Agent skill

Security Audit

by bybren-llc in bybren-llc/safe-agentic-workflow

RLS validation, security audits, OWASP compliance, and vulnerability scanning.

MITAuto-check passedSecurity

Install Security Audit

skills CLI
$ npx skills add bybren-llc/safe-agentic-workflow --skill security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bybren-llc/safe-agentic-workflow security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bybren-llc/safe-agentic-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-audit .claude/skills/security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-audit
GitHub stars
423
Token cost
~1.4k tokens
SKILL.md length
278 words
Files
4 (incl. scripts, references, assets)
Skills in repo
42
Repo updated
First seen
Licence
MIT

At a glance

RLS validation, security audits, OWASP compliance, and vulnerability scanning.

  • Works in 5 steps: RLS Validation → Authentication Checks → Credential Scanning → …
  • Validating RLS policies
  • SKILL.md covers Purpose, When This Skill Applies, Stop-the-Line Conditions and Security Audit Checklist, plus 5 more sections
  • Calls npm and pip; needs API_KEY and STRIPE_SECRET_KEY

What it does

Security Audit is an agent skill from bybren-llc/safe-agentic-workflow. RLS validation, security audits, OWASP compliance, and vulnerability scanning. Use when validating RLS policies, auditing API routes for auth, scanning for vulnerabilities, reviewing for exposed credentials, or performing pre-deployment security review. Do NOT use for routine feature development.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts, reference files and assets.

It sits in Security, covering Security review, Web application vulnerabilities and Vulnerability scanning. The repository describes itself as: SAW — SAFe Agentic Workflow AI Agent Harness for Multi-Agent Team Workflows Built on SAFe methodology (Scaled Agile Framework), adapted for AI agent teams (Now With AI-DLC!)… The licence is MIT.

When your agent uses it

  • Validating RLS policies
  • Auditing API routes for auth
  • Scanning for vulnerabilities
  • Reviewing for exposed credentials

Example prompts

  • “/security-audit”

Requirements

  • A credential in API_KEY
  • A credential in STRIPE_SECRET_KEY

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. RLS Validation
  2. Authentication Checks
  3. Credential Scanning
  4. Dependency Vulnerabilities
  5. Input Validation

What it can do on your machine

Read from SKILL.md and the folder at commit 26ca58b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY
    • STRIPE_SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Audit loads about 1.4k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 278 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from bybren-llc/safe-agentic-workflow at commit 26ca58b, republished under its MIT licence (© bybren-llc). 278 words, ~1,436 tokens.

Download SKILL.mdSave it as .claude/skills/security-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
security-audit
description
RLS validation, security audits, OWASP compliance, and vulnerability scanning. Use when validating RLS policies, auditing API routes for auth, scanning for vulnerabilities, reviewing for exposed credentials, or performing pre-deployment security review. Do NOT use for routine feature development.

Security Audit Skill

TEMPLATE: This skill uses {{PLACEHOLDER}} tokens. Replace with your project values before use.

Purpose

Guide security validation with RLS enforcement, OWASP compliance, and vulnerability detection following security-first architecture.

When This Skill Applies

  • Validating RLS policies
  • Auditing API routes for auth
  • Vulnerability scanning
  • Pre-deployment security review
  • Checking for exposed credentials
  • Reviewing database access patterns

Stop-the-Line Conditions

FORBIDDEN Patterns
typescript
// FORBIDDEN: Direct DB calls (bypass RLS)
const users = await db.user.findMany();
// Must use: withUserContext, withAdminContext, or withSystemContext

// FORBIDDEN: Missing authentication on protected routes
export async function GET(req: Request) {
  return getUserData(); // No auth check before accessing user data
}

// FORBIDDEN: Exposed credentials
const API_KEY = "sk_live_abc123"; // Hardcoded secret

// FORBIDDEN: SQL injection vulnerability
const query = `SELECT * FROM users WHERE id = ${userId}`; // Interpolated
CORRECT Patterns
typescript
// CORRECT: RLS context wrapper
const users = await withUserContext(db, userId, async (client) => {
  return client.user.findMany();
});

// CORRECT: Auth check before data access
export async function GET(req: Request) {
  const { userId } = await auth();
  if (!userId) {
    return new Response("Unauthorized", { status: 401 });
  }
  return getUserData(userId);
}

// CORRECT: Environment variables for secrets
const API_KEY = process.env.STRIPE_SECRET_KEY;

// CORRECT: Parameterized queries
const user = await db.$queryRaw`SELECT * FROM users WHERE id = ${userId}`;

Security Audit Checklist

1. RLS Validation
  • All database operations use context wrappers
  • No direct DB calls in route handlers
  • User isolation verified (user A cannot see user B's data)
  • Admin operations properly scoped
bash
# Find potential RLS bypasses
grep -r "db\." --include="*.ts" app/ lib/ | grep -v "withUserContext\|withAdminContext\|withSystemContext"
2. Authentication Checks
  • All protected routes verify authentication
  • Auth provider called before data access
  • Proper 401/403 responses for unauthorized
bash
# Find routes missing auth checks
grep -r "export async function" --include="route.ts" app/ | head -20
# Manually verify each has auth check
3. Credential Scanning
  • No hardcoded secrets in code
  • No API keys in client-side code
  • Environment variables used correctly
bash
# Scan for potential secrets
grep -rE "(sk_live|pk_live|password|secret|key)" --include="*.ts" --include="*.tsx" | grep -v "process.env\|.env"
4. Dependency Vulnerabilities
bash
# Run security audit
npm audit
# or
pip audit

# Check for high/critical vulnerabilities
npm audit --audit-level=high
5. Input Validation
  • User input validated with schemas (Zod, Pydantic, etc.)
  • No raw query interpolation
  • File upload restrictions in place

OWASP Top 10 Checklist

RiskCheckStatus
A01 Broken AccessRLS enforced, auth on all routes[ ]
A02 Crypto FailuresSecrets in env vars only[ ]
A03 InjectionParameterized queries, schemas[ ]
A04 Insecure DesignAuth-first pattern followed[ ]
A05 MisconfigurationProd env properly secured[ ]
A06 Vulnerable DepsDependency audit clean[ ]
A07 Auth FailuresAuth integration correct[ ]
A08 Data IntegrityRLS prevents tampering[ ]
A09 Logging FailuresSecurity events logged[ ]
A10 SSRFExternal URLs validated[ ]

Security Validation Commands

bash
# Complete security check
{{SECURITY_AUDIT_COMMAND}}

# RLS bypass detection
grep -r "db\." --include="*.ts" app/ lib/ | wc -l
# Compare with context wrapper count

# Secret detection
grep -rE "sk_|pk_|password=" . --include="*.ts"

Pre-Deployment Security Review

Before ANY production deployment:

  • Dependency audit shows no high/critical issues
  • RLS policies validated
  • No new direct DB calls
  • Environment variables documented
  • Backup taken before migration
  • Rollback plan documented

Security Audit Report Template

markdown
## Security Audit Report - {{TICKET_PREFIX}}-XXX

### Summary
- **Date**: [date]
- **Auditor**: Security Engineer
- **Scope**: [what was audited]

### Findings
| Severity | Issue | Location | Status |
| -------- | ----- | -------- | ------ |
| HIGH     | ...   | ...      | FIXED  |
| MEDIUM   | ...   | ...      | OPEN   |

### RLS Validation
- [x] All tables have RLS enabled
- [x] User isolation verified
- [x] Admin policies scoped correctly

### Recommendations
1. [recommendation]
2. [recommendation]

### Approval
- [ ] Security Engineer approves
- [ ] Ready for deployment

Authoritative References

  • Security Architecture: docs/guides/SECURITY_FIRST_ARCHITECTURE.md
  • RLS Implementation: docs/database/RLS_IMPLEMENTATION_GUIDE.md
  • RLS Policies: docs/database/RLS_POLICY_CATALOG.md
  • OWASP Top 10: https://owasp.org/Top10/

© bybren-llc, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references, assets) in .agents/skills/security-audit of bybren-llc/safe-agentic-workflow.

  • SKILL.md
  • assets/.gitkeep
  • references/.gitkeep
  • scripts/.gitkeep

Open the folder on GitHubat commit 26ca58b

Compare with similar skills

Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Audit this skillbybren-llc/safe-agentic-workflow423—~1.4kAutomated safety check: PassMIT
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Discover Securityrand/cc-polymath181—~1.9kAutomated safety check: PassMIT
Security AuditHouseofmvps/ultraship123—~3.9kAutomated safety check: NotesMIT
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone

Similar skills

  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Discover Security

    rand/cc-polymath

    Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management.

    181 GitHub stars~1.9k tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • Security Audit

    Houseofmvps/ultraship

    Run security audit — dependency vulnerabilities, secret scanning, OWASP pattern detection, HTTP headers.

    123 GitHub stars~3.9k tokensUpdated 3 mo ago
    SecurityAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed

More from bybren-llc/safe-agentic-workflow

All 42 skills in this repo
  • Multi-Agent Coordination Template

    bybren-llc/safe-agentic-workflow

    Agent assignment matrix, blocker escalation, and TDM coordination patterns. Use when assigning work to specialist agents, managing blockers across agents…

    423 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • API Route Patterns

    bybren-llc/safe-agentic-workflow

    API route implementation patterns with RLS, validation, and error handling. Use when creating API routes, implementing CRUD endpoints, adding server-side…

    423 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Technical Documentation Templates

    bybren-llc/safe-agentic-workflow

    Documentation templates for ADRs, runbooks, architecture docs, and knowledge transfer documents. Use when creating Architecture Decision Records, writing…

    423 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Deployment SOP Checklist

    bybren-llc/safe-agentic-workflow

    Deployment workflows, pre-deploy validation, smoke testing, and rollback procedures. Use when deploying to staging or production, running smoke tests…

    423 GitHub stars~950 tokensUpdated 2 mo ago
    Auto-check passed
  • Frontend Patterns Template

    bybren-llc/safe-agentic-workflow

    Frontend patterns for modern web frameworks, component libraries, auth flows, and analytics. Use when building UI components, creating pages, implementing…

    423 GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Advanced Git Operations

    bybren-llc/safe-agentic-workflow

    Advanced git operations including rebase, bisect, cherry-pick, and conflict resolution. Use when rebasing feature branches, debugging with bisect…

    423 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Security Audit

What does Security Audit do?

RLS validation, security audits, OWASP compliance, and vulnerability scanning. Security Audit is an agent skill from bybren-llc/safe-agentic-workflow. RLS validation, security audits, OWASP compliance, and vulnerability scanning.

When should I use Security Audit?

Security Audit fits situations like: validating RLS policies; auditing API routes for auth; scanning for vulnerabilities; reviewing for exposed credentials.

How do I install Security Audit in Claude Code?

Run `npx skills add bybren-llc/safe-agentic-workflow --skill security-audit -a claude-code`. Or copy the skill folder (.agents/skills/security-audit in bybren-llc/safe-agentic-workflow) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Security Audit in Codex?

Run `npx skills add bybren-llc/safe-agentic-workflow --skill security-audit -a codex`. Or copy the skill folder (.agents/skills/security-audit in bybren-llc/safe-agentic-workflow) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.

Can I use Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bybren-llc/safe-agentic-workflow --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.

What does Security Audit need to run?

Going by SKILL.md and its folder, Security Audit needs the command-line tools its instructions call (npm and pip) and credentials named API_KEY and STRIPE_SECRET_KEY. Our summary lists: A credential in API_KEY; A credential in STRIPE_SECRET_KEY.

Does Security Audit access the network?

SKILL.md names 1 domain. As links in the text: owasp.org. This is read from the text; nothing was executed.

Is Security Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Audit use?

Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Audit use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Audit?

Skills that share tags, products or a category with Security Audit: Security Auditor (eigent-ai/eigent, 15k stars), Security Review (github/awesome-copilot, 40k stars), Discover Security (rand/cc-polymath, 181 stars) and Security Audit (Houseofmvps/ultraship, 123 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Audit?

bybren-llc (a GitHub organization) maintains it in bybren-llc/safe-agentic-workflow, which has 423 GitHub stars. The repository holds 42 skills in this directory. The repository was last updated on July 20, 2026.

Source: bybren-llc/safe-agentic-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.