Bitrix Marketplace Security Skills
AI Security Skills
A skill set for security-auditing Bitrix PHP modules before Marketplace submission: scan, severity review, a running journal
Low risk
We rate an entry low when it mostly gives the agent instructions and reference material.
Why this level
- Only reads module code and writes local JSON reports; it does not connect to a live portal
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add skills/ai-security-skillsDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Assembled automatically, review before installing.
Run in a terminal in the project folder
npx skills add bitrix-tools/marketplace-security-skills --skill scan journal-review journal-update using-marketplace-sec scan-composer -a claude-code -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 0cdb4e3
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .claude/skills
cp -R "$tmp/skills/bitrix-security/scan" .claude/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .claude/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .claude/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .claude/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .claude/skills/scan-composerCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add bitrix-tools/marketplace-security-skills --skill scan journal-review journal-update using-marketplace-sec scan-composer -a cursor -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 0cdb4e3
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .agents/skills
cp -R "$tmp/skills/bitrix-security/scan" .agents/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .agents/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .agents/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .agents/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .agents/skills/scan-composerCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add bitrix-tools/marketplace-security-skills --skill scan journal-review journal-update using-marketplace-sec scan-composer -a github-copilot -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 0cdb4e3
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .github/skills
cp -R "$tmp/skills/bitrix-security/scan" .github/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .github/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .github/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .github/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .github/skills/scan-composerCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add bitrix-tools/marketplace-security-skills --skill scan journal-review journal-update using-marketplace-sec scan-composer -a codex -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 0cdb4e3
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .agents/skills
cp -R "$tmp/skills/bitrix-security/scan" .agents/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .agents/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .agents/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .agents/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .agents/skills/scan-composerCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add bitrix-tools/marketplace-security-skills --skill scan journal-review journal-update using-marketplace-sec scan-composer -a gemini-cli -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 0cdb4e3
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .agents/skills
cp -R "$tmp/skills/bitrix-security/scan" .agents/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .agents/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .agents/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .agents/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .agents/skills/scan-composerCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .devin/skills
cp -R "$tmp/skills/bitrix-security/scan" .devin/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .devin/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .devin/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .devin/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .devin/skills/scan-composerCommands for macOS and Linux, on Windows run them in Git Bash.
Formerly Windsurf.
Run in a terminal in the project folder
npx skills add bitrix-tools/marketplace-security-skills --skill scan journal-review journal-update using-marketplace-sec scan-composer -a cline -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 0cdb4e3
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .cline/skills
cp -R "$tmp/skills/bitrix-security/scan" .cline/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .cline/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .cline/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .cline/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .cline/skills/scan-composerCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add bitrix-tools/marketplace-security-skills --skill scan journal-review journal-update using-marketplace-sec scan-composer -a roo -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 0cdb4e3
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .roo/skills
cp -R "$tmp/skills/bitrix-security/scan" .roo/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .roo/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .roo/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .roo/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .roo/skills/scan-composerCommands for macOS and Linux, on Windows run them in Git Bash.
A fork of Roo Code, same .roo folders.
Run in a terminal in the project folder
npx skills add bitrix-tools/marketplace-security-skills --skill scan journal-review journal-update using-marketplace-sec scan-composer -a opencode -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 0cdb4e3
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .agents/skills
cp -R "$tmp/skills/bitrix-security/scan" .agents/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .agents/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .agents/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .agents/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .agents/skills/scan-composerCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .agents/skills
cp -R "$tmp/skills/bitrix-security/scan" .agents/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .agents/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .agents/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .agents/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .agents/skills/scan-composerCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/bitrix-tools/marketplace-security-skills.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/bitrix-security/scan/ /skills/bitrix-security/journal-review/ /skills/bitrix-security/journal-update/ /skills/bitrix-security/using-marketplace-sec/ /skills/bitrix-security/scan-composer/
git -C "$tmp" checkout 0cdb4e3fee90b825a0088870712d1dce0f6683f5
mkdir -p .agents/skills
cp -R "$tmp/skills/bitrix-security/scan" .agents/skills/scan
cp -R "$tmp/skills/bitrix-security/journal-review" .agents/skills/journal-review
cp -R "$tmp/skills/bitrix-security/journal-update" .agents/skills/journal-update
cp -R "$tmp/skills/bitrix-security/using-marketplace-sec" .agents/skills/using-marketplace-sec
cp -R "$tmp/skills/bitrix-security/scan-composer" .agents/skills/scan-composerCommands for macOS and Linux, on Windows run them in Git Bash.
Clone bitrix-tools/marketplace-security-skills, call the scan skill with scan modules/vendor.module, then run python3 skills/bitrix-security/journal-review/scripts/review_journal.py reports/vendor.module.json --output reports/vendor.module.reviewed.json to re-review severity.
Other ways from the author
git clone https://github.com/bitrix-tools/marketplace-security-skills.gitThe skills are engine-agnostic: SKILL.md files plus Python scripts, runnable in any compatible agent CLI after cloning.
This is third-party code. Review the repository files before installing.
What it does
The project provides a reproducible security workflow made of several skills. Scan runs a two-phase audit of one module: a deterministic recon pass over the code (controllers, AJAX entry points, admin files, handlers, dangerous sinks, aware of Bitrix specifics like ActionFilter and check_bitrix_sessid) followed by a focused review of the findings, saved as a JSON report. Journal-review re-evaluates the raw findings' severity with Bitrix and BUS context in mind (data source, user rights, real exploitability), adding a rationale and confidence level. Journal-update maintains a cumulative security-journal.json across repeated runs with statuses like open. An interactive orchestrator, using-marketplace-sec, ships a local Chart.js UI, and scan-composer offers a single-command headless alternative.
Who it is for. For Bitrix module developers preparing a solution for Marketplace submission who want a reproducible security audit beforehand.
Good fit when
- You are preparing a Bitrix PHP module for Marketplace submission and need a pre-submission security audit
- You need a cumulative vulnerability journal across repeated runs, not a one-off report
- You need severity adjusted for Bitrix specifics, not a raw scanner dump
Not a fit when
- Your module is not PHP or not built for the Bitrix platform
- You need the Marketplace's own official moderation process, not a preliminary local audit
- You need continuous production monitoring, not a one-off pre-submission check
Example request
Run a security audit of the modules/vendor.module module and show me the high-risk findingsLimitations
The skills do not replace the Marketplace's own moderation; they are a local pre-submission check. The recon phase is built for Bitrix encodings, including windows-1251, but finding quality depends on the specific module's structure. reports/*.json files are not committed and remain local run artifacts.
How to disable. Delete the skills/bitrix-security folder from your agent install.
Security check
- Only reads module code and writes local JSON reports; it does not connect to a live portal
README in short
The Russian README describes the project's five skills: scan, journal-review, journal-update, using-marketplace-sec and scan-composer, and their role in a pre-submission flow. It details the scanner's recon-phase properties: handling Cyrillic and windows-1251, and Bitrix-specific patterns and sinks. It gives run commands for journal-review and journal-update with --validate-only and --previous flags, finding statuses in the cumulative journal, and the skills, reports and tools folder layout with a local UI server.
FAQ
How is journal-review different from scan?
Scan finds issues and assigns a raw severity, while journal-review re-evaluates it with Bitrix context and real exploitability in mind, keeping the original finding fields.
Can I run the whole process with one command?
Yes, the scan-composer skill is a headless orchestrator with no UI for the whole pipeline.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents