Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问许可证需确认审计通过

senior-secops高级安全警察

Agent Skill

senior-secops 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

2,208

周安装

92

GitHub Stars

103

下载量

736
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:senior-secops(高级安全警察)
来源仓库:https://github.com/borghei/claude-skills
仓库路径:skills/senior-secops
安装命令:
npx skills add https://github.com/borghei/claude-skills --skill senior-secops
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/borghei/claude-skills --skill senior-secops

简介

senior-secops 扫描源码与依赖中的安全风险与合规差距。

  • 支持 SOC 2、PCI-DSS 等框架检查与 CVE 漏洞识别。
  • 输出修复建议与证据材料,便于审计与整改。
  • 扫描结果需人工复核以避免误报与漏报。
  • 适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。

SKILL.md

Senior SecOps Engineer

The agent scans source code for security vulnerabilities (hardcoded secrets, SQL injection, XSS, command injection), assesses dependency CVEs across npm/Python/Go ecosystems, and verifies compliance against SOC 2, PCI-DSS, HIPAA, and GDPR frameworks.


Core Capabilities

1. Security Scanner

Scan source code for security vulnerabilities including hardcoded secrets, SQL injection, XSS, command injection, and path traversal.

# Scan project for security issues
python scripts/security_scanner.py /path/to/project

# Filter by severity
python scripts/security_scanner.py /path/to/project --severity high

# JSON output for CI/CD
python scripts/security_scanner.py /path/to/project --json --output report.json

Detects:

  • Hardcoded secrets (API keys, passwords, AWS credentials, GitHub tokens, private keys)
  • SQL injection patterns (string concatenation, f-strings, template literals)
  • XSS vulnerabilities (innerHTML assignment, unsafe DOM manipulation, React unsafe patterns)
  • Command injection (shell=True, exec, eval with user input)
  • Path traversal (file operations with user input)

2. Vulnerability Assessor

Scan dependencies for known CVEs across npm, Python, and Go ecosystems.

# Assess project dependencies
python scripts/vulnerability_assessor.py /path/to/project

# Critical/high only
python scripts/vulnerability_assessor.py /path/to/project --severity high

# Export vulnerability report
python scripts/vulnerability_assessor.py /path/to/project --json --output vulns.json

Scans:

  • package.json and package-lock.json (npm)
  • requirements.txt and pyproject.toml (Python)
  • go.mod (Go)

Output:

  • CVE IDs with CVSS scores
  • Affected package versions
  • Fixed versions for remediation
  • Overall risk score (0-100)

3. Compliance Checker

Verify security compliance against SOC 2, PCI-DSS, HIPAA, and GDPR frameworks.

# Check all frameworks
python scripts/compliance_checker.py /path/to/project

# Specific framework
python scripts/compliance_checker.py /path/to/project --framework soc2
python scripts/compliance_checker.py /path/to/project --framework pci-dss
python scripts/compliance_checker.py /path/to/project --framework hipaa
python scripts/compliance_checker.py /path/to/project --framework gdpr

# Export compliance report
python scripts/compliance_checker.py /path/to/project --json --output compliance.json

Verifies:

  • Access control implementation
  • Encryption at rest and in transit
  • Audit logging
  • Authentication strength (MFA, password hashing)
  • Security documentation
  • CI/CD security controls

Workflows

Workflow 1: Security Audit

Complete security assessment of a codebase.

# Step 1: Scan for code vulnerabilities
python scripts/security_scanner.py . --severity medium

# Step 2: Check dependency vulnerabilities
python scripts/vulnerability_assessor.py . --severity high

# Step 3: Verify compliance controls
python scripts/compliance_checker.py . --framework all

# Step 4: Generate combined report
python scripts/security_scanner.py . --json --output security.json
python scripts/vulnerability_assessor.py . --json --output vulns.json
python scripts/compliance_checker.py . --json --output compliance.json

Workflow 2: CI/CD Security Gate

Integrate security checks into deployment pipeline.

# .github/workflows/security.yml
name: Security Scan

on:
  pull_request:
    branches: [main, develop]

jobs:
  security-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Set up Python
        uses: actions/setup-python@v5
        with:
          python-version: '3.11'

      - name: Security Scanner
        run: python scripts/security_scanner.py . --severity high

      - name: Vulnerability Assessment
        run: python scripts/vulnerability_assessor.py . --severity critical

      - name: Compliance Check
        run: python scripts/compliance_checker.py . --framework soc2

Workflow 3: CVE Triage

Respond to a new CVE affecting your application.

