XavierEr/appsec-agent-skills
Application security scanning skills for AI coding agents. SAST, DAST, dependency audit, secrets detection, config review, and compliance mapping — all powered by the agent itself, no external tools required. Follows the agentskills.io open
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
Copy this rig
# review before running: this installs third-party code
$ npx degit XavierEr/appsec-agent-skills/skills ./rig-appsec-agent-skills/skills MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit XavierEr/appsec-agent-skills/skills/api-contract-testing .claude/skills/api-contract-testing $ npx degit XavierEr/appsec-agent-skills/skills/compliance-mapper .claude/skills/compliance-mapper $ npx degit XavierEr/appsec-agent-skills/skills/dast-scanner .claude/skills/dast-scanner $ npx degit XavierEr/appsec-agent-skills/skills/dependency-audit .claude/skills/dependency-audit $ npx degit XavierEr/appsec-agent-skills/skills/llm-sast-scanner .claude/skills/llm-sast-scanner $ npx degit XavierEr/appsec-agent-skills/skills/remediation-validator .claude/skills/remediation-validator $ npx degit XavierEr/appsec-agent-skills/skills/secrets-scanner .claude/skills/secrets-scanner $ npx degit XavierEr/appsec-agent-skills/skills/security-audit .claude/skills/security-audit $ npx degit XavierEr/appsec-agent-skills/skills/security-config-review .claude/skills/security-config-review
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(.env)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(~/.aws/**)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/*.key)",
"Read(**/.env.*)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(git rebase *)",
"Bash(wget *)",
"Bash(npm publish:*)",
"Bash(git commit *)",
"Bash(gh pr merge *)"
]
}
} Skills (9)
Similar rigs
TheDecipherist/claude-code-mastery
The complete guide to Claude Code: CLAUDE.md, hooks, skills, MCP servers, and commands
Pragmatist 823 tok ·
jLAM-ERR/corp-llm-gateway
Corporate LLM gateway. Sanitizes traffic between developer Claude Code instances and Anthropic/OpenAI before it leaves the corp boundary.
Pragmatist 6.6k tok ·
pravindurgani/claude-code-multipane-iterm2
Stop your AI agent from reviewing its own code — 4-pane iTerm2 setup with role-locked Claude Code sessions. Step-by-step guide included.
Minimalist 1.0k tok ·
spawnpoint-inc/spawnpoint-plugin
Claude Code plugin for spawnpoint: your agent builds it, spawnpoint puts it online, you get a link.
Minimalist 187 tok ·