Agent skill

Bk Monitor Security Audit

by TencentBlueKing in TencentBlueKing/bk-bcs

对前端代码进行安全审计,检测 XSS、CSRF 等漏洞。当用户请求代码审查或询问代码安全性时使用. An agent skill from TencentBlueKing/bk-bcs.

Custom licenceAuto-check passedSecurity

Install Bk Monitor Security Audit

skills CLI
$ npx skills add TencentBlueKing/bk-bcs --skill bk-monitor-security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install TencentBlueKing/bk-bcs bk-monitor-security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/TencentBlueKing/bk-bcs.git skills-src && mkdir -p .claude/skills && cp -r skills-src/bcs-services/bcs-project-manager/.cursor/skills/bk-monitor-security-audit .claude/skills/bk-monitor-security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bk-monitor-security-audit
GitHub stars
840
Token cost
~216 tokens
SKILL.md length
50 words
Files
1
Skills in repo
30
Repo updated
First seen
Licence
Custom licence

At a glance

对前端代码进行安全审计,检测 XSS、CSRF 等漏洞。当用户请求代码审查或询问代码安全性时使用. An agent skill from TencentBlueKing/bk-bcs.

  • Works in 4 steps: 代码提交/审查请求 → 询问代码安全性/漏洞 → 涉及 DOM 操作、URL 处理、用户输入 → …
  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers 触发场景, 审计检查清单, 工作流程 and 📦 可用资源, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Bk Monitor Security Audit is an agent skill from TencentBlueKing/bk-bcs. 对前端代码进行安全审计,检测 XSS、CSRF 等漏洞。当用户请求代码审查或询问代码安全性时使用。

Its SKILL.md is about 220 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities and Security review. The repository describes itself as: 蓝鲸智云容器管理平台(BlueKing Container Service).

When your agent uses it

  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Security review

Example prompts

  • “/bk-monitor-security-audit”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. 代码提交/审查请求
  2. 询问代码安全性/漏洞
  3. 涉及 DOM 操作、URL 处理、用户输入
  4. 提及 XSS、CSRF、注入等安全关键词

What it can do on your machine

Read from SKILL.md and the folder at commit 282070c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bk Monitor Security Audit loads about 216 tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 50 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~216

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 50 words (~216 tokens).

name
bk-monitor-security-audit

Read the full SKILL.md on GitHub

Files

Just SKILL.md in bcs-services/bcs-project-manager/.cursor/skills/bk-monitor-security-audit of TencentBlueKing/bk-bcs.

Open the folder on GitHubat commit 282070c

Compare with similar skills

Bk Monitor Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bk Monitor Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bk Monitor Security Audit this skillTencentBlueKing/bk-bcs840—~216Automated safety check: PassCustom licence
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
Strix Code Vulnerability Scanusestrix/strix68k—~1.1kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence

Similar skills

  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    68k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    SecurityAuto-check: notes

More from TencentBlueKing/bk-bcs

All 30 skills in this repo
  • Tapd Story Pipeline

    TencentBlueKing/bk-bcs

    单需求实现流水线——把一个 TAPD 需求从零推进到代码提交。自动串联技术澄清、 开发计划、任务拆分、TDD 实现、架构/安全校验、代码提交六个阶段。

    840 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed
  • Harness Engineering

    TencentBlueKing/bk-bcs

    Harness Engineering 编排器——为 AI Agent 构建运行环境规范. An agent skill from TencentBlueKing/bk-bcs.

    840 GitHub stars~765 tokensUpdated 2 days ago
    Auto-check passed
  • Tapd Iteration Plan

    TencentBlueKing/bk-bcs

    TAPD 迭代规划技能。基于"approved"状态的需求池,结合需求依赖关系、size 规模、 优先级进行全局编排,将合适规模的需求规划进入指定迭代。支持新建迭代和已有迭代 重入两种模式,自动控制迭代总规模上限(默认 1000),通过有向无环图(DAG)分析 保证依赖需求优先入迭代。

    840 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Tapd Iteration Runner

    TencentBlueKing/bk-bcs

    TAPD 迭代调度器——批量开发一个迭代中的全部需求。自动完成环境初始化、 需求依赖分析、逐需求调度 pipeline 实现、迭代汇总报告四段编排。

    840 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Tapd Product Discovery

    TencentBlueKing/bk-bcs

    A skill your agent uses when work starts before a complete PRD exists, including 产品前置, 产品调研, 用户调研, 竞品分析, PRD, 原型, 想法建单, 老板需求, 需求来源, 产品父单, 角色拆单, 设计子单, 前端子单, 后端子单, 页面原型 Spec, BKUI 原型, HTML 原型, 原型评审…

    840 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Tapd Story Clarification

    TencentBlueKing/bk-bcs

    TAPD 需求澄清技能。从 TAPD 提取"规划中"状态的需求,按照研发最佳实践对需求进行 多维度澄清(业务逻辑、外部系统交互、上下文),整合项目背景知识,输出符合需求文档 规范的标准化 Markdown 需求文档,并回写 TAPD。

    840 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Bk Monitor Security Audit

What does Bk Monitor Security Audit do?

对前端代码进行安全审计,检测 XSS、CSRF 等漏洞。当用户请求代码审查或询问代码安全性时使用. An agent skill from TencentBlueKing/bk-bcs. Bk Monitor Security Audit is an agent skill from TencentBlueKing/bk-bcs.

When should I use Bk Monitor Security Audit?

Bk Monitor Security Audit fits situations like: tasks that involve Web application vulnerabilities; tasks that involve Security review.

How do I install Bk Monitor Security Audit in Claude Code?

Run `npx skills add TencentBlueKing/bk-bcs --skill bk-monitor-security-audit -a claude-code`. Or copy the skill folder (bcs-services/bcs-project-manager/.cursor/skills/bk-monitor-security-audit in TencentBlueKing/bk-bcs) into .claude/skills/bk-monitor-security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Bk Monitor Security Audit in Codex?

Run `npx skills add TencentBlueKing/bk-bcs --skill bk-monitor-security-audit -a codex`. Or copy the skill folder (bcs-services/bcs-project-manager/.cursor/skills/bk-monitor-security-audit in TencentBlueKing/bk-bcs) into .agents/skills/bk-monitor-security-audit in your project. Codex loads it when a task matches its description.

Can I use Bk Monitor Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TencentBlueKing/bk-bcs --skill bk-monitor-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bk-monitor-security-audit, .gemini/skills/bk-monitor-security-audit, .github/skills/bk-monitor-security-audit and .opencode/skills/bk-monitor-security-audit in your project.

What does Bk Monitor Security Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Bk Monitor Security Audit is instructions for the agent only.

Does Bk Monitor Security Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Bk Monitor Security Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bk Monitor Security Audit use?

Bk Monitor Security Audit has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Bk Monitor Security Audit use?

About 216 tokens (SKILL.md is roughly 864 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bk Monitor Security Audit?

Skills that share tags, products or a category with Bk Monitor Security Audit: Security Auditor (eigent-ai/eigent, 15k stars), Security Review (jewbetcha/opentrace, 116 stars), Strix Code Vulnerability Scan (usestrix/strix, 68k stars) and Code Audit (3stoneBrother/code-audit, 892 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bk Monitor Security Audit?

TencentBlueKing (a GitHub organization) maintains it in TencentBlueKing/bk-bcs, which has 840 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 9, 2026.

Source: TencentBlueKing/bk-bcs on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.