Agent skill

Security Audit

by 312362115 in 312362115/claude

服务上线前的 AI 安全审查,聚焦需要理解代码语义和业务逻辑的安全问题. An agent skill from 312362115/claude.

MITAuto-check passedSecurity

Install Security Audit

skills CLI
$ npx skills add 312362115/claude --skill security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install 312362115/claude security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-audit .claude/skills/security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-audit
GitHub stars
107
Token cost
~1.3k tokens
SKILL.md length
269 words
Files
1
Skills in repo
20
Repo updated
First seen
Licence
MIT

At a glance

服务上线前的 AI 安全审查,聚焦需要理解代码语义和业务逻辑的安全问题. An agent skill from 312362115/claude.

  • Works in 3 steps: 确定审计目标:哪些目录/模块/服务?用 AskUserQuestion 确认,不要猜 → 识别技术栈:检测 package.json / requirements.txt… → 识别敏感区域:优先审查以下目录和文件
  • Tasks that involve Security review
  • SKILL.md covers 第一步:确定审计范围和深度, 第二步:逐维度审查, 第三步:风险分级 and 第四步:生成审计报告, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Audit is an agent skill from 312362115/claude. 服务上线前的 AI 安全审查,聚焦需要理解代码语义和业务逻辑的安全问题。 覆盖注入防护、认证授权、敏感数据处理、配置安全、业务安全 5 个维度。 适用于 JS/TS 前端、TS/Python 后端项目。 CI/CD 自动化检测(依赖漏洞、敏感信息 grep)不在本 skill 范围内,由流水线承担。 触发词:安全审计、安全检查、上线前检查、有没有漏洞、security audit。 触发场景:release 发版前(强制)、涉及认证/支付/用户数据的改动后(建议)、用户主动要求。

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review, Prompt injection and agent security and CI/CD. It works with Python and SQL. The licence is MIT.

When your agent uses it

  • Tasks that involve Security review
  • Tasks that involve Prompt injection and agent security
  • Tasks that involve CI/CD

Example prompts

  • “/security-audit”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. 确定审计目标:哪些目录/模块/服务?用 AskUserQuestion 确认,不要猜
  2. 识别技术栈:检测 package.json / requirements.txt / pyproject.toml / tsconfig.json
  3. 识别敏感区域:优先审查以下目录和文件

What it can do on your machine

Read from SKILL.md and the folder at commit 2d4fa49. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Audit loads about 1.3k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 269 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from 312362115/claude at commit 2d4fa49, republished under its MIT licence (© 312362115). 269 words, ~1,267 tokens.

Download SKILL.mdSave it as .claude/skills/security-audit/SKILL.md (or your agent's skills folder).
name
security-audit
description
服务上线前的 AI 安全审查,聚焦需要理解代码语义和业务逻辑的安全问题。 覆盖注入防护、认证授权、敏感数据处理、配置安全、业务安全 5 个维度。 适用于 JS/TS 前端、TS/Python 后端项目。 CI/CD 自动化检测(依赖漏洞、敏感信息 grep)不在本 skill 范围内,由流水线承担。 触发词:安全审计、安全检查、上线前检查、有没有漏洞、security audit。 触发场景:release 发版前(强制)、涉及认证/支付/用户数据的改动后(建议)、用户主动要求。
version
1.0.0
last_updated
2026-04-08
repository
https://github.com/312362115/claude

安全审计(Security Audit)

CI/CD 拦确定性问题(依赖漏洞、硬编码密钥),本 skill 审需要理解力的问题(数据流追踪、业务逻辑安全)。 两者互补,不重复。


第一步:确定审计范围和深度

收到审计请求
  │
  ├─ 快速扫描(单模块 / 局部改动 / 敏感模块修改后)
  │   选 1-2 个最相关的维度检查
  │   产出:终端输出结果,不生成报告
  │
  └─ 完整审计(release 发版前 / 新服务首次上线 / 重大安全相关改动)
      5 个维度全量检查
      产出:docs/audits/YYYY-MM-DD-<服务名>-audit.md
范围识别
  1. 确定审计目标:哪些目录/模块/服务?用 AskUserQuestion 确认,不要猜
  2. 识别技术栈:检测 package.json / requirements.txt / pyproject.toml / tsconfig.json
  3. 识别敏感区域:优先审查以下目录和文件:
    • 路由定义、中间件(认证/鉴权相关)
    • 数据库操作层(ORM 调用、原生查询)
    • 用户输入处理(表单、API 参数解析)
    • 配置文件(CORS、安全头、环境变量引用)
    • 支付/订单/用户数据相关模块

