Agent skill

Security Audit

by bybren-llc in bybren-llc/safe-agentic-workflow

RLS validation, security audits, OWASP compliance, and vulnerability scanning.

MITAuto-check: notesSecurity

Install Security Audit

skills CLI
$ npx skills add bybren-llc/safe-agentic-workflow --skill security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bybren-llc/safe-agentic-workflow security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bybren-llc/safe-agentic-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/security-audit .claude/skills/security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-audit
GitHub stars
423
Token cost
~1.4k tokens
SKILL.md length
267 words
Files
2
Skills in repo
42
Repo updated
First seen
Licence
MIT

At a glance

RLS validation, security audits, OWASP compliance, and vulnerability scanning.

  • Works in 5 steps: RLS Validation → Authentication Checks → Credential Scanning → …
  • Validating RLS policies
  • SKILL.md covers Purpose, When This Skill Applies, Stop-the-Line Conditions and Security Audit Checklist, plus 5 more sections
  • Calls npm, yarn and git; needs API_KEY and STRIPE_SECRET_KEY

What it does

Security Audit is an agent skill from bybren-llc/safe-agentic-workflow. RLS validation, security audits, OWASP compliance, and vulnerability scanning. Use when validating RLS policies, auditing API routes, or scanning for security issues.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `README.md`).

It sits in Security, covering Security review, Web application vulnerabilities and Vulnerability scanning. The repository describes itself as: SAW — SAFe Agentic Workflow AI Agent Harness for Multi-Agent Team Workflows Built on SAFe methodology (Scaled Agile Framework), adapted for AI agent teams (Now With AI-DLC!)… The licence is MIT.

When your agent uses it

  • Validating RLS policies
  • Auditing API routes
  • Scanning for security issues

Example prompts

  • “/security-audit”

Requirements

  • A credential in API_KEY
  • A credential in STRIPE_SECRET_KEY
  • Pre-approved tools (allowed-tools): Read, Bash, Grep, Glob

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. RLS Validation
  2. Authentication Checks
  3. Credential Scanning
  4. Dependency Vulnerabilities
  5. Input Validation

What it can do on your machine

Read from SKILL.md and the folder at commit 26ca58b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • yarn
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY
    • STRIPE_SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Audit loads about 1.4k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 267 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Bash, Grep, Glob

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from bybren-llc/safe-agentic-workflow at commit 26ca58b, republished under its MIT licence (© bybren-llc). 267 words, ~1,419 tokens.

Download SKILL.mdSave it as .claude/skills/security-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
security-audit
description
RLS validation, security audits, OWASP compliance, and vulnerability scanning. Use when validating RLS policies, auditing API routes, or scanning for security issues.
allowed-tools
Read, Bash, Grep, Glob
context
fork
agent
Explore

Security Audit Skill

Purpose

Guide security validation with RLS enforcement, OWASP compliance, and vulnerability detection following security-first architecture.

When This Skill Applies

Invoke this skill when:

  • Validating RLS policies
  • Auditing API routes for auth
  • Vulnerability scanning
  • Pre-deployment security review
  • Checking for exposed credentials
  • Reviewing database access patterns

Stop-the-Line Conditions

FORBIDDEN Patterns
typescript
// FORBIDDEN: Direct Prisma calls (bypass RLS)
const users = await prisma.user.findMany();
// Must use: withUserContext, withAdminContext, or withSystemContext

// FORBIDDEN: Missing authentication on protected routes
export async function GET(req: Request) {
  // No auth check before accessing user data
  return getUserData();
}

// FORBIDDEN: Exposed credentials
const API_KEY = "sk_live_abc123"; // Hardcoded secret

// FORBIDDEN: SQL injection vulnerability
const query = `SELECT * FROM users WHERE id = ${userId}`; // Interpolated
CORRECT Patterns
typescript
// CORRECT: RLS context wrapper
const users = await withUserContext(prisma, userId, async (client) => {
  return client.user.findMany();
});

// CORRECT: Auth check before data access
export async function GET(req: Request) {
  const { userId } = await auth();
  if (!userId) {
    return new Response("Unauthorized", { status: 401 });
  }
  return getUserData(userId);
}

