Agent skill

Security

by travisjneuman in travisjneuman/.claude

Information security expertise for cybersecurity frameworks (NIST, ISO 27001), security architecture, incident response, vulnerability management, identity management, and cloud security.

MITAuto-check passedSecurity

Install Security

skills CLI
$ npx skills add travisjneuman/.claude --skill security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install travisjneuman/.claude security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/travisjneuman/.claude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security .claude/skills/security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security
GitHub stars
101
Token cost
~3.3k tokens
SKILL.md length
373 words
Files
4 (incl. references)
Skills in repo
21
Repo updated
First seen
Licence
MIT

At a glance

Information security expertise for cybersecurity frameworks (NIST, ISO 27001), security architecture, incident response, vulnerability management, identity management, and cloud security.

  • Works in 10 steps: Broken Access Control → Cryptographic Failures → Injection → …
  • Designing security programs
  • SKILL.md covers Security Architecture, Vulnerability Management, Identity & Access Management and Security Awareness, plus 4 more sections
  • Calls npm, semgrep and docker; needs JWT_SECRET

What it does

Security is an agent skill from travisjneuman/.claude. Information security expertise for cybersecurity frameworks (NIST, ISO 27001), security architecture, incident response, vulnerability management, identity management, and cloud security. Use when designing security programs, responding to incidents, or assessing vulnerabilities.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/fortune50-information-security.md`, `references/incident-response.md` and `references/security-frameworks.md`).

It sits in Security, covering Cloud security, Vulnerability scanning and SOC 2 and security compliance. The repository describes itself as: The Ultimate Claude Code Toolkit: 180 skills, 10 agents, 29 commands, 7 hooks, and 81 marketplace repos (11,000+ community skills). Drop-in ~/.claude config with a generated… The licence is MIT.

When your agent uses it

  • Designing security programs
  • Responding to incidents
  • Assessing vulnerabilities

Example prompts

  • “/security”

Requirements

  • Python 3
  • Docker
  • A credential in JWT_SECRET

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Broken Access Control
  2. Cryptographic Failures
  3. Injection
  4. Insecure Design
  5. Security Misconfiguration
  6. Vulnerable Components
  7. Authentication Failures
  8. Software and Data Integrity Failures
  9. Security Logging and Monitoring Failures
  10. Server-Side Request Forgery (SSRF)

What it can do on your machine

Read from SKILL.md and the folder at commit 139c07b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • semgrep
    • docker
    • cargo
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, docker and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • JWT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security loads about 3.3k tokens when it runs, and up to ~23k if it reads all its reference files. Until then it costs about 72 tokens; SKILL.md has 373 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~23k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from travisjneuman/.claude at commit 139c07b, republished under its MIT licence (© travisjneuman). 373 words, ~3,317 tokens.

Download SKILL.mdSave it as .claude/skills/security/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
security
description
Information security expertise for cybersecurity frameworks (NIST, ISO 27001), security architecture, incident response, vulnerability management, identity management, and cloud security. Use when designing security programs, responding to incidents, or assessing vulnerabilities.

Information Security Expert

Comprehensive security frameworks for cybersecurity, incident response, and security architecture.

Security Architecture

Zero Trust Architecture
ZERO TRUST PRINCIPLES:
- Never trust, always verify
- Assume breach
- Verify explicitly
- Least privilege access
- Micro-segmentation

ZERO TRUST COMPONENTS:

IDENTITY:
- Strong authentication (MFA)
- Identity governance
- Privileged access management
- Continuous validation

DEVICES:
- Device health verification
- Endpoint detection and response
- Mobile device management
- Asset inventory

NETWORK:
- Micro-segmentation
- Software-defined perimeter
- Encrypted communications
- Network access control

APPLICATIONS:
- Application-level authentication
- API security
- Web application firewall
- Secure coding practices

DATA:
- Data classification
- Encryption at rest and in transit
- Data loss prevention
- Access controls
Defense in Depth
SECURITY LAYERS:

PHYSICAL:
- Data center security
- Badge access
- Surveillance
- Environmental controls

PERIMETER:
- Firewalls
- IDS/IPS
- DMZ
- VPN

NETWORK:
- Segmentation
- Encryption
- Network monitoring
- NAC

HOST:
- Endpoint protection
- Host-based firewall
- Hardening
- Patch management

APPLICATION:
- WAF
- Secure coding
- Input validation
- Authentication

DATA:
- Encryption
- DLP
- Access controls
- Backup/recovery
Cloud Security
DomainControls
IdentitySSO, MFA, PAM, IAM policies
ComputeHardened images, container security
NetworkVPC, security groups, WAF
StorageEncryption, access policies, backup
LoggingCloudTrail, SIEM integration
ComplianceConfig rules, automated remediation

For detailed security frameworks (NIST, ISO 27001, CIS Controls, MITRE ATT&CK), see Security Frameworks Reference.

