Agent skill

Vc Security

by withkynam in withkynam/vibecode-pro-max-kit

STRIDE + OWASP-based security audit with optional auto-fix. An agent skill from withkynam/vibecode-pro-max-kit.

MITAuto-check passedSecurity

Install Vc Security

skills CLI
$ npx skills add withkynam/vibecode-pro-max-kit --skill vc-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install withkynam/vibecode-pro-max-kit vc-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/withkynam/vibecode-pro-max-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/vc-security .claude/skills/vc-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vc-security
GitHub stars
1.1k
Token cost
~1.2k tokens
SKILL.md length
445 words
Files
4 (incl. references)
Skills in repo
32
Repo updated
First seen
Licence
MIT

At a glance

STRIDE + OWASP-based security audit with optional auto-fix. An agent skill from withkynam/vibecode-pro-max-kit.

  • Works in 6 steps: Scope Resolution → STRIDE Analysis → OWASP Top 10 Check → …
  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers When to Use, When NOT to Use, Modes and Audit Methodology, plus 5 more sections
  • Calls pnpm and bundle

What it does

Vc Security is an agent skill from withkynam/vibecode-pro-max-kit. STRIDE + OWASP-based security audit with optional auto-fix. Scans code for vulnerabilities, categorizes by severity, and can iteratively fix findings using vc-autoresearch pattern.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/secret-patterns.md`, `references/stride-owasp-checklist.md` and `references/vulnerability-patterns.md`).

It sits in Security, covering Web application vulnerabilities, Threat modeling and Security review. The repository describes itself as: Your AI forgets. This remembers. Spec-driven coding harness for vibecoders, product owners, CEOs and real builders — self-improving context memory, 15 agents, 33 skills working…. The licence is MIT.

When your agent uses it

  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Threat modeling
  • Tasks that involve Security review

Example prompts

  • “/vc-security”

Requirements

  • Node.js

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Scope Resolution
  2. STRIDE Analysis
  3. OWASP Top 10 Check
  4. Dependency Audit
  5. Secret Detection
  6. Finding Categorization

What it can do on your machine

Read from SKILL.md and the folder at commit 3bcb2f9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • bundle

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vc Security loads about 1.2k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 48 tokens; SKILL.md has 445 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from withkynam/vibecode-pro-max-kit at commit 3bcb2f9, republished under its MIT licence (© withkynam). 445 words, ~1,241 tokens.

Download SKILL.mdSave it as .claude/skills/vc-security/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
vc-security
description
STRIDE + OWASP-based security audit with optional auto-fix. Scans code for vulnerabilities, categorizes by severity, and can iteratively fix findings using vc-autoresearch pattern.
argument-hint
<scope glob or 'full'> [--fix] [--iterations N]
trigger_keywords
security, vulnerability, auth, XSS, SQL injection
layer
helper
metadata.author
claudekit
metadata.attribution
Security audit pattern adapted from autoresearch by Udit Goenka (MIT)
metadata.license
MIT
metadata.version
1.0.0

vc-security — Security Audit

Output style: Follow process/development-protocols/communication-standards.md — answer-first, plain language, no unexplained jargon, TL;DR on long responses.

Runs a structured STRIDE + OWASP security audit on a given scope. Produces a severity-ranked findings report. With --fix, applies fixes iteratively using the vc-autoresearch guard pattern.

When to Use

  • Before a release or major deployment
  • After adding auth, payment, or data-handling features
  • Periodic security review (monthly/quarterly)
  • Compliance check (SOC 2, GDPR, PCI-DSS prep)

When NOT to Use

  • Purely cosmetic changes (CSS, copy edits)
  • No user-facing code or data handling involved

Modes

ModeInvocationBehavior
Audit only/vc-security <scope>Scan → categorize → report
Audit + Fix/vc-security <scope> --fixScan → categorize → fix iteratively
Bounded fix/vc-security <scope> --fix --iterations NLimit fix iterations to N

Audit Methodology

1. Scope Resolution

Expand the provided glob or full keyword into a file list. Read all in-scope files before analysis.

