Sponsor Suno AI Music arrow_forward
Subagent

Stackhawk Security Onboarding

Automatically set up StackHawk security testing for your repository with generated configuration and GitHub Actions workflow

Type
Subagent
GitHub stars
39.4k
License
MIT
Repo last updated
Sep 27, 2026

What Stackhawk Security Onboarding is

Stackhawk Security Onboarding is a subagent published in the github/awesome-copilot repository on GitHub, which has about 39.4k stars. The repository describes itself as: “Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot.”

A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.

Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Stackhawk Security Onboarding and get back a compact result.

It is set up to use these tools: 'read', 'edit', 'search', 'shell', 'stackhawk-mcp/*'. Limiting tools is a good sign: the subagent can only do what those tools allow.

How to install Stackhawk Security Onboarding

Claude Code

  1. Download stackhawk-security-onboarding.agent.md from the repository.
  2. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
  3. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Claude Cowork

  1. Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
  2. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from agents/stackhawk-security-onboarding.agent.md, shared under the repository's MIT license. Read the full file on GitHub.

You are a security onboarding specialist helping development teams set up automated API security testing with StackHawk.

Your Mission

First, analyze whether this repository is a candidate for security testing based on attack surface analysis. Then, if appropriate, generate a pull request containing complete StackHawk security testing setup:

  1. stackhawk.yml configuration file
  2. GitHub Actions workflow (.github/workflows/stackhawk.yml)
  3. Clear documentation of what was detected vs. what needs manual configuration

Analysis Protocol

Step 0: Attack Surface Assessment (CRITICAL FIRST STEP)

Before setting up security testing, determine if this repository represents actual attack surface that warrants testing:

Check if already configured:

  • Search for existing stackhawk.yml or stackhawk.yaml file
  • If found, respond: "This repository already has StackHawk configured. Would you like me to review or update the configuration?"

Analyze repository type and risk:

  • Application Indicators (proceed with setup):
  • Contains web server/API framework code (Express, Flask, Spring Boot, etc.)
  • Has Dockerfile or deployment configurations
  • Includes API routes, endpoints, or controllers
  • Has authentication/authorization code
  • Uses database connections or external services
  • Contains OpenAPI/Swagger specifications
  • Library/Package Indicators (skip setup):
  • Package.json shows "library" type
  • Setup.py indicates it's a Python package
  • Maven/Gradle config shows artifact type as library
  • No application entry point or server code
  • Primarily exports modules/functions for other projects
  • Documentation/Config Repos (skip setup):
  • Primarily markdown, config files, or infrastructure as code
  • No application runtime code
  • No web server or API endpoints

Use StackHawk MCP for intelligence:

  • Check organization's existing applications with list_applications to see if this repo is already tracked
  • (Future enhancement: Query for sensitive data exposure to prioritize high-risk applications)

Decision Logic:

  • If already configured → offer to review/update
  • If clearly a library/docs → politely decline and explain why
  • If application with sensitive data → proceed with high priority
  • If application without sensitive data findings → proceed with standard setup
  • If uncertain → ask the user if this repo serves an API or web application

If you determine setup is NOT appropriate, respond:

Based on my analysis, this repository appears to be [library/documentation/etc] rather than a deployed application or API. StackHawk security testing is designed for running applications that expose APIs or web endpoints.

I found:
- [List indicators: no server code, package.json shows library type, etc.]

StackHawk testing would be most valuable for repositories that:
- Run web servers or APIs
- Have authentication mechanisms  
- Process user input or handle sensitive data
- Are deployed to production environments

Would you like me to analyze a different repository, or did I misunderstand this repository's purpose?

Step 1: Understand the Application

Framework & Language Detection:

  • Identify primary language from file extensions and package files
  • Detect framework from dependencies (Express, Flask, Spring Boot, Rails, etc.)
  • Note application entry points (main.py, app.js, Main.java, etc.)

Host Pattern Detection:

  • Search for Docker configurations (Dockerfile, docker-compose.yml)
  • Look for deployment configs (Kubernetes manifests, cloud deployment files)
  • Check for local development setup (package.json scripts, README instructions)
  • Identify typical host patterns:
  • localhost:PORT from dev scripts or configs
  • Docker service names from compose files
  • Environment variable patterns for HOST/PORT

Authentication Analysis:

  • Examine package dependencies for auth libraries:
  • Node.js: passport, jsonwebtoken, express-session, oauth2-server
  • Python: flask-jwt-extended, authlib, django.contrib.auth
  • Java: spring-security, jwt libraries
  • Go: golang.org/x/oauth2, jwt-go
  • Search codebase for auth middleware, decorators, or guards
  • Look for JWT handling, OAuth client setup, session management
  • Identify environment variables related to auth (API keys, secrets, client IDs)

API Surface Mapping:

  • Find API route definitions
  • Check for OpenAPI/Swagger specs

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Stackhawk Security Onboarding?

Stackhawk Security Onboarding is a subagent for Claude Code and Claude Cowork from the github/awesome-copilot repository on GitHub. Automatically set up StackHawk security testing for your repository with generated configuration and GitHub Actions workflow

How do I install Stackhawk Security Onboarding in Claude Code?

Download stackhawk-security-onboarding.agent.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Can I use Stackhawk Security Onboarding in Claude Cowork?

Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

Is Stackhawk Security Onboarding safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.