Vulnerability Management

Vulnerability Management Process
LIFECYCLE:

1. DISCOVERY
   - Asset inventory
   - Vulnerability scanning
   - Penetration testing
   - Code analysis

2. PRIORITIZATION
   - CVSS scoring
   - Asset criticality
   - Exploit availability
   - Business context

3. REMEDIATION
   - Patch management
   - Configuration changes
   - Compensating controls
   - Risk acceptance

4. VERIFICATION
   - Rescan
   - Validation testing
   - Documentation
   - Reporting

5. REPORTING
   - Executive dashboards
   - Trend analysis
   - Compliance reporting
   - SLA tracking
CVSS Scoring
ScoreSeveritySLA Target
9.0-10.0Critical7 days
7.0-8.9High30 days
4.0-6.9Medium90 days
0.1-3.9LowBest effort
Patch Management
PATCH PROCESS:

1. IDENTIFICATION
   - Vendor announcements
   - Vulnerability feeds
   - Security bulletins

2. ASSESSMENT
   - Applicability
   - Risk evaluation
   - Test requirements

3. TESTING
   - Lab validation
   - Compatibility testing
   - Rollback planning

4. DEPLOYMENT
   - Pilot group
   - Phased rollout
   - Monitoring

5. VERIFICATION
   - Confirm installation
   - Functional testing
   - Documentation

Identity & Access Management

IAM Framework
IAM COMPONENTS:

IDENTITY LIFECYCLE:
- Provisioning
- Modification
- De-provisioning
- Certification

AUTHENTICATION:
- Password policies
- Multi-factor authentication
- Single sign-on
- Passwordless

AUTHORIZATION:
- Role-based access (RBAC)
- Attribute-based access (ABAC)
- Least privilege
- Separation of duties

GOVERNANCE:
- Access reviews
- Policy enforcement
- Audit logging
- Compliance reporting
Privileged Access Management
PAM CONTROLS:

VAULT:
- Credential storage
- Password rotation
- Secrets management

SESSION:
- Session recording
- Just-in-time access
- Time-limited credentials

MONITORING:
- Activity logging
- Behavioral analytics
- Alert on anomalies

GOVERNANCE:
- Access certification
- Policy enforcement
- Compliance reporting

Security Awareness

Security Training Program
TopicFrequencyAudience
New Hire SecurityOnboardingAll employees
Annual RefreshAnnuallyAll employees
Phishing AwarenessQuarterlyAll employees
Developer SecurityAnnuallyDevelopment team
Executive BriefingsQuarterlyLeadership
Role-BasedAs neededSpecific roles
Phishing Simulation
SIMULATION PROGRAM:

FREQUENCY: Monthly

DIFFICULTY LEVELS:
- Easy: Generic, obvious errors
- Medium: Branded, some personalization
- Hard: Targeted, well-crafted

METRICS:
- Click rate
- Report rate
- Training completion
- Trend over time

RESPONSE:
- Click → Immediate training
- Report → Positive reinforcement
- Repeat offenders → Additional training

Security Metrics

Key Security Metrics
CategoryMetricTarget
VulnerabilityCritical vulns open >30 days0
PatchingSystems patched within SLA95%+
IncidentsMean time to detect<24 hours
AccessOrphan accounts0
TrainingCompletion rate95%+
PhishingClick rate<5%
Security Dashboard
EXECUTIVE DASHBOARD:

RISK POSTURE:
- Overall risk score
- Risk trend
- Top risks

COMPLIANCE:
- Framework coverage
- Audit findings
- Remediation status

OPERATIONS:
- Incident summary
- Vulnerability status
- Patching compliance

INVESTMENT:
- Budget utilization
- Tool effectiveness
- Headcount

Threat Intelligence

Threat Intelligence Sources
TypeSourcesUse
StrategicIndustry reports, geopoliticalExecutive briefings
TacticalTTPs, malware analysisDetection rules
OperationalIOCs, campaignsActive response
TechnicalSignatures, hashesAutomated blocking

For detailed incident response processes and SOC operations, see Incident Response Reference.