2. STRIDE Analysis

Evaluate each threat category systematically:

  • Spoofing — identity/authentication weaknesses
  • Tampering — input validation, integrity controls
  • Repudiation — audit logging gaps
  • Information Disclosure — data leakage, secret exposure
  • Denial of Service — rate limits, resource exhaustion
  • Elevation of Privilege — broken access control, RBAC gaps
3. OWASP Top 10 Check

Map findings to OWASP categories (A01–A10). See references/stride-owasp-checklist.md for per-category checks.

4. Dependency Audit

Run the appropriate package audit tool for the detected stack:

  • Node.js: pnpm audit
  • Python: pip-audit
  • Go: govulncheck
  • Ruby: bundle audit
5. Secret Detection

Scan for hardcoded API keys, passwords, tokens, and private keys using regex patterns. See references/stride-owasp-checklist.md → Secret Patterns.

6. Finding Categorization

Assign each finding a severity level (see Severity Definitions below).


Output Format

## Security Audit Report

### Summary
- Files scanned: N
- Findings: X critical, Y high, Z medium, W low, V info

### Findings

| # | Severity | Category | File:Line | Description | Fix Recommendation |
|---|----------|----------|-----------|-------------|-------------------|
| 1 | Critical  | Injection | api/users.ts:45 | SQL string concatenation | Use parameterized queries |
| 2 | High      | Auth      | auth/login.ts:12 | No rate limiting | Add express-rate-limit |

Show full SKILL.md (189 more words)Show less

Fix Mode (--fix)

When --fix is provided, apply fixes iteratively after the audit:

  1. Sort all findings by severity (Critical → High → Medium → Low)
  2. For each finding: a. Apply one targeted fix b. Run guard (tests or lint) to verify no regression c. Commit: security(fix-N): <short description> d. Advance to next finding
  3. Stop early if guard fails — report the failure instead of proceeding
  4. Uses vc-autoresearch guard pattern for regression prevention

Tip: Use --iterations N to cap total fix iterations when scope is large.


Severity Definitions

SeverityDescriptionFix Priority
CriticalExploitable now, data breach or RCE riskImmediate — block release
HighExploitable with moderate effort, significant impactThis sprint
MediumLimited exploitability or impactNext sprint
LowTheoretical risk, defense-in-depth improvementBacklog
InfoBest practice suggestion, no direct riskOptional

Integration with Other Skills

  • Run after vc-predict when the security persona flags concerns
  • Feed Critical/High findings into vc-autoresearch --fix for automated remediation
  • Use vc-scenario with --focus authorization for deeper auth flow testing
  • Pair with generate-plan / plan-agent to schedule Medium/Low findings as sprint tasks

Example Invocations

bash
# Audit API layer only
/vc-security src/api/**/*.ts

# Audit entire src/ and auto-fix, max 15 iterations
/vc-security src/ --fix --iterations 15

# Full codebase audit (no fix)
/vc-security full

See references/stride-owasp-checklist.md for the detailed per-category checklist and secret detection regex patterns.

© withkynam, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in .claude/skills/vc-security of withkynam/vibecode-pro-max-kit.

  • SKILL.md
  • references/secret-patterns.md
  • references/stride-owasp-checklist.md
  • references/vulnerability-patterns.md

Open the folder on GitHubat commit 3bcb2f9

Compare with similar skills

Vc Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vc Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vc Security this skillwithkynam/vibecode-pro-max-kit1.1k—~1.2kAutomated safety check: PassMIT
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
CybersecurityAgriciDaniel/claude-cybersecurity227—~11kAutomated safety check: WarnMIT
Securitygaragon/nanostack207—~3.7kAutomated safety check: NotesApache-2.0
Csono-session/pstack131—~12kAutomated safety check: NotesMIT
007sickn33/agentic-awesome-skills47k2 repos~410Automated safety check: PassMIT

Similar skills

  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Cybersecurity

    AgriciDaniel/claude-cybersecurity

    Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.

    227 GitHub stars~11k tokensUpdated 5 mo ago
    SecurityAuto-check: warnings
  • Security

    garagon/nanostack

    Use before shipping to production. An agent skill from garagon/nanostack.

    207 GitHub stars~3.7k tokensUpdated 27 days ago
    SecurityAuto-check: notes
  • Cso

    no-session/pstack

    Chief Security Officer mode. An agent skill from no-session/pstack.

