Agentic GitHub Actions Auditor
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
服务上线前的 AI 安全审查,聚焦需要理解代码语义和业务逻辑的安全问题. An agent skill from 312362115/claude.
$ npx skills add 312362115/claude --skill security-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install 312362115/claude security-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-audit .claude/skills/security-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-audit" agent skill from https://github.com/312362115/claude/tree/main/skills/security-audit into .claude/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/312362115/claude/tree/main/skills/security-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add 312362115/claude --skill security-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install 312362115/claude security-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security-audit .agents/skills/security-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-audit" agent skill from https://github.com/312362115/claude/tree/main/skills/security-audit into .agents/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add 312362115/claude --skill security-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install 312362115/claude security-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security-audit .cursor/skills/security-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-audit" agent skill from https://github.com/312362115/claude/tree/main/skills/security-audit into .cursor/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/312362115/claude.git --path skills/security-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add 312362115/claude --skill security-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install 312362115/claude security-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security-audit .gemini/skills/security-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/312362115/claude/tree/main/skills/security-audit into .gemini/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install 312362115/claude security-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add 312362115/claude --skill security-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security-audit .github/skills/security-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/312362115/claude/tree/main/skills/security-audit into .github/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add 312362115/claude --skill security-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install 312362115/claude security-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security-audit .opencode/skills/security-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/312362115/claude/tree/main/skills/security-audit into .opencode/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-audit服务上线前的 AI 安全审查,聚焦需要理解代码语义和业务逻辑的安全问题. An agent skill from 312362115/claude.
Security Audit is an agent skill from 312362115/claude. 服务上线前的 AI 安全审查,聚焦需要理解代码语义和业务逻辑的安全问题。 覆盖注入防护、认证授权、敏感数据处理、配置安全、业务安全 5 个维度。 适用于 JS/TS 前端、TS/Python 后端项目。 CI/CD 自动化检测(依赖漏洞、敏感信息 grep)不在本 skill 范围内,由流水线承担。 触发词:安全审计、安全检查、上线前检查、有没有漏洞、security audit。 触发场景:release 发版前(强制)、涉及认证/支付/用户数据的改动后(建议)、用户主动要求。
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security review, Prompt injection and agent security and CI/CD. It works with Python and SQL. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 2d4fa49. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Audit loads about 1.3k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 269 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from 312362115/claude at commit 2d4fa49, republished under its MIT licence (© 312362115). 269 words, ~1,267 tokens.
