Agent skill

Warden Security Review

by UsefulSoftwareCo in UsefulSoftwareCo/executor

Run Warden security scans in this repo using Sentry's warden-skills.

MITAuto-check passedSecurity

Install Warden Security Review

skills CLI
$ npx skills add UsefulSoftwareCo/executor --skill warden-security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install UsefulSoftwareCo/executor warden-security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/UsefulSoftwareCo/executor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.skills/warden-security-review .claude/skills/warden-security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
warden-security-review
GitHub stars
4.1k
Token cost
~1.3k tokens
SKILL.md length
289 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
MIT

At a glance

Run Warden security scans in this repo using Sentry's warden-skills.

  • Asked to audit security
  • SKILL.md covers Setup, Local Outputs, Recommended Scans and How to Triage, plus 1 more section
  • Calls npm, rg and claude
  • Scan with Warden

What it does

Warden Security Review is an agent skill from UsefulSoftwareCo/executor. Run Warden security scans in this repo using Sentry's warden-skills. Use when asked to audit security, scan with Warden, investigate authz/data-exfil/code-execution/GitHub Actions risks, or triage Warden findings.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review and Authorization and RBAC. It works with GitHub Actions and Sentry. The repository describes itself as: The missing integration layer for AI agents. Let them call any OpenAPI / MCP / GraphQL / custom js functions in secure environment. The licence is MIT.

When your agent uses it

  • Asked to audit security
  • Scan with Warden
  • Investigate authz/data-exfil/code-execution/GitHub Actions risks
  • Triage Warden findings

Example prompts

  • “/warden-security-review”

What it can do on your machine

Read from SKILL.md and the folder at commit 9ef04e9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • rg
    • claude

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Warden Security Review loads about 1.3k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 289 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from UsefulSoftwareCo/executor at commit 9ef04e9, republished under its MIT licence (© UsefulSoftwareCo). 289 words, ~1,269 tokens.

Download SKILL.mdSave it as .claude/skills/warden-security-review/SKILL.md (or your agent's skills folder).
name
warden-security-review
description
Run Warden security scans in this repo using Sentry's warden-skills. Use when asked to audit security, scan with Warden, investigate authz/data-exfil/code-execution/GitHub Actions risks, or triage Warden findings.

Warden security review runbook

Use Warden as a first-pass scanner, then manually verify every finding against the code. A clean Warden run means "no findings from that skill/pass", not "the codebase is secure."

Setup

Warden uses Claude Code auth locally. For Claude Max usage:

bash
claude login

Run Warden through npm so the package version does not need to be committed:

bash
npm exec --yes --package=@sentry/warden -- warden --help

The repo has a warden.toml that uses remote skills from getsentry/warden-skills.

Reference skills are mirrored under .reference/warden-skills when needed. .reference/ is gitignored.

Local Outputs

Write run artifacts under .warden-runs/. Do not commit .warden/ or .warden-runs/.

Use JSONL output for later triage:

bash
mkdir -p .warden-runs
npm exec --yes --package=@sentry/warden -- \
  warden <targets...> --skill <skill> --fail-on off --report-on low --min-confidence low \
  --parallel 2 --log -o .warden-runs/<name>.jsonl

Warden may not treat bare directories as recursive targets. Prefer explicit quoted globs or a target file list.

Authz on cloud/API surfaces:

bash
npm exec --yes --package=@sentry/warden -- \
  warden "apps/cloud/src/auth/**/*.ts" "apps/cloud/src/api/**/*.ts" \
  "apps/cloud/src/routes/**/*.tsx" "packages/core/api/src/**/*.ts" \
  --skill wrdn-authz --fail-on off --report-on low --min-confidence low \
  --parallel 2 --log -o .warden-runs/authz.jsonl

