Bitrix Marketplace Security Skills

AI Security Skills

A skill set for security-auditing Bitrix PHP modules before Marketplace submission: scan, severity review, a running journal

SkillOfficialEditors’ pick

Low risk

We rate an entry low when it mostly gives the agent instructions and reference material.

Why this level

  • Only reads module code and writes local JSON reports; it does not connect to a live portal
All reasons and checks
Russian stack

bitrix-tools/marketplace-security-skills

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add skills/ai-security-skills

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Assembled automatically, review before installing.

Run in a terminal in the project folder

npx skills add bitrix-tools/marketplace-security-skills --skill scan journal-review journal-update using-marketplace-sec scan-composer -a claude-code -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Without third-party tools, from commit 0cdb4e3
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .claude/skills
cp -R "$tmp/skills/bitrix-security/scan" .claude/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .claude/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .claude/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .claude/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .claude/skills/scan-composer

Commands for macOS and Linux, on Windows run them in Git Bash.

Run in a terminal in the project folder

npx skills add bitrix-tools/marketplace-security-skills --skill scan journal-review journal-update using-marketplace-sec scan-composer -a cursor -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Without third-party tools, from commit 0cdb4e3
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .agents/skills
cp -R "$tmp/skills/bitrix-security/scan" .agents/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .agents/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .agents/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .agents/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .agents/skills/scan-composer

Commands for macOS and Linux, on Windows run them in Git Bash.

Run in a terminal in the project folder

npx skills add bitrix-tools/marketplace-security-skills --skill scan journal-review journal-update using-marketplace-sec scan-composer -a github-copilot -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Without third-party tools, from commit 0cdb4e3
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .github/skills
cp -R "$tmp/skills/bitrix-security/scan" .github/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .github/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .github/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .github/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .github/skills/scan-composer

Commands for macOS and Linux, on Windows run them in Git Bash.

Run in a terminal in the project folder

npx skills add bitrix-tools/marketplace-security-skills --skill scan journal-review journal-update using-marketplace-sec scan-composer -a codex -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Without third-party tools, from commit 0cdb4e3
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .agents/skills
cp -R "$tmp/skills/bitrix-security/scan" .agents/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .agents/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .agents/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .agents/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .agents/skills/scan-composer

Commands for macOS and Linux, on Windows run them in Git Bash.

Run in a terminal in the project folder

npx skills add bitrix-tools/marketplace-security-skills --skill scan journal-review journal-update using-marketplace-sec scan-composer -a gemini-cli -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Without third-party tools, from commit 0cdb4e3
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .agents/skills
cp -R "$tmp/skills/bitrix-security/scan" .agents/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .agents/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .agents/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .agents/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .agents/skills/scan-composer

Commands for macOS and Linux, on Windows run them in Git Bash.

Run in a terminal in the project folder

tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .devin/skills
cp -R "$tmp/skills/bitrix-security/scan" .devin/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .devin/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .devin/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .devin/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .devin/skills/scan-composer

Commands for macOS and Linux, on Windows run them in Git Bash.

Formerly Windsurf.

Run in a terminal in the project folder

npx skills add bitrix-tools/marketplace-security-skills --skill scan journal-review journal-update using-marketplace-sec scan-composer -a cline -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Without third-party tools, from commit 0cdb4e3
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .cline/skills
cp -R "$tmp/skills/bitrix-security/scan" .cline/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .cline/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .cline/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .cline/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .cline/skills/scan-composer

Commands for macOS and Linux, on Windows run them in Git Bash.

Run in a terminal in the project folder

npx skills add bitrix-tools/marketplace-security-skills --skill scan journal-review journal-update using-marketplace-sec scan-composer -a roo -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Without third-party tools, from commit 0cdb4e3
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .roo/skills
cp -R "$tmp/skills/bitrix-security/scan" .roo/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .roo/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .roo/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .roo/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .roo/skills/scan-composer

Commands for macOS and Linux, on Windows run them in Git Bash.

A fork of Roo Code, same .roo folders.

Run in a terminal in the project folder

npx skills add bitrix-tools/marketplace-security-skills --skill scan journal-review journal-update using-marketplace-sec scan-composer -a opencode -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Without third-party tools, from commit 0cdb4e3
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .agents/skills
cp -R "$tmp/skills/bitrix-security/scan" .agents/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .agents/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .agents/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .agents/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .agents/skills/scan-composer

Commands for macOS and Linux, on Windows run them in Git Bash.

Run in a terminal in the project folder

tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .agents/skills
cp -R "$tmp/skills/bitrix-security/scan" .agents/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .agents/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .agents/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .agents/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .agents/skills/scan-composer

Commands for macOS and Linux, on Windows run them in Git Bash.

Run in a terminal in the project folder

tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .agents/skills
cp -R "$tmp/skills/bitrix-security/scan" .agents/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .agents/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .agents/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .agents/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .agents/skills/scan-composer

Commands for macOS and Linux, on Windows run them in Git Bash.

You will need: Node.js

Checked against the repository on Sep 26, 2026, commit 0cdb4e3.

Text for your agent

Clone bitrix-tools/marketplace-security-skills, call the scan skill with scan modules/vendor.module, then run python3 skills/bitrix-security/journal-review/scripts/review_journal.py reports/vendor.module.json --output reports/vendor.module.reviewed.json to re-review severity.

Other ways from the author
git clone https://github.com/bitrix-tools/marketplace-security-skills.git

The skills are engine-agnostic: SKILL.md files plus Python scripts, runnable in any compatible agent CLI after cloning.

This is third-party code. Review the repository files before installing.

What it does

The project provides a reproducible security workflow made of several skills. Scan runs a two-phase audit of one module: a deterministic recon pass over the code (controllers, AJAX entry points, admin files, handlers, dangerous sinks, aware of Bitrix specifics like ActionFilter and check_bitrix_sessid) followed by a focused review of the findings, saved as a JSON report. Journal-review re-evaluates the raw findings' severity with Bitrix and BUS context in mind (data source, user rights, real exploitability), adding a rationale and confidence level. Journal-update maintains a cumulative security-journal.json across repeated runs with statuses like open. An interactive orchestrator, using-marketplace-sec, ships a local Chart.js UI, and scan-composer offers a single-command headless alternative.

Who it is for. For Bitrix module developers preparing a solution for Marketplace submission who want a reproducible security audit beforehand.

Good fit when

  • You are preparing a Bitrix PHP module for Marketplace submission and need a pre-submission security audit
  • You need a cumulative vulnerability journal across repeated runs, not a one-off report
  • You need severity adjusted for Bitrix specifics, not a raw scanner dump

Not a fit when

  • Your module is not PHP or not built for the Bitrix platform
  • You need the Marketplace's own official moderation process, not a preliminary local audit
  • You need continuous production monitoring, not a one-off pre-submission check

Example request

Run a security audit of the modules/vendor.module module and show me the high-risk findings

Limitations

The skills do not replace the Marketplace's own moderation; they are a local pre-submission check. The recon phase is built for Bitrix encodings, including windows-1251, but finding quality depends on the specific module's structure. reports/*.json files are not committed and remain local run artifacts.

How to disable. Delete the skills/bitrix-security folder from your agent install.

Security check

  • Only reads module code and writes local JSON reports; it does not connect to a live portal

README in short

The Russian README describes the project's five skills: scan, journal-review, journal-update, using-marketplace-sec and scan-composer, and their role in a pre-submission flow. It details the scanner's recon-phase properties: handling Cyrillic and windows-1251, and Bitrix-specific patterns and sinks. It gives run commands for journal-review and journal-update with --validate-only and --previous flags, finding statuses in the cumulative journal, and the skills, reports and tools folder layout with a local UI server.

FAQ

How is journal-review different from scan?

Scan finds issues and assigns a raw severity, while journal-review re-evaluates it with Bitrix context and real exploitability in mind, keeping the original finding fields.

Can I run the whole process with one command?

Yes, the scan-composer skill is a headless orchestrator with no UI for the whole pipeline.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIBitrix Marketplace Security Skills

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.