    131 GitHub stars~12k tokensUpdated 6 mo ago
    SecurityAuto-check: notes
  • 007

    sickn33/agentic-awesome-skills

    Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

    47k GitHub starsUsed in 2 repos~410 tokens
    SecurityAuto-check passed
  • Security Audit

    fossasia/eventyay-interpretation

    A skill your agent uses for security reviews of VoxBento code.

    1.6k GitHub stars~1.3k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from withkynam/vibecode-pro-max-kit

All 32 skills in this repo
  • Library Documentation Seeker

    withkynam/vibecode-pro-max-kit

    Looks up library and framework documentation through Context7 first, with bundled Node scripts as a fallback that fetch and analyze llms.txt files.

    1.1k GitHub starsUsed in 2 repos~1k tokens
    Auto-check: notes
  • Vc Sequential Thinking

    withkynam/vibecode-pro-max-kit

    Apply step-by-step analysis for complex problems with revision capability.

    1.1k GitHub starsUsed in 2 repos~854 tokens
    Auto-check passed
  • Agent Browser Automation

    withkynam/vibecode-pro-max-kit

    Drives a browser through the agent-browser CLI, using compact snapshots with element refs to keep context small in long sessions, plus video recording and cloud browsers.

    1.1k GitHub stars~2.6k tokensUpdated 3 mo ago
    Auto-check passed
  • Context Routing Audit

    withkynam/vibecode-pro-max-kit

    Audits a project's context routing, skill discoverability and skill wiring by running a chain of validator scripts and fixing whatever they report.

    1.1k GitHub stars~1.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Active Plan Audit

    withkynam/vibecode-pro-max-kit

    Reviews a codebase's active plan files for staleness and completion, then archives only the ones confirmed done or obsolete against the real code.

    1.1k GitHub stars~757 tokensUpdated 3 mo ago
    Auto-check passed
  • Systematic Debugging and Investigation

    withkynam/vibecode-pro-max-kit

    Forces root-cause investigation before any fix, combining a four-phase debugging method with log, CI and performance investigation techniques and a rule against unverified completion claims.

    1.1k GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Vc Security

What does Vc Security do?

STRIDE + OWASP-based security audit with optional auto-fix. An agent skill from withkynam/vibecode-pro-max-kit. Vc Security is an agent skill from withkynam/vibecode-pro-max-kit. STRIDE + OWASP-based security audit with optional auto-fix.

When should I use Vc Security?

Vc Security fits situations like: tasks that involve Web application vulnerabilities; tasks that involve Threat modeling; tasks that involve Security review.

How do I install Vc Security in Claude Code?

Run `npx skills add withkynam/vibecode-pro-max-kit --skill vc-security -a claude-code`. Or copy the skill folder (.claude/skills/vc-security in withkynam/vibecode-pro-max-kit) into .claude/skills/vc-security in your project. Claude Code loads it when a task matches its description.

How do I install Vc Security in Codex?

Run `npx skills add withkynam/vibecode-pro-max-kit --skill vc-security -a codex`. Or copy the skill folder (.claude/skills/vc-security in withkynam/vibecode-pro-max-kit) into .agents/skills/vc-security in your project. Codex loads it when a task matches its description.

Can I use Vc Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add withkynam/vibecode-pro-max-kit --skill vc-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vc-security, .gemini/skills/vc-security, .github/skills/vc-security and .opencode/skills/vc-security in your project.

What does Vc Security need to run?

Going by SKILL.md and its folder, Vc Security needs the command-line tools its instructions call (pnpm and bundle). Our summary lists: Node.js.

Does Vc Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vc Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vc Security use?

Vc Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vc Security use?

About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Vc Security?

Skills that share tags, products or a category with Vc Security: Security Audit Scanner (ruvnet/ruflo, 74k stars), Cybersecurity (AgriciDaniel/claude-cybersecurity, 227 stars), Security (garagon/nanostack, 207 stars) and Cso (no-session/pstack, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vc Security?

withkynam (a GitHub user) maintains it in withkynam/vibecode-pro-max-kit, which has 1,144 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on June 21, 2026.

Source: withkynam/vibecode-pro-max-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.