Agent skill

Security Auditor

by curiositech in curiositech/some_claude_skills

Security vulnerability scanner and OWASP compliance auditor for codebases.

MITAuto-check passedSecurity

Install Security Auditor

skills CLI
$ npx skills add curiositech/some_claude_skills --skill security-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install curiositech/some_claude_skills security-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/curiositech/some_claude_skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/security-auditor .claude/skills/security-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-auditor
GitHub stars
243
Token cost
~2.2k tokens
SKILL.md length
602 words
Files
6 (incl. scripts, references)
Skills in repo
109
Repo updated
First seen
Licence
MIT

At a glance

Security vulnerability scanner and OWASP compliance auditor for codebases.

  • Works in 4 steps: Dependency Scanning → Secret Detection → OWASP Top 10 Static Analysis → …
  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers When to Use, Quick Start, Core Scanning Capabilities and Anti-Patterns, plus 6 more sections
  • Runs Shell and Python scripts from its folder; calls npm, yarn and cargo; reaches owasp.org

What it does

Security Auditor is an agent skill from curiositech/some_claude_skills. Security vulnerability scanner and OWASP compliance auditor for codebases. Dependency scanning (npm audit, pip-audit), secret detection (high-entropy strings, API keys), SAST for injection/XSS vulnerabilities, and security posture reports. Activate on 'security audit', 'vulnerability scan', 'OWASP', 'secret detection', 'dependency check', 'CVE', 'security review', 'penetration testing prep'. NOT for runtime WAF configuration (use infrastructure tools), network security/firewalls, or compliance certifications like…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `.claude-plugin/plugin.json`, `references/owasp-top-10-2024.md` and `scripts/detect-secrets.sh`).

It sits in Security, covering Web application vulnerabilities, Security review and Vulnerability scanning. The repository describes itself as: Claude skills that make my life easier. The licence is MIT.

When your agent uses it

  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Security review
  • Tasks that involve Vulnerability scanning

Example prompts

  • “security audit”
  • “vulnerability scan”
  • “secret detection”
  • “/security-auditor”

Requirements

  • Python 3
  • A Bash shell
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(npm audit:*,pip-audit:*,grep:*,find:*), Grep, Glob

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Dependency Scanning
  2. Secret Detection
  3. OWASP Top 10 Static Analysis
  4. Language-Specific Checks

What it can do on your machine

Read from SKILL.md and the folder at commit 6713fc7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(npm audit:*
    • pip-audit:*
    • grep:*
    • find:*)
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Shell and Python), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • yarn
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Auditor loads about 2.2k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 143 tokens; SKILL.md has 602 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~143
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from curiositech/some_claude_skills at commit 6713fc7, republished under its MIT licence (© curiositech). 602 words, ~2,200 tokens.

Download SKILL.mdSave it as .claude/skills/security-auditor/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
security-auditor
description
Security vulnerability scanner and OWASP compliance auditor for codebases. Dependency scanning (npm audit, pip-audit), secret detection (high-entropy strings, API keys), SAST for injection/XSS vulnerabilities, and security posture reports. Activate on 'security audit', 'vulnerability scan', 'OWASP', 'secret detection', 'dependency check', 'CVE', 'security review', 'penetration testing prep'. NOT for runtime WAF configuration (use infrastructure tools), network security/firewalls, or compliance certifications like SOC2/HIPAA (legal/organizational).
allowed-tools
Read, Write, Edit, Bash(npm audit:*,pip-audit:*,grep:*,find:*), Grep, Glob
metadata.category
Code Quality & Testing
metadata.tags
security, owasp, vulnerabilities, sast, dependencies

Security Auditor

Comprehensive security scanning for codebases. Identifies vulnerabilities before they become incidents. Focuses on actionable findings with remediation guidance.

When to Use

Use for:

  • Pre-deployment security audits
  • Dependency vulnerability scanning
  • Secret/credential leak detection
  • Code-level SAST (Static Application Security Testing)
  • Security posture reports for stakeholders
  • OWASP Top 10 compliance checking
  • Pre-PR security reviews

Do NOT use for:

  • Runtime security (WAF, rate limiting) - use infrastructure tools
  • Network security/firewall rules - use cloud/DevOps skills
  • SOC2/HIPAA/PCI compliance - requires legal/organizational process
  • Penetration testing execution - this is detection, not exploitation

Quick Start

Full Security Audit
bash
# Run comprehensive scan
./scripts/full-audit.sh /path/to/project

