Agent skill

Security Audit

by alinaqi in alinaqi/maggy

Structured, adversarial, multi-phase security audit of a codebase — recon → coverage-led hunting → finder≠validator validation → machine-readable findings → target-neutral report

MITAuto-check: notesSecurity

Install Security Audit

skills CLI
$ npx skills add alinaqi/maggy --skill security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alinaqi/maggy security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alinaqi/maggy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-audit .claude/skills/security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-audit
GitHub stars
707
Token cost
~1.6k tokens
SKILL.md length
734 words
Files
3
Skills in repo
71
Repo updated
First seen
Licence
MIT

At a glance

Structured, adversarial, multi-phase security audit of a codebase — recon → coverage-led hunting → finder≠validator validation → machine-readable findings → target-neutral report

  • Works in 6 steps: Reconnaissance → architecture.md +… → Coverage-led hunting → Adversarial validation (finder ≠… → …
  • Tasks that involve Security review
  • SKILL.md covers Principles (read first), Phases, Anti-patterns and How it fits the harness
  • Runs Python scripts from its folder; calls python3

What it does

Security Audit is an agent skill from alinaqi/maggy. Structured, adversarial, multi-phase security audit of a codebase — recon → coverage-led hunting → finder≠validator validation → machine-readable findings → target-neutral report

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `report-schema.json` and `validate_findings.py`).

It sits in Security, covering Security review. The repository describes itself as: What started as an opinionated Claude Code setup kit is now an autonomous AI engineering command center. The licence is MIT.

When your agent uses it

  • Tasks that involve Security review

Example prompts

  • “/security-audit”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Glob, Grep, Bash, Task

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Reconnaissance → architecture.md + coverage-ledger.json
  2. Coverage-led hunting
  3. Adversarial validation (finder ≠ validator)
  4. Structured output → findings.json
  5. Record verification
  6. Target-neutral report → REPORT.md

What it can do on your machine

Read from SKILL.md and the folder at commit 72a456e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Grep
    • Bash
    • Task

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Audit loads about 1.6k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 734 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Glob, Grep, Bash, Task

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alinaqi/maggy at commit 72a456e, republished under its MIT licence (© alinaqi). 734 words, ~1,599 tokens.

Download SKILL.mdSave it as .claude/skills/security-audit/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
security-audit
description
Structured, adversarial, multi-phase security audit of a codebase — recon → coverage-led hunting → finder≠validator validation → machine-readable findings → target-neutral report
allowed-tools
Read, Glob, Grep, Bash, Task
when-to-use
When asked to "security audit", "find vulnerabilities", "pen-test the code", or audit a codebase/PR for security before a release. For preventive coding…
user-invocable
true
effort
high

Security Audit — adversarial, evidence-grounded

A full audit, not a checklist. It runs in phases, keeps a coverage ledger so nothing is skipped silently, and — the core discipline — the agent that finds a candidate is never the one that confirms it. Severity is likelihood × impact, not deviation from a style rule. Output is machine-readable and reproducible.

Methodology inspired by Cloudflare's public security-audit-skill, rebuilt to reuse maggy's own pieces: council-review for adversarial validation, cpg-analysis (Joern/CodeQL) for static taint/data-flow, agent-teams / polyphony for isolated parallel hunters, and security for the vuln classes.

Principles (read first)

  • Evidence over intuition. A finding is confirmed only when you can name the file:line of the boundary that fails and a concrete attack that crosses it.
  • Finder ≠ validator. Whoever proposes a candidate must not confirm it. A different agent (or a council-review model) tries to disprove it.
  • Impact-driven severity. Rate likelihood × impact, not "differs from best practice". A hardcoded key in a test fixture is not critical; an auth bypass on a tenant boundary is.
  • Coverage is tracked, not assumed. Every input surface / trust boundary is a ledger unit with a status; a coverage critic hunts the gaps.
  • No theater. Do not pad the report with generic "consider using HTTPS" advice. Report only boundary failures you can stand behind.

Phases

1. Reconnaissance → architecture.md + coverage-ledger.json

Map the target before hunting. Identify: entry points (HTTP routes, CLI, queue consumers, webhooks), trust boundaries (authn/authz, tenant isolation, privilege transitions), input surfaces (params, headers, files, env, deserialization), secret handling, external calls (SSRF surface), and data stores. Write a short architecture.md, then enumerate every surface as a unit in coverage-ledger.json ({id, surface, boundary, status: pending}).

2. Coverage-led hunting

For each ledger unit, hunt the relevant classes. Prefer isolated sub-agents (via agent-teams / polyphony) so one hunter's context does not bias another, and lean on cpg-analysis for data-flow/taint where a graph beats grep. Mark each unit hunted; a coverage critic pass re-reads the ledger and reopens units that were skimmed. Classes to cover (depth in security + cpg-analysis):

ClassLook for
InjectionSQL/NoSQL/OS/LDAP/template; unparameterized queries, shell=True, eval
AuthN / AuthZmissing checks, IDOR, broken tenant isolation, JWT/session flaws
Secretskeys in code/history/logs, client-exposed VITE_/NEXT_PUBLIC_ secrets
SSRF / egressuser-controlled URLs, metadata endpoints, unvalidated redirects
Deserializationpickle/yaml.load/Marshal on untrusted input
Path / filetraversal, arbitrary write, zip-slip, unsafe temp files
LLM / promptprompt injection, tool-abuse, unbounded fan-out, data exfil via output
Supply chaintyposquats, unpinned deps, postinstall scripts, CI token scope
Cloud / IaCover-broad IAM, public buckets, exposed admin, secrets in env
Client-sideXSS, DOM sinks, CSP gaps, sensitive data in localStorage
Resource / DoSunbounded loops/allocations, regex catastrophic backtracking
Data isolationcross-tenant reads, missing RLS, PII in logs/caches
Memory (native)overflow, UAF, integer wrap (for C/C++/unsafe Rust targets)
Show full SKILL.md (288 more words)Show less
3. Adversarial validation (finder ≠ validator)

For each unique candidate, a different reviewer attempts to disprove it: is the tainted input actually reachable? is there a guard upstream? is the sink real? Route this through council-review (multiple models vote) for anything rated high/critical. Assign a verdict: confirmed, needs_validation, or rejected.