1. ASSESS (0-2 hours)
   - Identify affected systems using vulnerability_assessor.py
   - Check if CVE is being actively exploited
   - Determine CVSS environmental score for your context

2. PRIORITIZE
   - Critical (CVSS 9.0+, internet-facing): 24 hours
   - High (CVSS 7.0-8.9): 7 days
   - Medium (CVSS 4.0-6.9): 30 days
   - Low (CVSS < 4.0): 90 days

3. REMEDIATE
   - Update affected dependency to fixed version
   - Run security_scanner.py to verify fix
   - Test for regressions
   - Deploy with enhanced monitoring

4. VERIFY
   - Re-run vulnerability_assessor.py
   - Confirm CVE no longer reported
   - Document remediation actions

Workflow 4: Incident Response

Security incident handling procedure.

PHASE 1: DETECT & IDENTIFY (0-15 min)
- Alert received and acknowledged
- Initial severity assessment (SEV-1 to SEV-4)
- Incident commander assigned
- Communication channel established

PHASE 2: CONTAIN (15-60 min)
- Affected systems identified
- Network isolation if needed
- Credentials rotated if compromised
- Preserve evidence (logs, memory dumps)

PHASE 3: ERADICATE (1-4 hours)
- Root cause identified
- Malware/backdoors removed
- Vulnerabilities patched (run security_scanner.py)
- Systems hardened

PHASE 4: RECOVER (4-24 hours)
- Systems restored from clean backup
- Services brought back online
- Enhanced monitoring enabled
- User access restored

PHASE 5: POST-INCIDENT (24-72 hours)
- Incident timeline documented
- Root cause analysis complete
- Lessons learned documented
- Preventive measures implemented
- Stakeholder report delivered

Tool Reference

security_scanner.py

OptionDescription
targetDirectory or file to scan
--severity, -sMinimum severity: critical, high, medium, low
--verbose, -vShow files as they're scanned
--jsonOutput results as JSON
--output, -oWrite results to file

Exit Codes:

  • 0: No critical/high findings
  • 1: High severity findings
  • 2: Critical severity findings

vulnerability_assessor.py

OptionDescription
targetDirectory containing dependency files
--severity, -sMinimum severity: critical, high, medium, low
--verbose, -vShow files as they're scanned
--jsonOutput results as JSON
--output, -oWrite results to file

Exit Codes:

  • 0: No critical/high vulnerabilities
  • 1: High severity vulnerabilities
  • 2: Critical severity vulnerabilities

compliance_checker.py

OptionDescription
targetDirectory to check
--framework, -fFramework: soc2, pci-dss, hipaa, gdpr, all
--verbose, -vShow checks as they run
--jsonOutput results as JSON
--output, -oWrite results to file

Exit Codes:

  • 0: Compliant (90%+ score)
  • 1: Non-compliant (50-69% score)
  • 2: Critical gaps (<50% score)

Security Standards

OWASP Top 10 Prevention

VulnerabilityPrevention
A01: Broken Access ControlImplement RBAC, deny by default, validate permissions server-side
A02: Cryptographic FailuresUse TLS 1.2+, AES-256 encryption, secure key management
A03: InjectionParameterized queries, input validation, escape output
A04: Insecure DesignThreat modeling, secure design patterns, defense in depth
A05: Security MisconfigurationHardening guides, remove defaults, disable unused features
A06: Vulnerable ComponentsDependency scanning, automated updates, SBOM
A07: Authentication FailuresMFA, rate limiting, secure password storage
A08: Data Integrity FailuresCode signing, integrity checks, secure CI/CD
A09: Security Logging FailuresComprehensive audit logs, SIEM integration, alerting
A10: SSRFURL validation, allowlist destinations, network segmentation

Secure Coding Checklist

## Input Validation
- [ ] Validate all input on server side
- [ ] Use allowlists over denylists
- [ ] Sanitize for specific context (HTML, SQL, shell)

## Output Encoding
- [ ] HTML encode for browser output
- [ ] URL encode for URLs
- [ ] JavaScript encode for script contexts

## Authentication
- [ ] Use bcrypt/argon2 for passwords
- [ ] Implement MFA for sensitive operations
- [ ] Enforce strong password policy

## Session Management
- [ ] Generate secure random session IDs
- [ ] Set HttpOnly, Secure, SameSite flags
- [ ] Implement session timeout (15 min idle)

## Error Handling
- [ ] Log errors with context (no secrets)
- [ ] Return generic messages to users
- [ ] Never expose stack traces in production