Show full SKILL.md (142 more words)Show less

References


OWASP Top 10 (with Code Examples)

1. Broken Access Control
python
# WRONG - No authorization check
@app.get("/api/users/{user_id}/data")
async def get_user_data(user_id: str):
    return db.get_user_data(user_id)  # Any user can access any data

# RIGHT - Verify ownership
@app.get("/api/users/{user_id}/data")
async def get_user_data(user_id: str, current_user: User = Depends(get_current_user)):
    if current_user.id != user_id and not current_user.is_admin:
        raise HTTPException(status_code=403, detail="Forbidden")
    return db.get_user_data(user_id)
2. Cryptographic Failures
python
# WRONG - Weak hashing
import hashlib
password_hash = hashlib.md5(password.encode()).hexdigest()

# RIGHT - Use bcrypt or argon2
from passlib.context import CryptContext
pwd_context = CryptContext(schemes=["bcrypt"], deprecated="auto")
password_hash = pwd_context.hash(password)
verified = pwd_context.verify(password, password_hash)
3. Injection
python
# WRONG - SQL injection via string formatting
query = f"SELECT * FROM users WHERE email = '{email}'"
cursor.execute(query)

# RIGHT - Parameterized queries
cursor.execute("SELECT * FROM users WHERE email = %s", (email,))

# WRONG - Command injection via unsanitized input
# Never pass user input to shell commands directly
# Always use subprocess with list arguments:

# RIGHT - Safe subprocess usage
import subprocess
subprocess.run(["convert", user_filename, "output.png"], check=True)
4. Insecure Design
python
# WRONG - No rate limiting on password reset
@app.post("/api/reset-password")
async def reset_password(email: str):
    send_reset_email(email)

# RIGHT - Rate limit + CAPTCHA
@app.post("/api/reset-password")
@limiter.limit("3/hour")
async def reset_password(email: str, captcha: str):
    if not verify_captcha(captcha):
        raise HTTPException(400, "Invalid CAPTCHA")
    send_reset_email(email)
5. Security Misconfiguration
python
# WRONG - Debug mode in production, exposing stack traces
# RIGHT - Environment-aware configuration
app = FastAPI(debug=os.getenv("ENV") == "development")

@app.exception_handler(Exception)
async def handle_error(request, exc):
    logger.error(f"Unhandled error: {exc}", exc_info=True)
    return JSONResponse(status_code=500, content={"error": "Internal server error"})
6. Vulnerable Components
bash
# Audit dependencies regularly
npm audit
pip audit
cargo audit
# Pin versions, use lockfiles (package-lock.json, Pipfile.lock, Cargo.lock)
7. Authentication Failures
typescript
// WRONG - JWT with no expiration, weak secret
const token = jwt.sign(payload, "secret123");

// RIGHT - Short expiry, strong secret, refresh tokens
const token = jwt.sign(payload, process.env.JWT_SECRET, {
  expiresIn: "15m",
  algorithm: "RS256",
  issuer: "my-app",
});
8. Software and Data Integrity Failures
yaml
# Pin action versions in GitHub Actions (not @main)
- uses: actions/checkout@v4.1.1
9. Security Logging and Monitoring Failures
python
# Log security-relevant events with structured data
logger.info("auth.login.success", extra={"user_id": user.id, "ip": request.client.host})
logger.warning("auth.login.failed", extra={"email": email, "ip": request.client.host})
logger.critical("auth.bruteforce.detected", extra={"ip": request.client.host, "attempts": count})
10. Server-Side Request Forgery (SSRF)
python
# WRONG - User controls URL without validation
# RIGHT - Allowlist domains, block internal IPs
from urllib.parse import urlparse
import ipaddress

ALLOWED_HOSTS = {"api.example.com", "cdn.example.com"}

def safe_fetch(url: str) -> Response:
    parsed = urlparse(url)
    if parsed.hostname not in ALLOWED_HOSTS:
        raise ValueError("Host not allowed")
    ip = ipaddress.ip_address(socket.gethostbyname(parsed.hostname))
    if ip.is_private:
        raise ValueError("Internal addresses not allowed")
    return requests.get(url, timeout=10)

Static Application Security Testing (SAST)

ToolLanguagesIntegration
Semgrep30+ languagesCI/CD, IDE, CLI
CodeQLC/C++, Java, JS, Python, GoGitHub Actions
SonarQube30+ languagesSelf-hosted, CI/CD
BanditPython onlyCLI, CI/CD
bash
# Semgrep (recommended - fast, customizable)
semgrep scan --config auto .
semgrep scan --config p/owasp-top-ten .
semgrep scan --config p/secrets .

Dynamic Application Security Testing (DAST)

bash
# OWASP ZAP baseline scan (passive, fast)
docker run -t ghcr.io/zaproxy/zaproxy:stable zap-baseline.py \
  -t https://your-app.com

# Full scan (active, thorough)
docker run -t ghcr.io/zaproxy/zaproxy:stable zap-full-scan.py \
  -t https://your-app.com

# API scan
docker run -t ghcr.io/zaproxy/zaproxy:stable zap-api-scan.py \
  -t https://your-app.com/openapi.json -f openapi

Supply Chain Security

Sigstore (Code Signing)
bash
# Sign container images with cosign
cosign sign --key cosign.key docker.io/myapp:latest

# Verify signatures
cosign verify --key cosign.pub docker.io/myapp:latest
SLSA (Supply-chain Levels for Software Artifacts)
LevelRequirements
SLSA 1Build process documented
SLSA 2Hosted build service, signed provenance
SLSA 3Hardened build platform, non-falsifiable provenance
Dependency Management
bash
# Lock dependencies and audit regularly
npm ci                    # Install from lockfile only
npm audit --audit-level=high
pip-audit
cargo audit
# Use Dependabot or Renovate for automated updates

See Also

© travisjneuman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/security of travisjneuman/.claude.

  • SKILL.md
  • references/fortune50-information-security.md
  • references/incident-response.md
  • references/security-frameworks.md

Open the folder on GitHubat commit 139c07b

Compare with similar skills

Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security this skilltravisjneuman/.claude101—~3.3kAutomated safety check: PassMIT
Find Cybersecurity Firmjeremylongshore/tons-of-skills-marketplace2.8k—~3.7kAutomated safety check: NotesMIT
Security Auditoraiskillstore/marketplace4306 repos~2.6kAutomated safety check: PassNone
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
DefectDojo Vulnerability ManagementAgentSecOps/SecOpsAgentKit220—~2.3kAutomated safety check: PassCustom licence
Security Setupluongnv89/skills131—~4.5kAutomated safety check: PassMIT

Similar skills

  • Find Cybersecurity Firm

    jeremylongshore/tons-of-skills-marketplace

    A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed…

    2.8k GitHub stars~3.7k tokensUpdated today
    SecurityAuto-check: notes
  • Security Auditor

    aiskillstore/marketplace

    Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.

    430 GitHub starsUsed in 6 repos~2.6k tokens
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • DefectDojo Vulnerability Management

    AgentSecOps/SecOpsAgentKit

    Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

    220 GitHub stars~2.3k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Security Setup

    luongnv89/skills

    Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.

    131 GitHub stars~4.5k tokensUpdated today
    SecurityAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    104 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed

More from travisjneuman/.claude

All 21 skills in this repo
  • Test Specialist

    travisjneuman/.claude

    Test-writing patterns for JS/TS, Python, Go, and Rust (unit, integration, E2E, visual regression).

    101 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Codebase Documenter

    travisjneuman/.claude

    Write codebase documentation: READMEs, architecture docs, getting-started guides, API docs, and code comments.

    101 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Business Strategy

    travisjneuman/.claude

    Business strategy expertise for strategic planning, competitive analysis, market entry, M&A strategy, portfolio management, and strategic decision-making.

    101 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed
  • Data Science

    travisjneuman/.claude

    Data science and analytics expertise for statistical analysis, machine learning pipelines, data governance, business intelligence, predictive modeling, and analytics strategy.

    101 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Finance

    travisjneuman/.claude

    Financial analysis expertise for financial modeling (DCF, LBO, M&A), valuation, financial statement analysis, capital allocation, treasury management, and corporate finance decisions.

    101 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed
  • Health Wellness

    travisjneuman/.claude

    Workplace health and wellness expertise for employee wellness programs, mental health initiatives, ergonomics and safety, healthcare benefits strategy, and health analytics.

    101 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Security

What does Security do?

Information security expertise for cybersecurity frameworks (NIST, ISO 27001), security architecture, incident response, vulnerability management, identity management, and cloud security. claude. Information security expertise for cybersecurity frameworks (NIST, ISO 27001), security architecture, incident response, vulnerability management, identity management, and cloud security.

When should I use Security?

Security fits situations like: designing security programs; responding to incidents; assessing vulnerabilities.

How do I install Security in Claude Code?

Run `npx skills add travisjneuman/.claude --skill security -a claude-code`. Or copy the skill folder (skills/security in travisjneuman/.claude) into .claude/skills/security in your project. Claude Code loads it when a task matches its description.

How do I install Security in Codex?

Run `npx skills add travisjneuman/.claude --skill security -a codex`. Or copy the skill folder (skills/security in travisjneuman/.claude) into .agents/skills/security in your project. Codex loads it when a task matches its description.

Can I use Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add travisjneuman/.claude --skill security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security, .gemini/skills/security, .github/skills/security and .opencode/skills/security in your project.

What does Security need to run?

Going by SKILL.md and its folder, Security needs the command-line tools its instructions call (npm, semgrep, docker, cargo and pip) and credentials named JWT_SECRET. Our summary lists: Python 3; Docker; A credential in JWT_SECRET.

Does Security access the network?

SKILL.md contains no URLs. Its commands use npm, docker and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security use?

Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 19k tokens, read only when the agent opens those files.

What are the alternatives to Security?

Skills that share tags, products or a category with Security: Find Cybersecurity Firm (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Security Auditor (aiskillstore/marketplace, 430 stars), Forensify (alexgreensh/repo-forensics, 188 stars) and DefectDojo Vulnerability Management (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security?

travisjneuman (a GitHub user) maintains it in travisjneuman/.claude, which has 101 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 6, 2026.

Source: travisjneuman/.claude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.