4. Structured output → findings.json

Emit findings.json conforming to report-schema.json (shipped in this skill). Validate it before reporting:

bash
python3 "$(cat ~/.claude/.bootstrap-dir)/skills/security-audit/validate_findings.py" findings.json

The validator enforces the rules that keep the audit honest: unique ids, valid enums, and that every confirmed finding has a file:line location, an attack scenario, and a validated_by that differs from found_by.

5. Record verification

A fresh agent re-opens each confirmed finding and checks the cited file:line still supports the claim (code may have moved). A material mismatch drops it back to needs_validation.

6. Target-neutral report → REPORT.md

Write REPORT.md (executive summary + confirmed findings by severity), FINDINGS-DETAIL.md (per-finding evidence + remediation), and NEEDS-VALIDATION.md (candidates that could not be confirmed). Neutral tone: no vendor names, no editorializing, just boundary → attack → impact → fix.

Anti-patterns

  • Confirming a finding you found yourself without an independent disprove attempt.
  • Severity inflation ("uses md5" rated critical with no reachable attack).
  • Grep-only hunting on a data-flow bug — use cpg-analysis.
  • A report that lists advice instead of reachable, evidence-backed findings.
  • Running audited target code outside a sandbox. Read and analyze; never execute untrusted target code to "see what it does".

How it fits the harness

  • Slots into the base Definition of Done for security-critical changes as the "prove it's safe" gate, above the preventive security skill.
  • Reuses council-review (adversarial validation), cpg-analysis (static taint), agent-teams / polyphony (isolated parallel hunters).
  • Iterations are additive: a second run over the same ledger typically surfaces more, so re-run before a major release rather than trusting one pass.

© alinaqi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in skills/security-audit of alinaqi/maggy.

  • SKILL.md
  • report-schema.json
  • validate_findings.py

Open the folder on GitHubat commit 72a456e

Compare with similar skills

Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Audit this skillalinaqi/maggy707—~1.6kAutomated safety check: NotesMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Skillward AuditFangcun-AI/SkillWard143—~2.9kAutomated safety check: PassCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes

More from alinaqi/maggy

All 71 skills in this repo
  • Aeo Optimization

    alinaqi/maggy

    AI Engine Optimization - semantic triples, page templates, content clusters for AI citations

    707 GitHub stars~3.7k tokensUpdated 15 days ago
    Auto-check passed
  • Agent Teams

    alinaqi/maggy

    Claude Code Agent Teams - default team-based development with strict TDD pipeline enforcement

    707 GitHub stars~5k tokensUpdated 15 days ago
    Auto-check: notes
  • AI Models

    alinaqi/maggy

    Latest AI models reference - Claude, OpenAI, Gemini, Eleven Labs, Replicate

    707 GitHub stars~4.1k tokensUpdated 15 days ago
    Auto-check passed
  • Android Java

    alinaqi/maggy

    Android Java development with MVVM, ViewBinding, and Espresso testing

    707 GitHub stars~3.9k tokensUpdated 15 days ago
    Auto-check: notes
  • Android Kotlin

    alinaqi/maggy

    Android Kotlin development with Coroutines, Jetpack Compose, Hilt, and MockK testing

    707 GitHub stars~3k tokensUpdated 15 days ago
    Auto-check passed
  • Autonomous Testing

    alinaqi/maggy

    AI-driven testing agent that auto-discovers, generates, executes, evaluates, and fixes tests for any project type

    707 GitHub stars~1.1k tokensUpdated 15 days ago
    Auto-check passed

Categories

Questions about Security Audit

What does Security Audit do?

Structured, adversarial, multi-phase security audit of a codebase — recon → coverage-led hunting → finder≠validator validation → machine-readable findings → target-neutral report. Security Audit is an agent skill from alinaqi/maggy.

When should I use Security Audit?

Security Audit fits situations like: tasks that involve Security review.

How do I install Security Audit in Claude Code?

Run `npx skills add alinaqi/maggy --skill security-audit -a claude-code`. Or copy the skill folder (skills/security-audit in alinaqi/maggy) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Security Audit in Codex?

Run `npx skills add alinaqi/maggy --skill security-audit -a codex`. Or copy the skill folder (skills/security-audit in alinaqi/maggy) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.

Can I use Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alinaqi/maggy --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.

What does Security Audit need to run?

Going by SKILL.md and its folder, Security Audit needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Glob, Grep, Bash, Task.

Does Security Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Audit safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Audit use?

Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Audit use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Audit?

Skills that share tags, products or a category with Security Audit: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Semgrep Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Audit?

alinaqi (a GitHub user) maintains it in alinaqi/maggy, which has 707 GitHub stars. The repository holds 71 skills in this directory. The repository was last updated on September 24, 2026.

Source: alinaqi/maggy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.