## Secrets Management
- [ ] Use environment variables or secrets manager
- [ ] Never commit secrets to version control
- [ ] Rotate credentials regularly

Compliance Frameworks

SOC 2 Type II Controls

ControlCategoryDescription
CC1Control EnvironmentSecurity policies, org structure
CC2CommunicationSecurity awareness, documentation
CC3Risk AssessmentVulnerability scanning, threat modeling
CC6Logical AccessAuthentication, authorization, MFA
CC7System OperationsMonitoring, logging, incident response
CC8Change ManagementCI/CD, code review, deployment controls

PCI-DSS v4.0 Requirements

RequirementDescription
Req 3Protect stored cardholder data (encryption at rest)
Req 4Encrypt transmission (TLS 1.2+)
Req 6Secure development (input validation, secure coding)
Req 8Strong authentication (MFA, password policy)
Req 10Audit logging (all access to cardholder data)
Req 11Security testing (SAST, DAST, penetration testing)

HIPAA Security Rule

SafeguardRequirement
164.312(a)(1)Unique user identification for PHI access
164.312(b)Audit trails for PHI access
164.312(c)(1)Data integrity controls
164.312(d)Person/entity authentication (MFA)
164.312(e)(1)Transmission encryption (TLS)

GDPR Requirements

ArticleRequirement
Art 25Privacy by design, data minimization
Art 32Security measures, encryption, pseudonymization
Art 33Breach notification (72 hours)
Art 17Right to erasure (data deletion)
Art 20Data portability (export capability)

Best Practices

Secrets Management

# BAD: Hardcoded secret
API_KEY = "sk-1234567890abcdef"

# GOOD: Environment variable
import os
API_KEY = os.environ.get("API_KEY")

# BETTER: Secrets manager
from your_vault_client import get_secret
API_KEY = get_secret("api/key")

SQL Injection Prevention

# BAD: String concatenation
query = f"SELECT * FROM users WHERE id = {user_id}"

# GOOD: Parameterized query
cursor.execute("SELECT * FROM users WHERE id = %s", (user_id,))

XSS Prevention

// BAD: Direct innerHTML assignment is vulnerable
// GOOD: Use textContent (auto-escaped)
element.textContent = userInput;

// GOOD: Use sanitization library for HTML
import DOMPurify from 'dompurify';
const safeHTML = DOMPurify.sanitize(userInput);

Authentication

// Password hashing
const bcrypt = require('bcrypt');
const SALT_ROUNDS = 12;

// Hash password
const hash = await bcrypt.hash(password, SALT_ROUNDS);

// Verify password
const match = await bcrypt.compare(password, hash);

Security Headers

// Express.js security headers
const helmet = require('helmet');
app.use(helmet());

// Or manually set headers:
app.use((req, res, next) => {
  res.setHeader('X-Content-Type-Options', 'nosniff');
  res.setHeader('X-Frame-Options', 'DENY');
  res.setHeader('X-XSS-Protection', '1; mode=block');
  res.setHeader('Strict-Transport-Security', 'max-age=31536000; includeSubDomains');
  res.setHeader('Content-Security-Policy', "default-src 'self'");
  next();
});

Reference Documentation

DocumentDescription
references/security_standards.mdOWASP Top 10, secure coding, authentication, API security
references/vulnerability_management_guide.mdCVE triage, CVSS scoring, remediation workflows
references/compliance_requirements.mdSOC 2, PCI-DSS, HIPAA, GDPR requirements

Tech Stack

Security Scanning:

  • Snyk (dependency scanning)
  • Semgrep (SAST)
  • CodeQL (code analysis)
  • Trivy (container scanning)
  • OWASP ZAP (DAST)

Secrets Management:

  • HashiCorp Vault
  • AWS Secrets Manager
  • Azure Key Vault
  • 1Password Secrets Automation

Authentication:

  • bcrypt, argon2 (password hashing)
  • jsonwebtoken (JWT)
  • passport.js (authentication middleware)
  • speakeasy (TOTP/MFA)

Logging & Monitoring:

  • Winston, Pino (Node.js logging)
  • Datadog, Splunk (SIEM)
  • PagerDuty (alerting)

Compliance:

  • Vanta (SOC 2 automation)
  • Drata (compliance management)
  • AWS Config (configuration compliance)

