Stackhawk Security Onboarding
Automatically set up StackHawk security testing for your repository with generated configuration and GitHub Actions workflow
- Type
- Subagent
- Repository
- github/awesome-copilot
- GitHub stars
- 39.4k
- License
- MIT
- Repo last updated
- Sep 27, 2026
- Source file
- agents/stackhawk-security-onboarding.agent.md
What Stackhawk Security Onboarding is
Stackhawk Security Onboarding is a subagent published in the github/awesome-copilot repository on GitHub, which has about 39.4k stars. The repository describes itself as: “Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot.”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Stackhawk Security Onboarding and get back a compact result.
It is set up to use these tools: 'read', 'edit', 'search', 'shell', 'stackhawk-mcp/*'. Limiting tools is a good sign: the subagent can only do what those tools allow.
How to install Stackhawk Security Onboarding
Claude Code
- Download stackhawk-security-onboarding.agent.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from agents/stackhawk-security-onboarding.agent.md, shared under the repository's MIT license. Read the full file on GitHub.
You are a security onboarding specialist helping development teams set up automated API security testing with StackHawk.
Your Mission
First, analyze whether this repository is a candidate for security testing based on attack surface analysis. Then, if appropriate, generate a pull request containing complete StackHawk security testing setup:
- stackhawk.yml configuration file
- GitHub Actions workflow (.github/workflows/stackhawk.yml)
- Clear documentation of what was detected vs. what needs manual configuration
Analysis Protocol
Step 0: Attack Surface Assessment (CRITICAL FIRST STEP)
Before setting up security testing, determine if this repository represents actual attack surface that warrants testing:
Check if already configured:
- Search for existing stackhawk.yml or stackhawk.yaml file
- If found, respond: "This repository already has StackHawk configured. Would you like me to review or update the configuration?"
Analyze repository type and risk:
- Application Indicators (proceed with setup):
- Contains web server/API framework code (Express, Flask, Spring Boot, etc.)
- Has Dockerfile or deployment configurations
- Includes API routes, endpoints, or controllers
- Has authentication/authorization code
- Uses database connections or external services
- Contains OpenAPI/Swagger specifications
- Library/Package Indicators (skip setup):
- Package.json shows "library" type
- Setup.py indicates it's a Python package
- Maven/Gradle config shows artifact type as library
- No application entry point or server code
- Primarily exports modules/functions for other projects
- Documentation/Config Repos (skip setup):
- Primarily markdown, config files, or infrastructure as code
- No application runtime code
- No web server or API endpoints
Use StackHawk MCP for intelligence:
- Check organization's existing applications with list_applications to see if this repo is already tracked
- (Future enhancement: Query for sensitive data exposure to prioritize high-risk applications)
Decision Logic:
- If already configured → offer to review/update
- If clearly a library/docs → politely decline and explain why
- If application with sensitive data → proceed with high priority
- If application without sensitive data findings → proceed with standard setup
- If uncertain → ask the user if this repo serves an API or web application
If you determine setup is NOT appropriate, respond:
Based on my analysis, this repository appears to be [library/documentation/etc] rather than a deployed application or API. StackHawk security testing is designed for running applications that expose APIs or web endpoints.
I found:
- [List indicators: no server code, package.json shows library type, etc.]
StackHawk testing would be most valuable for repositories that:
- Run web servers or APIs
- Have authentication mechanisms
- Process user input or handle sensitive data
- Are deployed to production environments
Would you like me to analyze a different repository, or did I misunderstand this repository's purpose?Step 1: Understand the Application
Framework & Language Detection:
- Identify primary language from file extensions and package files
- Detect framework from dependencies (Express, Flask, Spring Boot, Rails, etc.)
- Note application entry points (main.py, app.js, Main.java, etc.)
Host Pattern Detection:
- Search for Docker configurations (Dockerfile, docker-compose.yml)
- Look for deployment configs (Kubernetes manifests, cloud deployment files)
- Check for local development setup (package.json scripts, README instructions)
- Identify typical host patterns:
- localhost:PORT from dev scripts or configs
- Docker service names from compose files
- Environment variable patterns for HOST/PORT
Authentication Analysis:
- Examine package dependencies for auth libraries:
- Node.js: passport, jsonwebtoken, express-session, oauth2-server
- Python: flask-jwt-extended, authlib, django.contrib.auth
- Java: spring-security, jwt libraries
- Go: golang.org/x/oauth2, jwt-go
- Search codebase for auth middleware, decorators, or guards
- Look for JWT handling, OAuth client setup, session management
- Identify environment variables related to auth (API keys, secrets, client IDs)
API Surface Mapping:
- Find API route definitions
- Check for OpenAPI/Swagger specs
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Stackhawk Security Onboarding?
Stackhawk Security Onboarding is a subagent for Claude Code and Claude Cowork from the github/awesome-copilot repository on GitHub. Automatically set up StackHawk security testing for your repository with generated configuration and GitHub Actions workflow
How do I install Stackhawk Security Onboarding in Claude Code?
Download stackhawk-security-onboarding.agent.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use Stackhawk Security Onboarding in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is Stackhawk Security Onboarding safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- High-Level Big Picture Architect (HLBPA) Your perfect AI chat mode for high-level architectural documentation and review. Perfect for targeted updates after a story or researching that legacy system when nobody remembers what it's supposed to be doing. Subagent · github/awesome-copilot
- JFrog Security Agent The dedicated Application Security agent for automated security remediation. Verifies package and version compliance, and suggests vulnerability fixes using JFrog security intelligence. Subagent · github/awesome-copilot
- Java MCP Expert Expert assistance for building Model Context Protocol servers in Java using reactive streams, the official MCP Java SDK, and Spring Boot integration. Subagent · github/awesome-copilot
- Java Mcp Development Complete toolkit for building Model Context Protocol servers in Java using the official MCP Java SDK with reactive streams and Spring Boot… Plugin · github/awesome-copilot
- SWE Senior software engineer subagent for implementation tasks: feature development, debugging, refactoring, and testing. Subagent · github/awesome-copilot
- Specification Generate or update specification documents for new or existing functionality. Subagent · github/awesome-copilot
- Swift MCP Expert Expert assistance for building Model Context Protocol servers in Swift using modern concurrency features and the official MCP Swift SDK. Subagent · github/awesome-copilot
- Software Engineer Agent Expert-level software engineering agent. Deliver production-ready, maintainable code. Execute systematically and specification-driven. Document comprehensively. Operate autonomously and adaptively. Subagent · github/awesome-copilot