第二步:逐维度审查

按以下 5 个维度逐一检查。每个维度都需要读代码,不是凭印象判断。

维度 1:注入防护

审查目标:用户可控的输入是否经过正确处理后才进入危险操作。

检查清单:

注入类型关注点安全做法
SQL 注入原生 SQL 拼接、ORM 的 raw query参数化查询、预编译语句
命令注入exec()、child_process、os.system()、subprocess避免拼接用户输入到命令,用参数数组
XSSinnerHTML、dangerouslySetInnerHTML、模板中的未转义输出输出转义、CSP 头、避免直接插入 HTML
路径遍历用户输入拼接文件路径、../ 未过滤路径规范化、白名单校验、path.resolve 后检查前缀
SSRF用户输入作为 URL 发起服务端请求URL 白名单、禁止内网地址、DNS rebinding 防护
模板注入用户输入直接进入模板引擎渲染避免动态模板编译、使用沙箱

审查方法:

  1. 找到所有用户输入入口(路由参数、query、body、header、cookie)
  2. 追踪每个输入的数据流向——最终到了哪个危险函数?
  3. 中间有没有经过校验/转义/参数化处理?
维度 2:认证与授权

审查目标:确保每个需要保护的资源都有正确的认证和授权检查。

检查清单:

检查项关注点
认证覆盖有没有接口"裸奔"——应该要登录但没加认证中间件?
授权粒度用户 A 能不能通过改 ID 访问用户 B 的数据?(IDOR)
JWT/Session密钥强度、过期时间、刷新机制、注销是否真的失效
CORS 策略Access-Control-Allow-Origin 是否过于宽松(*)?credentials 模式下的 origin 检查
密码策略密码是否 bcrypt/argon2 哈希存储、是否有强度要求
权限绕过前端隐藏 ≠ 后端鉴权,检查是否只在前端做了权限判断

审查方法:

  1. 列出所有路由/接口,标注哪些有认证中间件、哪些没有
  2. 找到"裸奔"接口,判断是否应该加认证
  3. 检查授权逻辑:当前用户只能操作自己的资源吗?
维度 3:敏感数据处理

审查目标:敏感数据在存储、传输、日志中是否得到正确保护。

检查清单:

检查项关注点
密码存储是否用了 bcrypt/argon2?是否明文或 MD5/SHA1?
加密算法是否使用了已知弱算法(DES、RC4、MD5 用于加密)
日志脱敏日志里有没有打印密码、token、手机号、身份证号
错误信息异常响应是否泄露了堆栈、SQL 语句、内部路径
数据传输敏感 API 是否强制 HTTPS?cookie 是否设置 Secure 和 HttpOnly
前端存储token 存 localStorage(可被 XSS 窃取)还是 httpOnly cookie?

审查方法:

  1. 搜索密码/token 相关的存储和比对逻辑
  2. 搜索日志输出(console.log、logger.、print),检查是否包含敏感字段
  3. 检查错误处理中间件,确认生产环境不返回堆栈信息
维度 4:配置安全

审查目标:安全相关配置是否合理,生产环境是否加固。

检查清单:

检查项关注点
安全响应头X-Content-Type-Options、X-Frame-Options、Strict-Transport-Security、CSP
Debug 模式生产环境是否关闭 debug/详细错误输出
默认凭证是否存在默认密码、测试账号、admin/admin
速率限制登录、注册、验证码等接口是否有 rate limit
文件上传是否限制文件类型、大小?存储路径是否在 web 可访问目录外?
环境隔离生产配置和开发配置是否分离?环境变量是否正确引用
维度 5:业务安全

审查目标:识别需要理解业务语义才能发现的安全风险。

检查清单:

