AI Coding Agents AI security skills
Antigravity CLI, GitHub Copilot CLI, Claude Code, and OpenAI Codex workflows for secure review, remediation, CI/CD audit, and agent governance.
Security tool skills
Practical, evidence-first workflows for using AI with SIEM, CNAPP, endpoint, identity, AppSec, vulnerability management, and model gateway tools without losing control. Now includes secure coding-agent workflows for Antigravity CLI, GitHub Copilot CLI, Claude Code, and OpenAI Codex.

Antigravity CLI, GitHub Copilot CLI, Claude Code, and OpenAI Codex workflows for secure review, remediation, CI/CD audit, and agent governance.
Alert triage, SPL drafting, detection tuning, incident timelines, and SOC handoffs.
Attack path summaries, exposure prioritization, cloud ownership, and remediation planning.
Firewall policy review, Prisma Cloud risk summaries, Cortex investigations, and change review.
Endpoint process tree summaries, containment notes, threat hunting, and incident updates.
KQL query drafting, incident summaries, Microsoft 365 investigations, and automation review.
Suspicious login review, policy analysis, access review, identity incident recovery, and blast-radius summaries.
Pull request security review, code scanning triage, secret response, dependency review, and CI/CD checks.
Vulnerability clustering, container triage, SBOM review, IaC remediation, and risk briefs.
Model gateway policy review, virtual key control, token budgets, prompt log triage, and provider routing.
Coding agents
The safest pattern is not one magic assistant. It is a governed toolchain where each coding agent has a clear job, bounded access, auditable output, and human approval for risky changes.
Repository-scale implementation, secure refactors, test generation, and evidence-backed code changes.
Guardrail
Run in a branch, require diffs and tests, restrict secrets, and keep deployment behind human approval.
Security review, threat-model drafting, dependency triage, and explaining complex code paths.
Guardrail
Keep skills versioned, review tool permissions, and avoid broad filesystem or shell access for untrusted workflows.
Developer-in-IDE secure coding support, pull request assistance, tests, and lightweight remediation guidance.
Guardrail
Pair with branch protection, code scanning, secret scanning, dependency review, and required reviewer policies.
Command-line AI-assisted investigation, repetitive security checks, local developer workflows, and scripted triage.
Guardrail
Scope shell commands, log prompts and outputs, avoid production credentials, and prefer read-only investigation by default.
Operating model
Splunk events, Wiz graph paths, CrowdStrike detections, Okta logs, GitHub alerts, and Trivy findings should remain traceable in every AI-generated summary.
Let AI draft queries, tickets, summaries, and remediation plans. Keep containment, policy changes, identity changes, and production deploys behind human review.