Agent skill

Security

by vibeeval in vibeeval/vibecosystem

Security audit workflow - OWASP Top 10, input validation, auth, secret detection, vulnerability scan

MITAuto-check passedSecurity

Install Security

skills CLI
$ npx skills add vibeeval/vibecosystem --skill security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vibeeval/vibecosystem security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security .claude/skills/security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security
GitHub stars
531
Token cost
~807 tokens
SKILL.md length
193 words
Files
1
Skills in repo
144
Repo updated
First seen
Licence
MIT

At a glance

Security audit workflow - OWASP Top 10, input validation, auth, secret detection, vulnerability scan

  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers OWASP Top 10 (2021) Checklist, Input Validation, Auth Best Practices and Secret Detection, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Security review

What it does

Security is an agent skill from vibeeval/vibecosystem. Security audit workflow - OWASP Top 10, input validation, auth, secret detection, vulnerability scan

Its SKILL.md is about 810 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities, Security review and Penetration testing. The repository describes itself as: AI software team for Claude Code - 138 agents, 295 skills, 73 hooks. Self-learning, multi-agent swarm, autonomous skill evolution. The licence is MIT.

When your agent uses it

  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Security review
  • Tasks that involve Penetration testing

Example prompts

  • “/security”

What it can do on your machine

Read from SKILL.md and the folder at commit 3b763b1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security loads about 807 tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 193 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~27
When it runs · the whole SKILL.md, loaded when a task matches
~807

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vibeeval/vibecosystem at commit 3b763b1, republished under its MIT licence (© vibeeval). 193 words, ~807 tokens.

Download SKILL.mdSave it as .claude/skills/security/SKILL.md (or your agent's skills folder).
name
security
description
Security audit workflow - OWASP Top 10, input validation, auth, secret detection, vulnerability scan

Security Patterns

OWASP Top 10 (2021) Checklist

#VulnerabilityPrevention
A01Broken Access ControlRBAC, resource-level auth, CORS
A02Cryptographic FailuresEncrypt at rest/transit, no PII in logs
A03Injection (SQL/NoSQL/XSS/OS)Parameterized queries, output encoding, CSP
A04Insecure DesignThreat modeling, secure design patterns
A05Security MisconfigurationHardened defaults, no debug in prod
A06Vulnerable Componentsnpm audit, dependency scan, CVE tracking
A07Auth FailuresRate limiting, MFA, secure session
A08Data Integrity FailuresInput validation, signed updates, CI/CD security
A09Logging & Monitoring FailuresAudit log, alert on anomaly
A10SSRFURL allowlist, network segmentation

Input Validation

typescript
import { z } from 'zod';

const UserInput = z.object({
  email: z.string().email().max(255),
  name: z.string().min(1).max(100).regex(/^[\w\s-]+$/),
  age: z.number().int().min(0).max(150),
});

// Parameterized query (SQL injection prevention)
const user = await db.query('SELECT * FROM users WHERE id = $1', [userId]);

Auth Best Practices

typescript
// Password hashing
import bcrypt from 'bcryptjs';
const hash = await bcrypt.hash(password, 12);
const valid = await bcrypt.compare(password, hash);

// JWT with expiry
const token = jwt.sign({ userId: user.id, role: user.role }, secret, { expiresIn: '24h' });

// Rate limiting on auth endpoints
const authLimiter = rateLimit({ windowMs: 15 * 60 * 1000, max: 5 });
app.use('/api/auth', authLimiter);

Secret Detection

bash
# Git hooks ile secret engelleme
grep -rn "sk-\|pk_\|ghp_\|xoxb-\|AKIA" --include="*.ts" --include="*.js" src/
grep -rn "password\s*=\s*['\"]" --include="*.ts" src/

Security Headers

typescript
import helmet from 'helmet';
app.use(helmet());
// Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, etc.

Anti-Patterns

Anti-PatternCozum
Hardcoded secretsEnvironment variables
SQL string concatParameterized queries
No CORS configWhitelist origins
Debug mode in prodNODE_ENV check
No rate limitingexpress-rate-limit

Pentest Methodology (Overview)

Detayli rehber icin: pentest-methodology skill

5-faz pipeline: Recon > Vuln Analysis > Exploitation > Verification > Report

Proof Levels
LevelTanim
L1 - TheoreticalPotansiyel risk, exploit edilmemis
L2 - DemonstratedBypass/leak gosterildi
L3 - ExploitedTam exploit, veri erisimi
L4 - ChainedBirden fazla vuln zincirlendi
Source-to-Sink Taint Tracing

Kullanici input'unun (source) tehlikeli fonksiyona (sink) ulasip ulasamadigini kontrol et:

Source: req.body, req.query, req.params, req.headers, cookies
Sink: db.query(), eval(), exec(), res.redirect(), innerHTML

Kontrol: Source ile Sink arasinda sanitizasyon/validasyon var mi?

Bu yaklasimi her code review'da auth/data islerinde kullan.

© vibeeval, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security of vibeeval/vibecosystem.

Open the folder on GitHubat commit 3b763b1

Compare with similar skills

Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security this skillvibeeval/vibecosystem531—~807Automated safety check: PassMIT
Strix Code Vulnerability Scanusestrix/strix67k—~1.1kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Code Security AuditProgrammerAnthony/Expert-Coding-Harness235—~1.6kAutomated safety check: PassMIT
Security ReviewerAratKruglik/claude-laravel1551 repos~1.1kAutomated safety check: NotesNone

Similar skills

  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    67k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Code Security Audit

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…

    235 GitHub stars~1.6k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Security Reviewer

    AratKruglik/claude-laravel

    A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.

    155 GitHub starsUsed in 1 repo~1.1k tokens
    SecurityAuto-check: notes
  • Cso

    no-session/pstack

    Chief Security Officer mode. An agent skill from no-session/pstack.

    131 GitHub stars~12k tokensUpdated 6 mo ago
    SecurityAuto-check: notes

More from vibeeval/vibecosystem

All 144 skills in this repo
  • Agent Benchmark

    vibeeval/vibecosystem

    Framework for measuring and tracking agent response quality over time.

    531 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Differential Review

    vibeeval/vibecosystem

    Security-focused differential code review with blast radius analysis, risk-adaptive depth (DEEP/FOCUSED/SURGICAL), git history correlation, and structured finding format.

    531 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Factcheck Guard

    vibeeval/vibecosystem

    A skill your agent uses when making any factual claim about the codebase — existence, absence, or behavior.

    531 GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Fp Check

    vibeeval/vibecosystem

    Systematic false positive verification for security findings.

    531 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • N8n Workflows

    vibeeval/vibecosystem

    n8n otomasyon workflow'lari. An agent skill from vibeeval/vibecosystem.

    531 GitHub stars~3.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Notepad System

    vibeeval/vibecosystem

    A skill your agent uses when context compression is imminent, when resuming a session, or when preserving critical decisions across long tasks.

    531 GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Security

What does Security do?

Security audit workflow - OWASP Top 10, input validation, auth, secret detection, vulnerability scan. Security is an agent skill from vibeeval/vibecosystem.

When should I use Security?

Security fits situations like: tasks that involve Web application vulnerabilities; tasks that involve Security review; tasks that involve Penetration testing.

How do I install Security in Claude Code?

Run `npx skills add vibeeval/vibecosystem --skill security -a claude-code`. Or copy the skill folder (skills/security in vibeeval/vibecosystem) into .claude/skills/security in your project. Claude Code loads it when a task matches its description.

How do I install Security in Codex?

Run `npx skills add vibeeval/vibecosystem --skill security -a codex`. Or copy the skill folder (skills/security in vibeeval/vibecosystem) into .agents/skills/security in your project. Codex loads it when a task matches its description.

Can I use Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vibeeval/vibecosystem --skill security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security, .gemini/skills/security, .github/skills/security and .opencode/skills/security in your project.

What does Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Security is instructions for the agent only.

Does Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security use?

Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security use?

About 807 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security?

Skills that share tags, products or a category with Security: Strix Code Vulnerability Scan (usestrix/strix, 67k stars), Code Audit (3stoneBrother/code-audit, 893 stars), Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars) and Code Security Audit (ProgrammerAnthony/Expert-Coding-Harness, 235 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security?

vibeeval (a GitHub user) maintains it in vibeeval/vibecosystem, which has 531 GitHub stars. The repository holds 144 skills in this directory. The repository was last updated on August 8, 2026.

Source: vibeeval/vibecosystem on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.