检查项关注点
越权访问(IDOR)修改请求中的 ID/参数能否访问他人数据
批量枚举用户名/邮箱是否可被枚举(注册/登录/找回密码的不同返回)
竞态条件余额扣减、库存扣减、优惠券核销是否有并发保护
逻辑绕过支付金额是否可在前端篡改?流程步骤是否可跳过?
重放攻击关键操作是否有幂等性保护或 nonce 机制
信息泄露API 响应是否返回了多余字段(如其他用户的信息、内部 ID)

审查方法:

  1. 站在攻击者视角思考:"如果我想偷数据/薅羊毛/搞破坏,我会怎么做?"
  2. 检查关键业务操作的参数校验和权限检查
  3. 关注"前端校验但后端没校验"的情况

第三步:风险分级

每个发现按以下标准分级:

等级标准处理要求
高危可直接导致数据泄露、未授权访问、代码执行必须修复后才能上线,给出具体修复代码
中危存在利用条件但风险可控,或防御纵深不足建议修复,给出修复方向
低危最佳实践缺失,短期内风险较小记录待改进,不阻断上线

分级原则:

  • 不确定时往高了分,宁可过度警惕不可遗漏
  • 但不要把所有发现都标高危——狼来了效应会降低警觉
  • 已有其他防御措施的可适当降级(如 XSS 风险但已有严格 CSP)

第四步:生成审计报告

完整审计时,生成报告到 docs/audits/YYYY-MM-DD-<服务名>-audit.md:

markdown
# 安全审计报告:<服务名>

## 审计概览
- 审计日期:YYYY-MM-DD
- 审计范围:<目录/模块列表>
- 技术栈:<自动识别结果>
- 风险摘要:🔴 X 高危 / 🟡 X 中危 / 🟢 X 低危

## 审计结论

**✅ 通过** / **⚠️ 有条件通过(需修复高危后上线)** / **❌ 不通过**

## 详细发现

### 1. 注入防护
(发现 / 无风险)

### 2. 认证与授权
(发现 / 无风险)

### 3. 敏感数据处理
(发现 / 无风险)

### 4. 配置安全
(发现 / 无风险)

### 5. 业务安全
(发现 / 无风险)

## 修复清单

| # | 等级 | 维度 | 问题描述 | 文件位置 | 修复建议 |
|---|------|------|---------|---------|---------|

## 历史审计
- [上次审计](链接)(如有)

每个发现必须包含:

  • 具体代码位置(文件:行号)
  • 问题描述(是什么、为什么危险)
  • 攻击场景(攻击者怎么利用)
  • 修复建议(高危给代码,中危给方向)

第五步:修复与复查

  1. 高危问题:给出具体修复代码,协助用户当场修复
  2. 修复后复查:修复完成后,重新检查对应维度确认修复有效
  3. 报告更新:在修复清单中标记已修复项

与其他 skill/流程的衔接

CI/CD 安全流水线(自动化,确定性)
  ├─ pre-commit: gitleaks 拦截敏感信息
  └─ PR Check: 依赖漏洞 + 静态规则扫描
         │
         ↓ 自动化通过后
security-audit(本 skill,AI 审查)
  ├─ task-finish 提示:涉及敏感模块时建议快速扫描
  └─ release 强制:发版前完整审计
         │
         ↓ 审计通过
release — 发版

审计报告目录:docs/audits/,命名格式 YYYY-MM-DD-<服务名>-audit.md


注意事项

  • 不要替代 CI/CD:依赖漏洞扫描(npm audit)、敏感信息 grep(gitleaks)是自动化流水线的事,本 skill 不重复做
  • 不要过度报告:只报告真实风险,不要为了显得全面把无关紧要的 warning 都列上
  • 理解业务再审:先用 code-walkthrough 或快速阅读理解业务逻辑,再做安全审查。脱离业务的安全审查是低效的
  • 攻击者思维:每个维度都要问"如果我是攻击者,我怎么利用这个?"。找不到攻击路径的问题不算高危

© 312362115, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security-audit of 312362115/claude.

