secrets-scan
25backspace-shmackspace/claude-devkit
Skill Claude CodeCodex
Pre-commit secrets detection with pattern-based scanning for API keys, tokens, passwords, private keys, and connection strings. Self-contained — no external tools required.
backspace-shmackspace/claude-devkit
Skill Claude CodeCodex
Pre-commit secrets detection with pattern-based scanning for API keys, tokens, passwords, private keys, and connection strings. Self-contained — no external tools required.
backspace-shmackspace/claude-devkit
Skill Claude CodeCodex
Deep semantic security review of code changes with data flow tracing, taint analysis, and trust boundary validation. Composable building block invoked by /audit when deployed.
backspace-shmackspace/claude-devkit
Skill Claude CodeCodex
Run Semgrep static analysis scan on a codebase using parallel subagents. Supports two scan modes — "run all" (full ruleset coverage) and "important only" (high-confidence security vulnerabilities). Automatically detects and uses Semgrep Pro for cross-file taint analysis when available. Use when asked to scan code for…
backspace-shmackspace/claude-devkit
Skill Claude CodeCodex
Execute an approved plan using unattended implementation and validation with worktree isolation.
backspace-shmackspace/claude-devkit
Skill Claude CodeCodex
Synchronize CLAUDE.md and README with recent code changes.
backspace-shmackspace/claude-devkit
Skill Claude CodeCodex
Use when planning security-sensitive features — authentication, authorization, data handling, API design, cryptography, or network configuration — requires explicit threat modeling before implementation decisions are made.
backspace-shmackspace/claude-devkit
Skill Claude CodeCodex
Use when performing threat modeling for a project, feature, or system architecture. Applies STRIDE threat categorization with DREAD risk rating to produce structured threat models in OTM JSON and markdown formats. Covers system decomposition, trust boundary mapping, data flow analysis, per-subsystem threat…
backspace-shmackspace/claude-devkit
Skill Claude CodeCodex
Use when about to claim work is complete, before committing or creating PRs - requires fresh verification evidence before any completion claim. Triggers on phrases like "done", "finished", "ready to commit", "all tests pass", "looks good", "should work", "I think that's it".
backspace-shmackspace/deep-code-security
Agent Claude Code
Security-focused code review specialist for deep-code-security — deep-dive reviews for sandbox, taint engine, and MCP server code.
backspace-shmackspace/deep-code-security
Agent Claude Code
Code review specialist for deep-code-security — security-first review for SAST tooling.
backspace-shmackspace/deep-code-security
Agent Claude Code
Code implementation specialist for deep-code-security.
backspace-shmackspace/deep-code-security
Agent Claude Code
QA testing specialist for deep-code-security — validates SAST accuracy, sandbox safety, and pipeline correctness.
backspace-shmackspace/deep-code-security
Agent Claude Code
Security threat modeling specialist for deep-code-security — a SAST tool that itself must be secure.
backspace-shmackspace/deep-code-security
Agent Claude Code
High-level design and implementation planning for deep-code-security — a multi-language SAST product with agentic verification.
backspace-shmackspace/deep-code-security
Instructions file
Claude Code instructions for backspace-shmackspace/deep-code-security, covering deep-code-security -- claude code project guide, project overview, architecture, critical rules and security (non-negotiable).
backspace-shmackspace/deep-code-security
MCP server Claude CodeCodexCursor +2
MCP server "deep-code-security" as configured in backspace-shmackspace/deep-code-security. Runs locally from the deep-code-security Python package.