Code execution on sink-bearing runtime/plugin files:

bash
rg -l "\b(exec|spawn|execFile|fork|subprocess|Deno\.Command|new Function|eval\(|vm\.|QuickJS|quickjs|Worker\(|import\(|compile|instantiate|runIn|shell|command|child_process)\b" \
  apps/local/src/server apps/cli/src packages/core/execution/src packages/core/sdk/src packages/kernel packages/plugins \
  -g "*.ts" -g "*.tsx" -g "!*.test.ts" -g "!*.spec.ts" -g "!*.e2e.ts" -g "!**/dist/**" -g "!**/node_modules/**" \
  > .warden-runs/code-execution-targets.txt

npm exec --yes --package=@sentry/warden -- \
  warden $(tr '\n' ' ' < .warden-runs/code-execution-targets.txt) \
  --skill wrdn-code-execution --fail-on off --report-on low --min-confidence low \
  --parallel 2 --log -o .warden-runs/code-execution.jsonl

Data exfiltration on backend/API/storage/plugin SDK surfaces:

bash
find apps/cloud/src/api apps/cloud/src/auth apps/local/src/server \
  packages/core/api/src packages/core/storage-core/src packages/core/storage-file/src \
  packages/core/storage-postgres/src packages/core/storage-drizzle/src \
  packages/plugins/mcp/src packages/plugins/openapi/src packages/plugins/graphql/src \
  packages/plugins/google-discovery/src packages/plugins/oauth2/src \
  packages/plugins/onepassword/src packages/plugins/workos-vault/src \
  packages/plugins/file-secrets/src packages/plugins/keychain/src \
  -type f \( -name "*.ts" -o -name "*.tsx" \) |
  rg -v '(\.test\.|\.spec\.|\.e2e\.|dist/|node_modules/|embedded-migrations\.gen\.ts|/react/)' \
  > .warden-runs/exfil-targets-focused.txt

npm exec --yes --package=@sentry/warden -- \
  warden $(tr '\n' ' ' < .warden-runs/exfil-targets-focused.txt) \
  --skill wrdn-data-exfil --fail-on off --report-on low --min-confidence low \
  --parallel 2 --log -o .warden-runs/data-exfil.jsonl

GitHub Actions workflow risks:

bash
find .github -type f \( -name "*.yml" -o -name "*.yaml" \) > .warden-runs/gha-targets.txt

npm exec --yes --package=@sentry/warden -- \
  warden $(tr '\n' ' ' < .warden-runs/gha-targets.txt) \
  --skill wrdn-gha-workflows --fail-on off --report-on low --min-confidence low \
  --parallel 2 --log -o .warden-runs/gha-workflows.jsonl

How to Triage

Deduplicate findings by root cause. Warden often reports the same bug at the low-level sink, wrapper, API handler, and plugin-tool entrypoint.

For each candidate:

  • Trace whether input is user-controlled.
  • Identify the exact sink.
  • Check whether auth, scope, host allowlists, private-IP blocks, redirects, and DNS rebinding defenses exist.
  • Determine what data returns to the caller: raw body, parsed fields, typed error message, timing/status oracle, or no observable data.
  • State confidence and deployment caveats.

Current Known Findings

As of the Warden pass on 2026-04-29:

  • Real: authenticated SSRF in plugin/source setup URL fetching for OpenAPI, Google Discovery, GraphQL, and MCP remote endpoints.
  • Real: mutable third-party GitHub Actions refs in publish/release workflows, especially oven-sh/setup-bun@v2 and changesets/action@v1.
  • Clean in that pass: authz scan on cloud auth/API/core API surfaces; code-execution scan on narrowed CLI/runtime/kernel/plugin sink files.

Do not claim the whole codebase is secure from those clean runs. They are scoped scanner results.

© UsefulSoftwareCo, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .skills/warden-security-review of UsefulSoftwareCo/executor.

Open the folder on GitHubat commit 9ef04e9

Compare with similar skills

Warden Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Warden Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Warden Security Review this skillUsefulSoftwareCo/executor4.1k—~1.3kAutomated safety check: PassMIT
Sentry Securitygetsentry/sentry46k—~2.3kAutomated safety check: NotesCustom licence
Agentic GitHub Actions Auditortrailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0
Vercel Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: NotesMIT
Secure GitHub Actionsvechain/x-app-template450—~1.2kAutomated safety check: PassMIT
Absolute Auditmaddhruv/absolute2181 repos~1.2kAutomated safety check: PassMIT

Similar skills

  • Sentry Security

    getsentry/sentry

    Official

    Sentry-specific security review based on real vulnerability history.

