Skip to main content

🛡️ CyberSecurity Superpowers

The Ultimate Enterprise DevSecOps & Cybersecurity Extension for AI Coding Agents. Embed automated threat modeling, secure coding, SAST scanning, red-team penetration testing, NIST incident response, and supply-chain security into any agentic workflow.

CI Pipeline [Release](https://github.com/rohit-barui/CyberSecurity-Superpowers/actions/workflows/release.yml[...] PyPI Skills Version License Standards


⚡ Why CyberSecurity Superpowers is THE Go-To Skill Set

AI coding assistants are faster than ever at writing code — but speed without security creates vulnerabilities at scale. CyberSecurity Superpowers transforms any AI assistant (Claude Code, G[...]

🌟 Key Differentiators & Benefits

  • 🎯 360° SDLC Security Coverage: From pre-code threat modeling to post-breach incident playbooks, cover every phase of security automatically.
  • 🤖 Autonomous ReAct Orchestrator: Intelligently routes tasks to specific security skill modules without manual intervention.
  • 🏆 Industry-Standard Alignment: Native integration with OWASP Top 10, OWASP WSTG, MITRE ATT&CK, NIST SP 800-61, CVSS v3.1, and CycloneDX/SPDX.
  • 🌐 Harness-Agnostic & Zero Lock-in: Works out of the box with any LLM, CLI, or agent runtime on Linux, macOS, and Windows.
  • 📊 Audit-Ready Artifact Generation: Automatically generates structured, version-controlled Markdown & JSON reports in artifacts/reports/.

🚀 Quickstart

Get up and running in 30 seconds. Choose your install method:

📦 One-Click Install (curl | bash)

curl -sSL https://raw.githubusercontent.com/rohit-barui/CyberSecurity-Superpowers/main/install.sh | bash
cybersec demo

🐍 PyPI (pip / pipx)

pipx install cybersec-superpowers
# or: pip install --user cybersec-superpowers
cybersec threat-model "My App"

📁 Git Clone

git clone https://github.com/rohit-barui/CyberSecurity-Superpowers.git
cd CyberSecurity-Superpowers
bash scripts/setup.sh
bash examples/demo-project/run-demo.sh

🧩 The 6 Core Cybersecurity Superpowers

Superpower Description Industry Standard Output Artifact
🧠 Threat Modeling Automated STRIDE threat analysis, trust boundary mapping, & CVSS v3.1 risk scoring NIST SP 800-53 / OWASP ASVS artifacts/reports/stride-model.md
🛡️ Secure Coding Language-specific security checklist enforcement (JS, TS, Python, Go, Rust) OWASP Top 10 artifacts/reports/SECURITY.md
🔍 Static Analysis (SAST) Multi-engine SAST & dependency vulnerability scanning (Semgrep, Bandit, Gosec, NPM Audit) SARIF / CWE / CVE artifacts/reports/SECURITY_SCAN.md
⚔️ Penetration Testing Scoped red-team attack plan generator mapped to offensive tactics MITRE ATT&CK & OWASP WSTG artifacts/reports/pentest-plan.md
🚨 Incident Response Incident playbook generator for Ransomware, Data Breach, Phishing, DDoS, & Insider Threats NIST SP 800-61 Rev. 2 artifacts/reports/incident-playbook.md
📦 Supply-Chain Security Automated SBOM generation (CycloneDX / SPDX) and dependency vulnerability audit NTIA Minimum Elements artifacts/sbom/sbom-report.json

🏗️ Architecture & Orchestration

The system utilizes an autonomous ReAct Orchestrator (scripts/run-orchestrator.sh) that accepts natural language intent or CLI modes and routes them across the underlying security modules:

