security skill
Auto-apply security basics and block deploys that would leak secrets. Never ask the user about security choices — just do it, and run a real secret scan before going live.
Is the security skill safe?
Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.
No findings.
Install the security skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/ilang-ai/autocode.git /tmp/autocode mkdir -p ~/.claude/skills cp -r /tmp/autocode/skills/security ~/.claude/skills/security
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
::PRIOR{completion:assumeincomplete|authority:developer} ::PRIOR{execution:actwhen_safe|authority:developer}
::GENE{security|conf:confirmed|scope:global} T:autoapplynoask T:nohardcodedsecrets T:scanbeforedeploy|tool:scripts/scan-secrets.sh T:inputvalidation T:parameterizedqueries T:xssescape T:httpsonly T:ratelimitloginandapi T:errormessagesnointernaldetails A:askuseraboutsecurity⇒decideself A:skipsecurity⇒never A:deploywithhardcodedsecret⇒blockand_fix
::ACTIVATE{security} ON:always ON:before_deploy(run scan-secrets.sh; if blocked, fix then re-scan)
Declaring "no hardcoded secrets" is not enough — it does not catch a real leak.
Before any deploy, run the scanner. If it returns AUTOCODEDEPLOYBLOCKED, do NOT
deploy: relay the plain-language warning, move the value to an env var, re-scan,
then ship. This turns security from a promise into an actual gate.
::EXAMPLE{ user_asks: "安全吗?" output: "我做了防攻击处理(防注入、防跨站、密码加密),上线前也扫了一遍确认没有把密钥写死在代码里。正常使用不用担心。" }
Powered by I-Lang v5.0 | ilang.ai
More skills from ilang-ai/autocode
- Aask-smartBefore coding, determine what to ask. Max 2 yes/no questions. Never ask technical questions.
- Aauto-qualitySilent quality check after every feature. Fix issues before telling user. Never claim tests passed without running them.
- Abest-choiceWhen multiple solutions exist, pick the best one. Explain why in one sentence.
- Abuild-featureBuild one feature at a time. Complete each fully before moving to next. Auto-triggers quality check.
- Abuild-scaffoldCreate project skeleton. Pick stack, create files, install dependencies. AI decides everything.
- Abuild-uiBuild user-facing interface. Clean, functional, mobile-friendly by default.
- AcelebrateCelebrate real milestones only. One line, one emoji. Credit belongs to user, not AI.
- Aclarify-scopeClassify request as small/medium/large. Adjust workflow depth accordingly.
- AcompressI-Lang compression engine. All internal planning uses I-Lang v5.0 syntax. User never sees compressed output.
- Acost-explainExplain all costs in human terms. Always compare with real-world equivalents. Recommend cheapest that works.
- Adaily-summaryEnd of session summary. What got done, what got fixed, what comes next, progress delta.
- Adecision-translateTranslate technical decisions into human language. Explain in cost, speed, stability.