    46k GitHub stars~2.3k tokensUpdated today
    SecurityAuto-check: notes
  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.4k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • Vercel Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Apply Vercel security best practices for secrets, headers, and access control.

    2.8k GitHub stars~1.9k tokensUpdated today
    SecurityAuto-check: notes
  • Secure GitHub Actions

    vechain/x-app-template

    Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.

    450 GitHub stars~1.2k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Absolute Audit

    maddhruv/absolute

    Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without…

    218 GitHub starsUsed in 1 repo~1.2k tokens
    SecurityAuto-check passed
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    322 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from UsefulSoftwareCo/executor

All 21 skills in this repo
  • Effect Client Wrapper

    UsefulSoftwareCo/executor

    Pattern for wrapping third-party SDK clients (Stripe, Resend, AWS, etc.) with Effect.

    4.1k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • CLI Release

    UsefulSoftwareCo/executor

    Runbook for releasing the executor CLI package (stable and beta).

    4.1k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Effect Atom Optimistic Updates

    UsefulSoftwareCo/executor

    Pattern for implementing optimistic UI updates with effect-atom in this codebase.

    4.1k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Effect HTTP Testing

    UsefulSoftwareCo/executor

    Testing Effect HttpApi services end-to-end. An agent skill from UsefulSoftwareCo/executor.

    4.1k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Emulate

    UsefulSoftwareCo/executor

    Use the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a…

    4.1k GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • Prod Telemetry

    UsefulSoftwareCo/executor

    Query Executor's production telemetry — Axiom traces (executor-cloud dataset), prod Postgres via PlanetScale, PostHog product analytics — through the Executor MCP.

    4.1k GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Questions about Warden Security Review

What does Warden Security Review do?

Run Warden security scans in this repo using Sentry's warden-skills. Warden Security Review is an agent skill from UsefulSoftwareCo/executor. Run Warden security scans in this repo using Sentry's warden-skills.

When should I use Warden Security Review?

Warden Security Review fits situations like: asked to audit security; scan with Warden; investigate authz/data-exfil/code-execution/GitHub Actions risks; triage Warden findings.

How do I install Warden Security Review in Claude Code?

Run `npx skills add UsefulSoftwareCo/executor --skill warden-security-review -a claude-code`. Or copy the skill folder (.skills/warden-security-review in UsefulSoftwareCo/executor) into .claude/skills/warden-security-review in your project. Claude Code loads it when a task matches its description.

How do I install Warden Security Review in Codex?

Run `npx skills add UsefulSoftwareCo/executor --skill warden-security-review -a codex`. Or copy the skill folder (.skills/warden-security-review in UsefulSoftwareCo/executor) into .agents/skills/warden-security-review in your project. Codex loads it when a task matches its description.

Can I use Warden Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add UsefulSoftwareCo/executor --skill warden-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/warden-security-review, .gemini/skills/warden-security-review, .github/skills/warden-security-review and .opencode/skills/warden-security-review in your project.

What does Warden Security Review need to run?

Going by SKILL.md and its folder, Warden Security Review needs the command-line tools its instructions call (npm, rg and claude).

Does Warden Security Review access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Warden Security Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Warden Security Review use?

Warden Security Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Warden Security Review use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Warden Security Review?

Skills that share tags, products or a category with Warden Security Review: Sentry Security (getsentry/sentry, 46k stars), Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars), Vercel Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Secure GitHub Actions (vechain/x-app-template, 450 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Warden Security Review?

UsefulSoftwareCo (a GitHub organization) maintains it in UsefulSoftwareCo/executor, which has 4,111 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 9, 2026.

Source: UsefulSoftwareCo/executor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.