Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.
.claude/skills/davila7-senior-security/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 17% | 0% |
| case-03 | ✗→✓ | ▲ Improved | -19% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 51% | 0% |
| case-08 | ✗→✓ | ▲ Improved | 20% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 46% | 0% |
Complete toolkit for senior security with modern tools and best practices.
This skill provides three core capabilities through automated scripts:
bash# Script 1: Threat Modeler python scripts/threat_modeler.py [options] # Script 2: Security Auditor python scripts/security_auditor.py [options] # Script 3: Pentest Automator python scripts/pentest_automator.py [options]
Automated tool for threat modeler tasks.
Features:
Usage:
bashpython scripts/threat_modeler.py <project-path> [options]
Comprehensive analysis and optimization tool.
Features:
Usage:
bashpython scripts/security_auditor.py <target-path> [--verbose]
Advanced tooling for specialized tasks.
Features:
Usage:
bashpython scripts/pentest_automator.py [arguments] [options]
Comprehensive guide available in references/security_architecture_patterns.md:
Complete workflow documentation in references/penetration_testing_guide.md:
Technical reference guide in references/cryptography_implementation.md:
Languages: TypeScript, JavaScript, Python, Go, Swift, Kotlin Frontend: React, Next.js, React Native, Flutter Backend: Node.js, Express, GraphQL, REST APIs Database: PostgreSQL, Prisma, NeonDB, Supabase DevOps: Docker, Kubernetes, Terraform, GitHub Actions, CircleCI Cloud: AWS, GCP, Azure
bash# Install dependencies npm install # or pip install -r requirements.txt # Configure environment cp .env.example .env
bash# Use the analyzer script python scripts/security_auditor.py . # Review recommendations # Apply fixes
Follow the patterns and practices documented in:
references/security_architecture_patterns.mdreferences/penetration_testing_guide.mdreferences/cryptography_implementation.mdbash# Development npm run dev npm run build npm run test npm run lint # Analysis python scripts/security_auditor.py . python scripts/pentest_automator.py --analyze # Deployment docker build -t app:latest . docker-compose up -d kubectl apply -f k8s/
Check the comprehensive troubleshooting section in references/cryptography_implementation.md.
references/security_architecture_patterns.mdreferences/penetration_testing_guide.mdreferences/cryptography_implementation.mdscripts/ directory| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 7,477 | 4,310 | -42% | 1 | 1 | 0% | 1,440 | 1,690 | +17% | 0 | 0 | — |
case-02 | fail→fail | 13,863 | 8,502 | -39% | 1 | 1 | 0% | 1,119 | 1,976 | +77% | 0 | 0 | — |
case-03 | fail→pass | 8,169 | 1,722 | -79% | 1 | 1 | 0% | 1,508 | 1,225 | -19% | 0 | 0 | — |
case-04 | pass→pass | 14,337 | 14,152 | -1% | 1 | 1 | 0% | 3,062 | 3,912 | +28% | 0 | 0 | — |
case-05 | pass→pass | 11,651 | 11,941 | +2% | 1 | 1 | 0% | 2,330 | 3,315 | +42% | 0 | 0 | — |
case-06 | pass→pass | 11,646 | 8,712 | -25% | 1 | 1 | 0% | 2,280 | 2,665 | +17% | 0 | 0 | — |
case-07 | fail→pass | 5,634 | 2,150 | -62% | 1 | 1 | 0% | 908 | 1,373 | +51% | 0 | 0 | — |
case-08 | fail→pass | 5,863 | 4,932 | -16% | 1 | 1 | 0% | 1,022 | 1,224 | +20% | 0 | 0 | — |
case-09 | fail→pass | 4,729 | 3,252 | -31% | 1 | 1 | 0% | 837 | 1,219 | +46% | 0 | 0 | — |
case-18 | pass→pass | 3,814 | 3,172 | -17% | 1 | 1 | 0% | 586 | 1,171 | +100% | 0 | 0 | — |
case-10 | fail→pass | 11,369 | 1,472 | -87% | 1 | 1 | 0% | 2,190 | 1,244 | -43% | 0 | 0 | — |
case-11 | fail→pass | 10,032 | 3,472 | -65% | 1 | 1 | 0% | 1,749 | 1,419 | -19% | 0 | 0 | — |
case-12 | pass→pass | 3,263 | 1,114 | -66% | 1 | 1 | 0% | 589 | 1,172 | +99% | 0 | 0 | — |
case-13 | pass→pass | 3,239 | 1,448 | -55% | 1 | 1 | 0% | 560 | 1,155 | +106% | 0 | 0 | — |
case-14 | pass→pass | 2,074 | 2,089 | +1% | 1 | 1 | 0% | 331 | 1,277 | +286% | 0 | 0 | — |
case-15 | pass→pass | 2,613 | 1,745 | -33% | 1 | 1 | 0% | 429 | 1,219 | +184% | 0 | 0 | — |
case-16 | pass→pass | 4,550 | 1,583 | -65% | 1 | 1 | 0% | 914 | 1,156 | +26% | 0 | 0 | — |
case-17 | pass→pass | 4,567 | 1,488 | -67% | 1 | 1 | 0% | 919 | 1,175 | +28% | 0 | 0 | — |
case-19 | pass→pass | 10,043 | 9,064 | -10% | 1 | 1 | 0% | 373 | 1,346 | +261% | 0 | 0 | — |
case-20 | fail→pass | 12,915 | 1,338 | -90% | 1 | 1 | 0% | 2,223 | 1,156 | -48% | 0 | 0 | — |
case-21 | pass→pass | 5,507 | 5,893 | +7% | 1 | 1 | 0% | 950 | 2,010 | +112% | 0 | 0 | — |
case-22 | pass→pass | 5,803 | 2,451 | -58% | 1 | 1 | 0% | 1,008 | 1,381 | +37% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +36 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.