Open the folder on GitHubat commit 2d4fa49

Compare with similar skills

Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Audit this skill312362115/claude107—~1.3kAutomated safety check: PassMIT
Agentic GitHub Actions Auditortrailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0
MCP Server Security Auditawarexone/Agentic-Bug-Hunter5.3k—~1.9kAutomated safety check: WarnMIT
Agent-Core Security ChecklistopenJiuwen-ai/agent-core446—~1.7kAutomated safety check: NotesApache-2.0
Sast BanditAgentSecOps/SecOpsAgentKit2201 repos~2.6kAutomated safety check: PassCustom licence
Snowflake Developmentsickn33/agentic-awesome-skills47k2 repos~2.1kAutomated safety check: PassMIT

Similar skills

  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.4k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • MCP Server Security Audit

    awarexone/Agentic-Bug-Hunter

    Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates.

    5.3k GitHub stars~1.9k tokensUpdated today
    SecurityAuto-check: warnings
  • Agent-Core Security Checklist

    openJiuwen-ai/agent-core

    A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection.

    446 GitHub stars~1.7k tokensUpdated today
    SecurityAuto-check: notes
  • Sast Bandit

    AgentSecOps/SecOpsAgentKit

    Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping.

    220 GitHub starsUsed in 1 repo~2.6k tokens
    SecurityAuto-check passed
  • Snowflake Development

    sickn33/agentic-awesome-skills

    Comprehensive Snowflake development assistant covering SQL best practices, data pipeline design (Dynamic Tables, Streams, Tasks, Snowpipe), Cortex AI functions, Cortex Agents, Snowpark Python, dbt…

    47k GitHub starsUsed in 2 repos~2.1k tokens
    DatabasesAuto-check passed
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes

More from 312362115/claude

All 20 skills in this repo
  • Diagram

    312362115/claude

    专业图表生成技能:根据需求自动选择合适的图表类型,生成符合设计规范的 PNG 图表. An agent skill from 312362115/claude.

    107 GitHub stars~2.7k tokensUpdated 4 mo ago
    Auto-check passed
  • Deep Research

    312362115/claude

    深度调研技能:对任意命题进行系统性调研并输出专业研究报告. An agent skill from 312362115/claude.

    107 GitHub stars~6.6k tokensUpdated 4 mo ago
    Auto-check passed
  • Preview Md

    312362115/claude

    MD 文件浏览器预览:GitHub 风格渲染 + 左侧自动目录. An agent skill from 312362115/claude.

    107 GitHub stars~636 tokensUpdated 4 mo ago
    Auto-check passed
  • Writing

    312362115/claude

    通用写作技能:以"内容→组件→组合"的方式产出技术文档、产品文档、汇报材料. An agent skill from 312362115/claude.

    107 GitHub stars~1.6k tokensUpdated 4 mo ago
    Auto-check passed
  • Code Walkthrough

    312362115/claude

    代码导读技能:帮助快速理解不熟悉的项目或模块,建立心智模型. An agent skill from 312362115/claude.

    107 GitHub stars~1k tokensUpdated 4 mo ago
    Auto-check: notes
  • DB Review

    312362115/claude

    数据库代码审查 + Migration 安全检查. An agent skill from 312362115/claude.

    107 GitHub stars~1.8k tokensUpdated 4 mo ago
    Auto-check passed

Works with

Categories

Questions about Security Audit

What does Security Audit do?

服务上线前的 AI 安全审查,聚焦需要理解代码语义和业务逻辑的安全问题. An agent skill from 312362115/claude. Security Audit is an agent skill from 312362115/claude.

When should I use Security Audit?

Security Audit fits situations like: tasks that involve Security review; tasks that involve Prompt injection and agent security; tasks that involve CI/CD.

How do I install Security Audit in Claude Code?

Run `npx skills add 312362115/claude --skill security-audit -a claude-code`. Or copy the skill folder (skills/security-audit in 312362115/claude) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Security Audit in Codex?

Run `npx skills add 312362115/claude --skill security-audit -a codex`. Or copy the skill folder (skills/security-audit in 312362115/claude) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.

Can I use Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add 312362115/claude --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.

What does Security Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Audit is instructions for the agent only. Our summary lists: Python 3.

Does Security Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Audit use?

Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Audit use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Audit?

Skills that share tags, products or a category with Security Audit: Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars), MCP Server Security Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars), Agent-Core Security Checklist (openJiuwen-ai/agent-core, 446 stars) and Sast Bandit (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Audit?

312362115 (a GitHub user) maintains it in 312362115/claude, which has 107 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on May 14, 2026.

Source: 312362115/claude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.