πŸ›‘οΈ
QualityShell

Security Pipeline

by sangrokjung

Security Pipeline is a Quality skill for Claude Code, published by sangrokjung in claude-forge.

806 stars175 forkson sangrokjung/claude-forgeAdded 2026/08/22Repository updated 2026/08/21
agentsai-assistantai-codingai-frameworkai-pair-programminganthropicautomationclaude-codeclaude-code-agentscli-toolsdeveloper-experiencedeveloper-toolsdotfileshooksllmmacosproductivityshellslash-commandsworkflow
Install in seconds
Install Security Pipeline
Copy Security Pipeline into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/sangrokjung/claude-forge/tree/main/skills/security-pipeline ~/.claude/skills/security-pipeline

Requires Node.js. Downloads this skill only β€” not the rest of the repository β€” into your Claude Code skills folder.

Without Node.js

git clone https://github.com/sangrokjung/claude-forge.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
skills/security-pipeline/SKILL.md in sangrokjung/claude-forge
Installs to
~/.claude/skills/security-pipeline
Collection
One of 25 skills cataloged from this repository
Category
Quality β€” 1354 skills

What Security Pipeline does

Security Pipeline runs CWE Top 25 checks, STRIDE analysis, and pre-commit vulnerability scanning when sensitive code changes or security commands are used. It helps gate commits and review fixes for common security issues.

Security Pipeline is cataloged under Quality on DirSkills. Security Pipeline comes from a repository tagged agents, ai-assistant, ai-coding, ai-framework and ai-pair-programming.

Documentation

README

Overview

λ³΄μ•ˆ νŒŒμ΄ν”„λΌμΈ μŠ€ν‚¬μ€ μ½”λ“œ λ³€κ²½ μ‹œ μžλ™μœΌλ‘œ CWE Top 25 기반 λ³΄μ•ˆ 검증을 μˆ˜ν–‰ν•œλ‹€. /handoff-verify --security, /commit-push-pr μ‹€ν–‰ μ‹œ 톡합 λ™μž‘ν•œλ‹€. λ³΄μ•ˆ 체크리슀트 μ°Έμ‘°: ~/.claude/skills/_reference/security-checklist.md

effort:maxκ°€ 항상 κ°•μ œ μ μš©λœλ‹€. λ³΄μ•ˆ 검증은 μΆ•μ•½ν•˜μ§€ μ•ŠλŠ”λ‹€.


Trigger Conditions

파일 νŒ¨ν„΄ 기반 μžλ™ 트리거

λ‹€μŒ νŒ¨ν„΄μ„ ν¬ν•¨ν•˜λŠ” 파일이 λ³€κ²½λ˜λ©΄ λ³΄μ•ˆ νŒŒμ΄ν”„λΌμΈμ΄ μžλ™μœΌλ‘œ μ‹€ν–‰λœλ‹€:

This is the opening of the README. Read the full README on GitHub.

Commands Security Pipeline provides

Slash commands named in this skill’s SKILL.md, listed in the order they first appear.

  • /handoff-verify
  • /commit-push-pr
  • /security-review

Frequently asked about Security Pipeline

  • What else does sangrokjung publish alongside Security Pipeline?

    Security Pipeline is one of 25 skills that DirSkills catalogs from sangrokjung/claude-forge, the repository it ships in. Its siblings there include BigCode Evaluation Harness, Blind Spot Pass and Build System. Each one is a separate skill with its own page in this directory, installs the same way Security Pipeline does, and is maintained by sangrokjung in that same repository. The rest of the collection is listed on the sangrokjung/claude-forge page.

  • How does Security Pipeline compare to other Quality skills?

    Security Pipeline ranks #951 by stars among the 1354 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Security Pipeline against them. Open each page to compare what they document and how they install.

More from sangrokjung/claude-forge

Security Pipeline is one of 25 skills cataloged on DirSkills from sangrokjung/claude-forge.

See all 25 skills β†’
πŸ§ͺ
1w ago

BigCode Evaluation Harness

BigCode Evaluation Harness evaluates code generation models on HumanEval, MBPP, MultiPL-E, and other benchmarks with pass@k metrics. Use it to compare coding ability, multi-language support, or overall code generation quality.
Quality
806175
🧭
1w ago

Blind Spot Pass

Blind Spot Pass surfaces the unknown unknowns in a domain before you start work, so you can prompt and decide with enough context. Use it when you are new to a field or handing off unfamiliar work and need a brief briefing first.
AI Engineering
806175
πŸ› οΈ
1w ago

Build System

Build System detects a project's build tool and runs the right build or test command. Use it when setting up, building, or testing projects with npm, Python, Gradle, Maven, Cargo, Go, or Make.
DevOps
806175
🧩
1w ago

Cache Components

Cache Components gives guidance for Next.js Cache Components and Partial Prerendering. Use it when `cacheComponents: true` is enabled to decide what to cache, stream, tag, and invalidate in Server Components.
Frontend
806175
πŸ€–
1w ago

Claude Code Agent

Claude Code Agent guides Claude Code projects with spec-first planning, context engineering, sub-agents, and post-dev verification. Use it when writing CLAUDE.md or spec.md, dispatching parallel agent work, or running the handoff and docs sync workflow.
AI Engineering
806175
🧠
1w ago

Continuous Learning V2

Continuous Learning V2 turns Claude Code sessions into atomic instincts using hooks, confidence scoring, and background pattern detection. Use it to capture repeated behaviors and evolve them into skills, commands, or agents.
AI Engineering
806175