Anti-Patterns

  • Relying solely on automated scanning -- SAST tools miss business logic flaws and authorization issues; combine with manual code review for auth-sensitive code
  • Ignoring medium-severity findings -- exit code 0 on medium findings does not mean safe; parse JSON output for comprehensive CI gating
  • Hardcoding secrets in test fixtures -- test files with example tokens trigger false positives; use environment variables or mock values even in tests
  • Compliance score as a goal -- a 90% compliance score with failed encryption controls is worse than 80% with all critical controls passing; prioritize by severity
  • One-time security audits -- running the scanner once per quarter misses regressions; integrate into every PR via CI/CD
  • Treating warnings as passed -- compliance checker scores warnings at 0.5 (partial credit); any control below passed needs remediation

Troubleshooting

ProblemCauseSolution
Security scanner reports zero findings on a known-vulnerable projectTest and spec files are excluded by the false-positive filterRename the file to remove test/spec from the path, or review the _is_false_positive method
Vulnerability assessor misses a CVE for a listed dependencyThe package or CVE is not in the built-in KNOWN_CVES databaseSupplement with an external feed (Snyk, OSV, npm audit) and use the assessor for triage prioritization
Compliance checker shows CRITICAL_GAPS despite controls being presentPattern-based file search did not match the specific naming convention used in your codebaseRun with --verbose to see which checks fail, then verify the matching code patterns or filenames
--json output is printed to stdout even when --output is specifiedBoth flags are set correctly; this is expected behavior (summary prints to stderr-style console, JSON to file)Redirect stdout if you need a clean pipe: python script.py. --json --output report.json > /dev/null
Exit code is 0 despite medium-severity findingsExit codes only trigger on critical (exit 2) or high (exit 1) severity findingsUse --severity medium to surface medium findings in the report, and parse the JSON output for CI/CD gating
Scanner is slow on large monoreposAll files matching SCAN_EXTENSIONS are read in fullNarrow the target to a subdirectory, or exclude heavy vendor directories by placing them in SKIP_DIRS
Compliance score appears inflated because many controls show warningWarnings score 0.5 (partial credit) in the weighted calculationTreat any control below passed as requiring remediation; filter the JSON output for status!= "passed"

Success Criteria

  • Zero critical CVEs in production -- all critical-severity vulnerabilities are patched or mitigated before deployment.
  • Mean time to patch under 48 hours -- critical and high-severity findings are remediated within two business days of detection.
  • Compliance score at or above 90% -- the compliance checker returns COMPLIANT status for every applicable framework before each release.
  • 100% of secrets externalized -- the security scanner reports zero hardcoded secrets (API keys, passwords, private keys) across the entire codebase.
  • CI/CD security gate pass rate above 95% -- fewer than 5% of pull requests are blocked by security scans, indicating proactive secure coding practices.
  • Incident response time under 15 minutes -- security incidents are acknowledged and an incident commander assigned within the Phase 1 detection window.
  • Quarterly dependency audit cadence -- the vulnerability assessor is executed against all ecosystems (npm, Python, Go) at least once per quarter with results documented.

Scope & Limitations

This skill covers:

  • Static analysis of source code for common vulnerability classes (secrets, injection, XSS, command injection, path traversal).
  • Dependency vulnerability assessment against a built-in CVE database for npm, Python, and Go ecosystems.
  • Compliance verification for SOC 2 Type II, PCI-DSS v4.0, HIPAA Security Rule, and GDPR.
  • Security workflow orchestration including CI/CD gating, CVE triage, and incident response procedures.

This skill does NOT cover:

  • Dynamic application security testing (DAST) or runtime analysis -- use OWASP ZAP or Burp Suite for live scanning.
  • Infrastructure-as-code security (Terraform, CloudFormation misconfigurations) -- see the senior-devops skill for IaC hardening.
  • Container image scanning or Kubernetes admission control -- see the senior-devops skill or use Trivy directly.
  • Penetration testing execution or red-team operations -- these require specialized tooling and authorized human operators.

Integration Points

SkillIntegrationData Flow
senior-devopsInfrastructure hardening and CI/CD pipeline configurationSecurity scan results feed into deployment gates; DevOps provides container and IaC scanning
senior-backendSecure coding patterns and input validation in server-side codeSecOps scanner findings drive backend remediation; backend applies parameterized queries and output encoding
senior-qaSecurity test cases and regression verification after patchesVulnerability reports generate QA test cases; QA confirms fixes do not introduce regressions
senior-architectThreat modeling, defense-in-depth design, and zero-trust architectureCompliance gaps inform architecture decisions; architect provides security design patterns
code-reviewerSecurity-focused code review and pre-merge analysisScanner findings prioritize review focus areas; reviewer enforces secure coding standards
senior-fullstackEnd-to-end security across frontend and API layers (XSS, CSRF, auth)SecOps identifies frontend and API vulnerabilities; fullstack applies framework-level mitigations

Tool Reference

security_scanner.py

Purpose: Scan source code for security vulnerabilities including hardcoded secrets, SQL injection, XSS, command injection, and path traversal patterns.

