πŸ›‘οΈ
AI EngineeringPython

RAG Security First

by lyonzin

RAG Security First is an AI Engineering skill for Claude Code, published by lyonzin in knowledge-rag.

265 stars38 forkson lyonzin/knowledge-ragAdded 2026/09/02+2% in starsRepository updated 2026/09/01
antigravityclaudeclaude-codeclaude-code-clicodexcursor-aidocument-searchhybrid-searchinteligencia-artificialknowledge-baselocal-aimcpmcp-serverragrag-chatbotrag-pipelinererankingretrieval-augmented-generationsemantic-searchvector-database
Install in seconds
Install RAG Security First
Copy RAG Security First into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/lyonzin/knowledge-rag/tree/master/skills/domain/rag-security-first ~/.claude/skills/rag-security-first

Requires Node.js. Downloads this skill only β€” not the rest of the repository β€” into your Claude Code skills folder.

Without Node.js

git clone https://github.com/lyonzin/knowledge-rag.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
skills/domain/rag-security-first/SKILL.md in lyonzin/knowledge-rag
Installs to
~/.claude/skills/rag-security-first
Collection
One of 10 skills cataloged from this repository
Category
AI Engineering β€” 2631 skills

What RAG Security First does

RAG Security First routes security questions through the local corpus before external threat-intel lookups. Use it for incident response, MITRE mapping, CVE analysis, detections, and red/blue team research grounded in local playbooks.

RAG Security First is cataloged under AI Engineering on DirSkills. RAG Security First comes from a repository tagged antigravity, claude, claude-code, claude-code-cli and codex.

Documentation

README

rag-security-first β€” RAG-driven security workflow

When to use this skill

Trigger this skill for any security-flavored task:

  • Threat triage or incident response
  • MITRE ATT&CK technique mapping (T1078, T1055, …)
  • CVE lookup or vulnerability analysis
  • Exploit / payload / attacker-technique questions
  • Red team / blue team / purple team exercises
  • CTF challenge analysis
  • Detection engineering (Sigma / Snort / YARA / KQL / SPL / LQL rules)
  • Defensive control validation
  • Compliance / hardening questions

This is the opening of the README. Read the full README on GitHub.

Commands RAG Security First provides

Slash commands named in this skill’s SKILL.md, listed in the order they first appear.

  • /nowrap
  • /aes

Frequently asked about RAG Security First

  • What else does lyonzin publish alongside RAG Security First?

    RAG Security First is one of 10 skills that DirSkills catalogs from lyonzin/knowledge-rag, the repository it ships in. Its siblings there include RAG Check First, RAG Code Review and RAG Evaluate Quality. Each one is a separate skill with its own page in this directory, installs the same way RAG Security First does, and is maintained by lyonzin in that same repository. The rest of the collection is listed on the lyonzin/knowledge-rag page.

  • How does RAG Security First compare to other AI Engineering skills?

    RAG Security First ranks #2243 by stars among the 2631 AI Engineering skills in this catalog. The most-starred ones next to it are Architecture Decision Records, AI-First Engineering and Agentic OS. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of RAG Security First against them. Open each page to compare what they document and how they install.

More from lyonzin/knowledge-rag

RAG Security First is one of 10 skills cataloged on DirSkills from lyonzin/knowledge-rag.

See all 10 skills β†’
πŸ”Ž
1h ago

RAG Check First

RAG Check First requires a local knowledge search before answering technical questions, code requests, or team-specific factual claims. Use it to ground responses in indexed docs, ADRs, runbooks, and prior work.
AI Engineering
26538
πŸ”
1h ago

RAG Code Review

RAG Code Review consults related ADRs, standards, similar files, and prior incidents before commenting on a code change. Use it for PR reviews or any critique of a diff so feedback is grounded in the team’s own decisions.
AI Engineering
26538
πŸ“ˆ
1h ago

RAG Evaluate Quality

RAG Evaluate Quality measures retrieval performance with MRR@5, Recall@5, Precision@5, and index health stats. Use it weekly, after reindexing, or when answer quality seems to drop.
AI Engineering
26538
🧠
1h ago

RAG Index Decisions

RAG Index Decisions prompts you to turn important architectural choices, bug fixes, and team conventions into indexed documents. Use it when a conclusion should be searchable the next time the same issue comes up.
AI Engineering
26538
πŸ”Ž
1h ago

RAG Onboard Context

RAG Onboard Context probes the indexed knowledge base at the start of a session or after a topic shift. It checks index stats, categories, and a few sample searches so the agent knows what content is available before answering.
AI Engineering
26538
πŸ”Ž
1h ago

RAG Web Fallback

RAG Web Fallback forces an agent to search the local knowledge base before using external web tools. It is used when a question might be answered from indexed docs and the agent must explain why it escalated if local coverage is missing.
AI Engineering
26538