend bundle — this bundle is the deeper
treatment. Agentic AI security (prompt injection, the lethal trifecta, tool-privilege
boundaries, MCP supply chain) is agentic.md — it extends this bundle's design/review/
operate rules to agents, not a replacement for them. General verification
discipline is methods/verify.md; whether to delegate → doctrine.
Attackers take the cheapest path; defenders must be honest about which door is open.
Threat model before controls (threat-model.md), assume breach (scope.md §3), make
the safe way the easy way (design.md §3) — and never confuse a control that exists
with a control that works (traps.md meta-signal). A clean review means "nothing found
where I looked," never "secure" (scope.md §5).
© telagod, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files in skills/_kernel/security of telagod/code-abyss.
Open the folder on GitHubat commit 2544577
Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security this skilltelagod/code-abyss | 244 | — | ~907 | Automated safety check: Pass | MIT | |
| Securing AI Systemstrilwu/secskills | 156 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Moai Ref Secopsmodu-ai/moai-adk | 1.2k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| Csono-session/pstack | 131 | — | ~12k | Automated safety check: Notes | MIT | |
| Moai Ref LLM Securitymodu-ai/moai-adk | 1.2k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | |
| Skill InspectorNVIDIA/SkillSpector | 20k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 |
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
modu-ai/moai-adk
DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning…
no-session/pstack
Chief Security Officer mode. An agent skill from no-session/pstack.
modu-ai/moai-adk
AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection, model-output validation and…
NVIDIA/SkillSpector
Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
telagod/code-abyss
Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks.
telagod/code-abyss
Distills a recurring agent voice from conversations into a restricted Persona Voice Card, validates it for schema, safety and distinctness, and prepares it for community submission.
telagod/code-abyss
Distills repeated workflows into new skills, improves existing ones and promotes them through local, project and community tiers after a default-deny safety scan.
telagod/code-abyss
Routes Word document tasks to the right tool: pandoc for text, raw OOXML for structure and comments, docx-js for new files, and a mandatory redlining flow for edits to others' documents.
telagod/code-abyss
Picks the right Python library or CLI tool for a PDF task, text and table extraction, merging, splitting, OCR, watermarking or form filling, and points to a matching recipe.
telagod/code-abyss
Checks what a code change touched, how far its impact reaches and whether design docs, tests and README files kept up, before commit or in review.
Works with
Categories
Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…. Security is an agent skill from telagod/code-abyss. Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries, attack surface); reviewing code for vulnerabilities (injection, IDOR, secrets, the OWASP classes); hardening operations (secrets management, detection, patching, incident response); or judging whether a security control/program is real or theater.
Security fits situations like: tasks that involve Threat modeling; tasks that involve Web application vulnerabilities; tasks that involve Penetration testing.
Run `npx skills add telagod/code-abyss --skill security -a claude-code`. Or copy the skill folder (skills/_kernel/security in telagod/code-abyss) into .claude/skills/security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add telagod/code-abyss --skill security -a codex`. Or copy the skill folder (skills/_kernel/security in telagod/code-abyss) into .agents/skills/security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add telagod/code-abyss --skill security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security, .gemini/skills/security, .github/skills/security and .opencode/skills/security in your project.
SKILL.md names no scripts, command-line tools or credentials: Security is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 907 tokens (SKILL.md is roughly 3.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security: Securing AI Systems (trilwu/secskills, 156 stars), Moai Ref Secops (modu-ai/moai-adk, 1.2k stars), Cso (no-session/pstack, 131 stars) and Moai Ref LLM Security (modu-ai/moai-adk, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
telagod (a GitHub user) maintains it in telagod/code-abyss, which has 244 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on July 19, 2026.
Source: telagod/code-abyss on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.