Usage:

python scripts/security_scanner.py <target> [options]

Flags:

FlagShortTypeDefaultDescription
target--positional*(required)*Directory or file to scan
--severity-schoicelowMinimum severity to report: critical, high, medium, low, info
--verbose-vflagoffPrint each file path as it is scanned
--json--flagoffOutput results as JSON (to stdout or combined with --output)
--output-ostring--Write results to the specified file path

Example:

# Scan current directory for high and critical findings, export JSON
python scripts/security_scanner.py . --severity high --json --output security-report.json

Output Formats:

  • Human-readable (default): Prints a summary table with severity counts and the top 5 findings including file path, line number, and description.
  • JSON (--json): Full structured report with status, files_scanned, scan_duration_seconds, total_findings, severity_counts, and a findings array. Each finding includes rule_id, severity, category, title, description, file_path, line_number, code_snippet, and recommendation.

Exit Codes: 0 = no critical/high findings, 1 = high-severity findings present, 2 = critical-severity findings present.


vulnerability_assessor.py

Purpose: Scan project dependency manifests (package.json, requirements.txt, pyproject.toml, package-lock.json, go.mod) for known CVEs and calculate an overall risk score.

Usage:

python scripts/vulnerability_assessor.py <target> [options]

Flags:

FlagShortTypeDefaultDescription
target--positional*(required)*Directory containing dependency files
--severity-schoicelowMinimum severity to report: critical, high, medium, low
--verbose-vflagoffPrint each dependency file path as it is scanned
--json--flagoffOutput results as JSON (to stdout or combined with --output)
--output-ostring--Write results to the specified file path

Example:

# Assess dependencies, show only critical vulnerabilities
python scripts/vulnerability_assessor.py /path/to/project --severity critical --verbose

Output Formats:

  • Human-readable (default): Prints a summary with files scanned, packages scanned, risk score (0-100), risk level (NONE/LOW/MEDIUM/HIGH/CRITICAL), severity counts, and the top 5 vulnerabilities sorted by CVSS score.
  • JSON (--json): Full structured report with status, target, files_scanned, packages_scanned, scan_duration_seconds, total_vulnerabilities, risk_score, risk_level, severity_counts, and a vulnerabilities array. Each vulnerability includes cve_id, package, installed_version, fixed_version, severity, cvss_score, description, ecosystem, and recommendation.

Exit Codes: 0 = no critical/high vulnerabilities, 1 = high-severity vulnerabilities present, 2 = critical-severity vulnerabilities present.


compliance_checker.py

Purpose: Verify security compliance against SOC 2 Type II, PCI-DSS v4.0, HIPAA Security Rule, and GDPR by scanning project files for evidence of required controls.

Usage:

python scripts/compliance_checker.py <target> [options]

Flags:

FlagShortTypeDefaultDescription
target--positional*(required)*Directory to check for compliance
--framework-fchoiceallCompliance framework: soc2, pci-dss, hipaa, gdpr, all
--verbose-vflagoffPrint each framework check as it runs
--json--flagoffOutput results as JSON (to stdout or combined with --output)
--output-ostring--Write results to the specified file path

Example:

# Check SOC 2 compliance and export report
python scripts/compliance_checker.py . --framework soc2 --json --output soc2-report.json

Output Formats:

  • Human-readable (default): Prints compliance score as a percentage with level (COMPLIANT/PARTIALLY_COMPLIANT/NON_COMPLIANT/CRITICAL_GAPS), a passed/failed/warning/N/A breakdown, and the top 5 failed controls with severity and remediation recommendations.
  • JSON (--json): Full structured report with status, target, framework, scan_duration_seconds, compliance_score, compliance_level, summary (passed/failed/warnings/not_applicable/total), and a controls array. Each control includes control_id, framework, category, title, description, status, evidence, recommendation, and severity.

Exit Codes: 0 = compliant (90%+ score), 1 = non-compliant (50-69% score), 2 = critical gaps (<50% score).

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

38.01%
按下载量换算280

Claude

30.53%
按下载量换算225

Cursor

18.11%
按下载量换算133

Gemini CLI

10.7%
按下载量换算79

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills