security
Run repository security scans for vulnerabilities, dependency risk, secrets, and release gates.
What this skill does
# Security Skill > **Purpose:** Run repeatable security checks across code, scripts, hooks, and release gates, plus composable binary/internal-testing primitives and offline repo-surface redteam for authorized targets. Use this skill when you need deterministic security validation before merge/release, recurring scheduled checks, binary black-box assurance, or offline prompt-surface redteam. This skill has two complementary surfaces: 1. **Repository security gate** (`scripts/security-gate.sh`) — fast/full/nightly scanner gates for code, scripts, hooks, and release readiness. 2. **Composable security suite** (`scripts/security_suite.py`, `scripts/prompt_redteam.py`) — testable, reusable primitives for authorized binaries and repo-managed prompt surfaces, with policy gating and machine-consumable outputs. ## Quick Start ```bash /security # quick security gate /security --full # full gate with test-inclusive toolchain checks /security --release # full gate for release readiness /security --json # machine-readable report output ``` ## Guardrails (suite primitives) - Use the binary/redteam primitives only on binaries you own or are explicitly authorized to assess. - Do not use this workflow to bypass legal restrictions or extract third-party proprietary content without authorization. - Prefer behavioral assurance and policy gating over ad-hoc one-off reverse-engineering. ## Execution Contract (repository gate) ### 1) Pre-PR (fast) Run quick gate: ```bash scripts/security-gate.sh --mode quick ``` Expected behavior: - Fails on high/critical findings from available scanners. - Writes artifacts under `$TMPDIR/agentops-security/<run-id>/`. ### 2) Pre-Release (strict) Run full gate: ```bash scripts/security-gate.sh --mode full ``` Expected behavior: - Full scanner pass before release workflow can continue. - Artifacts retained for audit and incident response. ### 3) Nightly (continuous) Nightly workflow should run: ```bash scripts/security-gate.sh --mode full ``` Expected behavior: - Detects drift/regressions outside active PR windows. - Failing run creates actionable signal in workflow summary/issues. ## Composable Security Suite This surface separates concerns into primitives so security workflows stay testable and reusable. ### Primitive Model 1. `collect-static` — file metadata, runtime heuristics, linked libraries, embedded archive signatures. 2. `collect-dynamic` — sandboxed execution trace (processes, file changes, network endpoints). 3. `collect-contract` — machine-readable behavior contract from help-surface probing. 4. `compare-baseline` — current vs baseline contract drift (added/removed commands, runtime change). 5. `enforce-policy` — allowlist/denylist gates and severity-based verdict. 6. `collect-redteam` — offline repo-surface attack-pack scan for prompt-injection, tool-misuse, secret-exfiltration, and unsafe-shell regressions. 7. `run` — thin binary orchestrator that composes primitives and writes suite summary. ### Suite Quick Start Single run (default dynamic command is `--help`): ```bash python3 skills/security/scripts/security_suite.py run \ --binary "$(command -v ao)" \ --out-dir .tmp/security-suite/ao-current ``` Baseline regression gate: ```bash python3 skills/security/scripts/security_suite.py run \ --binary "$(command -v ao)" \ --out-dir .tmp/security-suite/ao-current \ --baseline-dir .tmp/security-suite/ao-baseline \ --fail-on-removed ``` Policy gate: ```bash python3 skills/security/scripts/security_suite.py run \ --binary "$(command -v ao)" \ --out-dir .tmp/security-suite/ao-current \ --policy-file skills/security/references/policy-example.json \ --fail-on-policy-fail ``` Repo-surface redteam: ```bash python3 skills/security/scripts/prompt_redteam.py scan \ --repo-root . \ --pack-file skills/security/references/agentops-redteam-pack.json \ --out-dir .tmp/security-suite-redteam ``` For OWASP Top 10 code-level review, see [references/owasp-checklist.md](references/owasp-checklist.md). ### Recommended Suite Workflow 1. Capture baseline on known-good release. 2. Run suite on candidate binary in CI. 3. Compare against baseline and enforce policy. 4. Block promotion on failing verdict. ### Suite Output Contract All outputs are written under `--out-dir`: - `static/static-analysis.json` - `dynamic/dynamic-analysis.json` - `contract/contract.json` - `compare/baseline-diff.json` (when baseline supplied) - `policy/policy-verdict.json` (when policy supplied) - `suite-summary.json` - `redteam/redteam-results.json` (when repo-surface redteam is run) This output structure is intentionally machine-consumable for CI gates. ### Policy Model Use `skills/security/references/policy-example.json` as a starting point. Policy gating produces a machine-readable `policy-verdict.json`. Supported checks: - `required_top_level_commands` - `deny_command_patterns` - `max_created_files` - `forbid_file_path_patterns` - `allow_network_endpoint_patterns` - `deny_network_endpoint_patterns` - `block_if_removed_commands` - `min_command_count` ### Redteam Pack Model Use [agentops-redteam-pack.json](references/agentops-redteam-pack.json) as the starting point for offline repo-surface redteam checks. Supported target fields: - `globs` - `require_groups` - `forbidden_any` - `applies_if_any` Each case expresses a concrete adversarial prompt or operator-bypass attempt and binds it to one or more repo-owned files. The first shipped pack covers instruction precedence, context overexposure, destructive git misuse, security gate bypass, and unsafe shell or secret-handling regressions. ### Technique Coverage This suite is designed for broad binary classes, not just CLI metadata: - static runtime/library fingerprinting - sandboxed behavior observation - command/contract capture - drift classification - policy enforcement and CI verdicting - repo-surface redteam checks for prompt and operator-contract regressions It is intentionally modular so you can add deeper primitives later (syscall tracing, SBOM attestation verification, fuzz harnesses) without rewriting the workflow. ## Triage Guidance When the repository gate fails: 1. Open latest artifact in `$TMPDIR/agentops-security/` and identify scanner + file. 2. Classify severity (critical/high/medium). 3. Fix immediately for critical/high or create tracked follow-up issue with owner. 4. Re-run `scripts/security-gate.sh` until gate passes. ## Reporting Template ```markdown Security gate run: <run-id> Mode: <quick|full> Result: <pass|blocked> Top findings: - <scanner> <severity> <file> <summary> Actions: - <fix or issue id> ``` ## Validation Run the merged skill validator (asserts the suite scripts/references, gate, and redteam pack stay healthy): ```bash bash skills/security/scripts/validate.sh bash tests/scripts/test-security-suite-redteam.sh ``` Suite smoke test (recommended): ```bash python3 skills/security/scripts/security_suite.py run \ --binary "$(command -v ao)" \ --out-dir .tmp/security-suite-smoke \ --policy-file skills/security/references/policy-example.json ``` Repo-surface smoke test: ```bash python3 skills/security/scripts/prompt_redteam.py scan \ --repo-root . \ --pack-file skills/security/references/agentops-redteam-pack.json \ --out-dir .tmp/security-suite-redteam-smoke ``` ## Notes - Use this as the canonical security runbook instead of ad-hoc scanner commands. - Keep workflow wiring aligned with this contract in: - `.github/workflows/validate.yml` - `.github/workflows/nightly.yml` - `.github/workflows/release.yml` - For binary/internal black-box assurance plus offline repo-surface redteam, use the composable suite above (`security_suite.py` and `prompt_redteam.py`). - For dependency vulnerability and license scanning, use: - [deps](../deps/SKILL.md) — Dependency audit, vulnerability scanning, and license compliance ## Examples ### Scenario: Quic
Related in Security
mac-ops
IncludedComprehensive macOS workstation operations — diagnose kernel panics, identify failing drives, audit launchd startup items, decode wake reasons, triage TCC permission denials, manage APFS snapshots, recover from no-boot. Use for: Mac is slow, slow bootup, won't boot, kernel panic, kernel_task hot, mds_stores CPU, photoanalysisd, cloudd, login loop, gray screen, sleep wake failure, drive failing, IO errors, APFS snapshots eating space, Time Machine local snapshots, Spotlight indexing, launchd, LaunchAgent, LaunchDaemon, login items, TCC permissions, Full Disk Access, Screen Recording denied, Gatekeeper, quarantine, com.apple.quarantine, app is damaged, helper tool, /Library/PrivilegedHelperTools, pmset, wake reasons, dark wake, sysdiagnose, panic.ips, DiagnosticReports, configuration profile, MDM profile, remote diagnostics over SSH.
a11y-audit
IncludedRun accessibility audits on web projects combining automated scanning (axe-core, Lighthouse) with WCAG 2.1 AA compliance mapping, manual check guidance, and structured reporting. Output is configurable: markdown report only, markdown plus machine-readable JSON, or markdown plus issue tracker integration. Use this skill whenever the user mentions "accessibility audit", "a11y audit", "WCAG audit", "accessibility check", "compliance scan", or asks to check a web project for accessibility issues. Also trigger when the user wants to verify WCAG conformance or map findings to a specific standard (CAN-ASC-6.2, EN 301 549, ADA/AODA).
erpclaw
IncludedAI-native ERP system with self-extending OS. Full accounting, invoicing, inventory, purchasing, tax, billing, HR, payroll, advanced accounting (ASC 606/842, intercompany, consolidation), and financial reporting. 413 actions across 14 domains, 43 expansion modules. Constitutional guardrails, adversarial audit, schema migration. Double-entry GL, immutable audit trail, US GAAP.
assess
IncludedAssesses and rates quality 0-10 across multiple dimensions (correctness, maintainability, security, performance, testability, simplicity) with pros/cons analysis. Compares against project conventions and prior decisions from memory. Produces structured evaluation reports with actionable improvement suggestions. Use when evaluating code, designs, architectures, or comparing alternative approaches.
spring-boot-security-jwt
IncludedProvides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
code-hardcode-audit
IncludedDetect hardcoded values, magic numbers, and leaked secrets. TRIGGERS - hardcode audit, magic numbers, PLR2004, secret scanning.