.claude/skills/security-audit/SKILL.md (or your agent's skills folder).CI/CD 拦确定性问题(依赖漏洞、硬编码密钥),本 skill 审需要理解力的问题(数据流追踪、业务逻辑安全)。 两者互补,不重复。
收到审计请求
│
├─ 快速扫描(单模块 / 局部改动 / 敏感模块修改后)
│ 选 1-2 个最相关的维度检查
│ 产出:终端输出结果,不生成报告
│
└─ 完整审计(release 发版前 / 新服务首次上线 / 重大安全相关改动)
5 个维度全量检查
产出:docs/audits/YYYY-MM-DD-<服务名>-audit.mdAskUserQuestion 确认,不要猜package.json / requirements.txt / pyproject.toml / tsconfig.json按以下 5 个维度逐一检查。每个维度都需要读代码,不是凭印象判断。
审查目标:用户可控的输入是否经过正确处理后才进入危险操作。
检查清单:
| 注入类型 | 关注点 | 安全做法 |
|---|---|---|
| SQL 注入 | 原生 SQL 拼接、ORM 的 raw query | 参数化查询、预编译语句 |
| 命令注入 | exec()、child_process、os.system()、subprocess | 避免拼接用户输入到命令,用参数数组 |
| XSS | innerHTML、dangerouslySetInnerHTML、模板中的未转义输出 | 输出转义、CSP 头、避免直接插入 HTML |
| 路径遍历 | 用户输入拼接文件路径、../ 未过滤 | 路径规范化、白名单校验、path.resolve 后检查前缀 |
| SSRF | 用户输入作为 URL 发起服务端请求 | URL 白名单、禁止内网地址、DNS rebinding 防护 |
| 模板注入 | 用户输入直接进入模板引擎渲染 | 避免动态模板编译、使用沙箱 |
审查方法:
审查目标:确保每个需要保护的资源都有正确的认证和授权检查。
检查清单:
| 检查项 | 关注点 |
|---|---|
| 认证覆盖 | 有没有接口"裸奔"——应该要登录但没加认证中间件? |
| 授权粒度 | 用户 A 能不能通过改 ID 访问用户 B 的数据?(IDOR) |
| JWT/Session | 密钥强度、过期时间、刷新机制、注销是否真的失效 |
| CORS 策略 | Access-Control-Allow-Origin 是否过于宽松(*)?credentials 模式下的 origin 检查 |
| 密码策略 | 密码是否 bcrypt/argon2 哈希存储、是否有强度要求 |
| 权限绕过 | 前端隐藏 ≠ 后端鉴权,检查是否只在前端做了权限判断 |
审查方法:
审查目标:敏感数据在存储、传输、日志中是否得到正确保护。
检查清单:
| 检查项 | 关注点 |
|---|---|
| 密码存储 | 是否用了 bcrypt/argon2?是否明文或 MD5/SHA1? |
| 加密算法 | 是否使用了已知弱算法(DES、RC4、MD5 用于加密) |
| 日志脱敏 | 日志里有没有打印密码、token、手机号、身份证号 |
| 错误信息 | 异常响应是否泄露了堆栈、SQL 语句、内部路径 |
| 数据传输 | 敏感 API 是否强制 HTTPS?cookie 是否设置 Secure 和 HttpOnly |
| 前端存储 | token 存 localStorage(可被 XSS 窃取)还是 httpOnly cookie? |
审查方法:
console.log、logger.、print),检查是否包含敏感字段审查目标:安全相关配置是否合理,生产环境是否加固。
检查清单:
| 检查项 | 关注点 |
|---|---|
| 安全响应头 | X-Content-Type-Options、X-Frame-Options、Strict-Transport-Security、CSP |
| Debug 模式 | 生产环境是否关闭 debug/详细错误输出 |
| 默认凭证 | 是否存在默认密码、测试账号、admin/admin |
| 速率限制 | 登录、注册、验证码等接口是否有 rate limit |
| 文件上传 | 是否限制文件类型、大小?存储路径是否在 web 可访问目录外? |
| 环境隔离 | 生产配置和开发配置是否分离?环境变量是否正确引用 |
审查目标:识别需要理解业务语义才能发现的安全风险。
检查清单:
| 检查项 | 关注点 |
|---|---|
| 越权访问(IDOR) | 修改请求中的 ID/参数能否访问他人数据 |
| 批量枚举 | 用户名/邮箱是否可被枚举(注册/登录/找回密码的不同返回) |
| 竞态条件 | 余额扣减、库存扣减、优惠券核销是否有并发保护 |
| 逻辑绕过 | 支付金额是否可在前端篡改?流程步骤是否可跳过? |
| 重放攻击 | 关键操作是否有幂等性保护或 nonce 机制 |
| 信息泄露 | API 响应是否返回了多余字段(如其他用户的信息、内部 ID) |
审查方法:
每个发现按以下标准分级:
| 等级 | 标准 | 处理要求 |
|---|---|---|
| 高危 | 可直接导致数据泄露、未授权访问、代码执行 | 必须修复后才能上线,给出具体修复代码 |
| 中危 | 存在利用条件但风险可控,或防御纵深不足 | 建议修复,给出修复方向 |
| 低危 | 最佳实践缺失,短期内风险较小 | 记录待改进,不阻断上线 |
分级原则:
完整审计时,生成报告到 docs/audits/YYYY-MM-DD-<服务名>-audit.md:
# 安全审计报告:<服务名>
## 审计概览
- 审计日期:YYYY-MM-DD
- 审计范围:<目录/模块列表>
- 技术栈:<自动识别结果>
- 风险摘要:🔴 X 高危 / 🟡 X 中危 / 🟢 X 低危
## 审计结论
**✅ 通过** / **⚠️ 有条件通过(需修复高危后上线)** / **❌ 不通过**
## 详细发现
### 1. 注入防护
(发现 / 无风险)
### 2. 认证与授权
(发现 / 无风险)
### 3. 敏感数据处理
(发现 / 无风险)
### 4. 配置安全
(发现 / 无风险)
### 5. 业务安全
(发现 / 无风险)
## 修复清单
| # | 等级 | 维度 | 问题描述 | 文件位置 | 修复建议 |
|---|------|------|---------|---------|---------|
## 历史审计
- [上次审计](链接)(如有)每个发现必须包含:
CI/CD 安全流水线(自动化,确定性)
├─ pre-commit: gitleaks 拦截敏感信息
└─ PR Check: 依赖漏洞 + 静态规则扫描
│
↓ 自动化通过后
security-audit(本 skill,AI 审查)
├─ task-finish 提示:涉及敏感模块时建议快速扫描
└─ release 强制:发版前完整审计
│
↓ 审计通过
release — 发版审计报告目录:docs/audits/,命名格式 YYYY-MM-DD-<服务名>-audit.md
code-walkthrough 或快速阅读理解业务逻辑,再做安全审查。脱离业务的安全审查是低效的© 312362115, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/security-audit of 312362115/claude.