                  ┌───────────────────────────────┐
                  │    User / AI Agent Intent     │
                  └───────────────┬───────────────┘
                                  │
                                  ▼
                  ┌───────────────────────────────┐
                  │      ReAct Orchestrator       │
                  │   (scripts/run-orchestrator)  │
                  └───────────────┬───────────────┘
                                  │
      ┌───────────────┬───────────┼───────────┬───────────────┐
      ▼               ▼           ▼           ▼               ▼
┌───────────┐   ┌───────────┐ ┌───────────┐ ┌───────────┐   ┌─────────��[...]
│  Threat   │   │  Secure   │ │  Static   │ │   Pentest │   │ Incident  │
│ Modeling  │   │  Coding   │ │ Analysis  │ │   Plan    │   │ Response  │
└─────┬─────┘   └─────┬─────┘ └─────┬─────┘ └─────┬─────┘   └─────┬───��[...]
      │               │           │           │               │
      └───────────────┴───────────┼───────────┴───────────────┘
                                  │
                                  ▼
                  ┌───────────────────────────────┐
                  │ Audit-Ready Markdown & JSON   │
                  │ (artifacts/reports/*.md)      │
                  └───────────────────────────────┘

💻 Usage & CLI Examples

Automated Orchestration

# Run Secure Coding + SAST on current codebase
bash scripts/run-orchestrator.sh implement "Authentication microservice"

# Generate complete Threat Model for a project
bash scripts/run-orchestrator.sh threat-model "Payment Gateway API"

# Run full 5-phase security suite
bash scripts/run-orchestrator.sh full "Production Release Candidate"

Direct Skill Execution

# Threat Modeling
bash skills/cybersecurity/threat-modeling/run.sh --project "E-Commerce System"

# Secure Coding Checklists
bash skills/cybersecurity/secure-coding/run.sh --language python --target-dir ./src

# Static Analysis (SAST)
bash skills/cybersecurity/static-analysis/run.sh --target-dir ./src --format md

# Penetration Testing Plan
bash skills/cybersecurity/penetration-testing/run.sh --target-app "Portal API" --scope web

# Incident Response Playbook
bash skills/cybersecurity/incident-response/run.sh --incident-type ransomware

# Supply Chain SBOM Generation
bash scripts/generate-sbom.sh --target-dir .

Git Hooks & DevSecOps Automation

Protect your main branch automatically before commits and pushes:

# Install automated Git hooks (Pre-commit SAST & Pre-push security gates)
bash scripts/init-project.sh

🛡️ CI/CD Pipeline

Every commit and pull request is automatically validated by GitHub Actions (.github/workflows/ci.yml):

  • ✅ Lint & Frontmatter Validation: ShellCheck, Yamllint, and SKILL.md spec validation.
  • ✅ Automated Skill Tests: End-to-end unit test execution across all 6 superpowers (tests/run-skill-tests.sh).
  • ✅ Orchestrator Verification: Live execution check of the orchestrator pipeline.
  • ✅ Security Gate Build: Summary matrix validation with non-zero exit enforcement on failure.

👥 Contributing

We welcome community contributions! Check out our Good First Issues and review CONTRIBUTING.md to get started.


📄 License

This project is licensed under the GNU Affero General Public License v3.0 (AGPL-3.0). Feel free to use, adapt, and build upon it under the terms of the AGPL-3.0.


Built with ❤️ for the AI Security & DevSecOps Community.

Metadata

Release files for cybersec-superpowers 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cybersec-superpowers 0.1.1
File Size Uploaded
cybersec_superpowers-0.1.1.tar.gz 10.7 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for cybersec-superpowers 0.1.1
File Interpreter ABI Platform
cybersec_superpowers-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 10.7 MB

Release files / cybersec_superpowers-0.1.1.tar.gz

Download URL cybersec_superpowers-0.1.1.tar.gz
Size 10.7 MB
Tags Source
SHA-256 checksum
How to use checksums
c7ad562ed925cf4c46e1e9f29c8af728d84f0d2a464a79b24f19595b5ee27bd9
BLAKE2b-256 checksum
How to use checksums
4d0cbe9ed55a3ba06137cfbe9461b259f6d59d11416981dd792aa4ab83fbc653
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.5

Release files / cybersec_superpowers-0.1.1-py3-none-any.whl

Download URL cybersec_superpowers-0.1.1-py3-none-any.whl
Size 15.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
22d5e3124e38f4588dcf6e544d3c219a757e0dc8cb5644a733f40e4c9ebef098
BLAKE2b-256 checksum
How to use checksums
4f2a9a5616c78b63826e81fd91dfd7ef4d78c6abb93c859601c5b62d45be051f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.5

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page