// CORRECT: Environment variables for secrets
const API_KEY = process.env.STRIPE_SECRET_KEY;

// CORRECT: Parameterized queries
const user = await prisma.$queryRaw`SELECT * FROM users WHERE id = ${userId}`;

Security Audit Checklist

1. RLS Validation
  • All database operations use context wrappers
  • No direct Prisma calls in route handlers
  • User isolation verified (user A cannot see user B's data)
  • Admin operations properly scoped
bash
# Find potential RLS bypasses
grep -r "prisma\." --include="*.ts" app/ lib/ | grep -v "withUserContext\|withAdminContext\|withSystemContext"
2. Authentication Checks
  • All protected routes verify authentication
  • Clerk auth() called before data access
  • Proper 401/403 responses for unauthorized
bash
# Find routes missing auth checks
grep -r "export async function" --include="route.ts" app/ | head -20
# Manually verify each has auth check
3. Credential Scanning
  • No hardcoded secrets in code
  • No API keys in client-side code
  • Environment variables used correctly
bash
# Scan for potential secrets
grep -rE "(sk_live|pk_live|password|secret|key)" --include="*.ts" --include="*.tsx" | grep -v "process.env\|.env"
4. Dependency Vulnerabilities
bash
# Run security audit
npm audit
yarn audit

# Check for high/critical vulnerabilities
npm audit --audit-level=high
5. Input Validation
  • User input validated with Zod schemas
  • No raw query interpolation
  • File upload restrictions in place

OWASP Top 10 Checklist

RiskCheckStatus
A01 Broken AccessRLS enforced, auth on all routes☐
A02 Crypto FailuresSecrets in env vars only☐
A03 InjectionParameterized queries, Zod☐
A04 Insecure DesignAuth-first pattern followed☐
A05 MisconfigurationProd env properly secured☐
A06 Vulnerable Depsnpm audit clean☐
A07 Auth FailuresClerk integration correct☐
A08 Data IntegrityRLS prevents tampering☐
A09 Logging FailuresSecurity events logged☐
A10 SSRFExternal URLs validated☐

Security Validation Commands

bash
# Complete security check
npm audit && yarn lint && echo "Security checks passed"

# RLS bypass detection
grep -r "prisma\." --include="*.ts" app/ lib/ | wc -l
# Compare with context wrapper count

# Secret detection
git secrets --scan  # If git-secrets installed
grep -rE "sk_|pk_|password=" . --include="*.ts"

Pre-Deployment Security Review

Before ANY production deployment:

  • npm audit shows no high/critical issues
  • RLS policies validated
  • No new direct Prisma calls
  • Environment variables documented
  • Backup taken before migration
  • Rollback plan documented

Security Audit Report Template

markdown
## Security Audit Report - {{TICKET_PREFIX}}-XXX

### Summary

- **Date**: [date]
- **Auditor**: Security Engineer
- **Scope**: [what was audited]

### Findings

| Severity | Issue | Location | Status |
| -------- | ----- | -------- | ------ |
| HIGH     | ...   | ...      | FIXED  |
| MEDIUM   | ...   | ...      | OPEN   |

### RLS Validation

- [x] All tables have RLS enabled
- [x] User isolation verified
- [x] Admin policies scoped correctly

### Recommendations

1. [recommendation]
2. [recommendation]

### Approval

- [ ] Security Engineer approves
- [ ] Ready for deployment

Authoritative References

  • Security Architecture: docs/guides/SECURITY_FIRST_ARCHITECTURE.md
  • RLS Implementation: docs/database/RLS_IMPLEMENTATION_GUIDE.md
  • RLS Policies: docs/database/RLS_POLICY_CATALOG.md
  • OWASP Top 10: https://owasp.org/Top10/

© bybren-llc, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .claude/skills/security-audit of bybren-llc/safe-agentic-workflow.

  • SKILL.md
  • README.md

Open the folder on GitHubat commit 26ca58b

Compare with similar skills

Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Audit this skillbybren-llc/safe-agentic-workflow423—~1.4kAutomated safety check: NotesMIT
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Octopus Security Auditnyldn/claude-octopus4.2k1 repos~2.3kAutomated safety check: PassMIT
Security Checkgocronx-team/gocron808—~690Automated safety check: PassMIT

Similar skills

  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Octopus Security Audit

    nyldn/claude-octopus

    OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

    4.2k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check passed
  • Security Check

    gocronx-team/gocron

    Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

    808 GitHub stars~690 tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    283 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings

More from bybren-llc/safe-agentic-workflow

All 42 skills in this repo
  • Multi-Agent Coordination Template

    bybren-llc/safe-agentic-workflow

    Agent assignment matrix, blocker escalation, and TDM coordination patterns. Use when assigning work to specialist agents, managing blockers across agents…

    423 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • API Route Patterns

    bybren-llc/safe-agentic-workflow

    API route implementation patterns with RLS, validation, and error handling. Use when creating API routes, implementing CRUD endpoints, adding server-side…

    423 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Technical Documentation Templates

    bybren-llc/safe-agentic-workflow

    Documentation templates for ADRs, runbooks, architecture docs, and knowledge transfer documents. Use when creating Architecture Decision Records, writing…

    423 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Deployment SOP Checklist

    bybren-llc/safe-agentic-workflow

    Deployment workflows, pre-deploy validation, smoke testing, and rollback procedures. Use when deploying to staging or production, running smoke tests…

    423 GitHub stars~950 tokensUpdated 2 mo ago
    Auto-check passed
  • Frontend Patterns Template

    bybren-llc/safe-agentic-workflow

    Frontend patterns for modern web frameworks, component libraries, auth flows, and analytics. Use when building UI components, creating pages, implementing…

    423 GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Advanced Git Operations

    bybren-llc/safe-agentic-workflow

    Advanced git operations including rebase, bisect, cherry-pick, and conflict resolution. Use when rebasing feature branches, debugging with bisect…

    423 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Security Audit

What does Security Audit do?

RLS validation, security audits, OWASP compliance, and vulnerability scanning. Security Audit is an agent skill from bybren-llc/safe-agentic-workflow. RLS validation, security audits, OWASP compliance, and vulnerability scanning.

When should I use Security Audit?

Security Audit fits situations like: validating RLS policies; auditing API routes; scanning for security issues.

How do I install Security Audit in Claude Code?

Run `npx skills add bybren-llc/safe-agentic-workflow --skill security-audit -a claude-code`. Or copy the skill folder (.claude/skills/security-audit in bybren-llc/safe-agentic-workflow) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Security Audit in Codex?

Run `npx skills add bybren-llc/safe-agentic-workflow --skill security-audit -a codex`. Or copy the skill folder (.claude/skills/security-audit in bybren-llc/safe-agentic-workflow) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.

Can I use Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bybren-llc/safe-agentic-workflow --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.

What does Security Audit need to run?

Going by SKILL.md and its folder, Security Audit needs the command-line tools its instructions call (npm, yarn and git) and credentials named API_KEY and STRIPE_SECRET_KEY. Our summary lists: A credential in API_KEY; A credential in STRIPE_SECRET_KEY. Its frontmatter pre-approves these tools: Read, Bash, Grep, Glob.

Does Security Audit access the network?

SKILL.md names 1 domain. As links in the text: owasp.org. This is read from the text; nothing was executed.

Is Security Audit safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Audit use?

Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Audit use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Audit?

Skills that share tags, products or a category with Security Audit: Security Auditor (eigent-ai/eigent, 15k stars), Code Audit (3stoneBrother/code-audit, 892 stars), Security Audit Scanner (ruvnet/ruflo, 74k stars) and Octopus Security Audit (nyldn/claude-octopus, 4.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Audit?

bybren-llc (a GitHub organization) maintains it in bybren-llc/safe-agentic-workflow, which has 423 GitHub stars. The repository holds 42 skills in this directory. The repository was last updated on July 20, 2026.

Source: bybren-llc/safe-agentic-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.