Open the folder on GitHubat commit 2d4fa49
Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Audit this skill312362115/claude | 107 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Agentic GitHub Actions Auditortrailofbits/skills | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| MCP Server Security Auditawarexone/Agentic-Bug-Hunter | 5.3k | — | ~1.9k | Automated safety check: Warn | MIT | |
| Agent-Core Security ChecklistopenJiuwen-ai/agent-core | 446 | — | ~1.7k | Automated safety check: Notes | Apache-2.0 | |
| Sast BanditAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~2.6k | Automated safety check: Pass | Custom licence | |
| Snowflake Developmentsickn33/agentic-awesome-skills | 47k | 2 repos | ~2.1k | Automated safety check: Pass | MIT |
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
awarexone/Agentic-Bug-Hunter
Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates.
openJiuwen-ai/agent-core
A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection.
AgentSecOps/SecOpsAgentKit
Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping.
sickn33/agentic-awesome-skills
Comprehensive Snowflake development assistant covering SQL best practices, data pipeline design (Dynamic Tables, Streams, Tasks, Snowpipe), Cortex AI functions, Cortex Agents, Snowpark Python, dbt…
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
312362115/claude
专业图表生成技能:根据需求自动选择合适的图表类型,生成符合设计规范的 PNG 图表. An agent skill from 312362115/claude.
312362115/claude
深度调研技能:对任意命题进行系统性调研并输出专业研究报告. An agent skill from 312362115/claude.
312362115/claude
MD 文件浏览器预览:GitHub 风格渲染 + 左侧自动目录. An agent skill from 312362115/claude.
312362115/claude
通用写作技能:以"内容→组件→组合"的方式产出技术文档、产品文档、汇报材料. An agent skill from 312362115/claude.
312362115/claude
代码导读技能:帮助快速理解不熟悉的项目或模块,建立心智模型. An agent skill from 312362115/claude.
312362115/claude
数据库代码审查 + Migration 安全检查. An agent skill from 312362115/claude.
Categories
服务上线前的 AI 安全审查,聚焦需要理解代码语义和业务逻辑的安全问题. An agent skill from 312362115/claude. Security Audit is an agent skill from 312362115/claude.
Security Audit fits situations like: tasks that involve Security review; tasks that involve Prompt injection and agent security; tasks that involve CI/CD.
Run `npx skills add 312362115/claude --skill security-audit -a claude-code`. Or copy the skill folder (skills/security-audit in 312362115/claude) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add 312362115/claude --skill security-audit -a codex`. Or copy the skill folder (skills/security-audit in 312362115/claude) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add 312362115/claude --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.
SKILL.md names no scripts, command-line tools or credentials: Security Audit is instructions for the agent only. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Audit: Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars), MCP Server Security Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars), Agent-Core Security Checklist (openJiuwen-ai/agent-core, 446 stars) and Sast Bandit (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
312362115 (a GitHub user) maintains it in 312362115/claude, which has 107 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on May 14, 2026.
Source: 312362115/claude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.