# Output: security-report.json + summary
Quick Checks
bash
# Dependency vulnerabilities only
npm audit --json > deps-audit.json

# Secret detection only
./scripts/detect-secrets.sh /path/to/project

# OWASP check specific file
./scripts/owasp-check.py /path/to/file.js

Core Scanning Capabilities

1. Dependency Scanning
Package ManagerCommandSeverity Levels
npmnpm audit --jsoncritical, high, moderate, low
yarnyarn audit --jsonsame as npm
pippip-audit --format jsoncritical, high, medium, low
cargocargo audit --jsonsame

Decision Tree:

Critical severity found?
├── YES → Block deployment, immediate fix required
│   └── Check if patch available → npm audit fix --force
├── NO → High severity?
    ├── YES → Fix within sprint, document if deferred
    └── NO → Low/Moderate → Track, fix during maintenance
2. Secret Detection

High-Risk Patterns:

  • API keys: /[A-Za-z0-9_]{20,}/ near "key", "api", "secret"
  • AWS credentials: AKIA[0-9A-Z]{16}
  • Private keys: -----BEGIN (RSA|EC|OPENSSH) PRIVATE KEY-----
  • JWT tokens: eyJ[A-Za-z0-9_-]+\.eyJ[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+
  • Connection strings: ://[^:]+:[^@]+@

Entropy Analysis:

  • Shannon entropy > 4.5 on strings > 20 chars = suspicious
  • Base64-encoded blobs in source = investigate

False Positive Handling:

Secret-like pattern found?
├── In test file? → Lower severity, document
├── In example/docs? → Check if placeholder
├── High entropy + near "password"/"secret" → High confidence
└── In .env.example? → Acceptable if placeholder values
3. OWASP Top 10 Static Analysis
#VulnerabilityDetection Pattern
A01Broken Access ControlMissing auth checks on routes
A02Cryptographic FailuresWeak algorithms (MD5, SHA1 for passwords)
A03InjectionUnparameterized queries, eval(), innerHTML
A04Insecure DesignHardcoded credentials, missing rate limits
A05Security MisconfigurationDebug mode in prod, default credentials
A06Vulnerable ComponentsKnown CVEs in dependencies
A07Auth FailuresWeak password policies, session issues
A08Integrity FailuresUnsigned updates, untrusted deserialization
A09Logging FailuresSensitive data in logs, missing audit trails
A10SSRFUnvalidated URL inputs to fetch/request
4. Language-Specific Checks

JavaScript/TypeScript:

  • eval(), new Function() - code injection
  • innerHTML, outerHTML - XSS vectors
  • document.write() - DOM-based XSS
  • child_process.exec() with user input - command injection
  • Regex without timeout - ReDoS vulnerability

Python:

  • pickle.loads() with untrusted data - arbitrary code execution
  • yaml.load() without Loader=SafeLoader - code injection
  • subprocess.shell=True - command injection
  • eval(), exec() - code injection
  • SQL string concatenation - SQL injection

SQL:

  • String concatenation in queries - SQL injection
  • LIKE '%' + input + '%' - injection via wildcards
  • Missing parameterization - critical vulnerability

Anti-Patterns

Anti-Pattern: Security by Obscurity

What it looks like: "Nobody will find this hardcoded password" Why wrong: Secrets in source always leak eventually Instead: Environment variables, secret managers, zero hardcoded secrets

Show full SKILL.md (238 more words)Show less
Anti-Pattern: Audit Fatigue

What it looks like: 500 findings, all "medium", team ignores Why wrong: Critical issues buried in noise Instead: Prioritize by exploitability, start with critical/high only

Anti-Pattern: Fix Without Understanding

What it looks like: npm audit fix --force without review Why wrong: May introduce breaking changes, doesn't address root cause Instead: Review each fix, understand the vulnerability, test after

Anti-Pattern: One-Time Audit

What it looks like: "We did a security audit last year" Why wrong: New CVEs daily, code changes constantly Instead: CI/CD integration, weekly automated scans minimum

Security Report Format

json
{
  "summary": {
    "critical": 0,
    "high": 2,
    "medium": 5,
    "low": 12,
    "informational": 8
  },
  "findings": [
    {
      "id": "SEC-001",
      "severity": "high",
      "category": "A03:Injection",
      "title": "SQL Injection in user search",
      "location": "src/api/users.js:45",
      "description": "User input concatenated directly into SQL query",
      "evidence": "const query = `SELECT * FROM users WHERE name = '${input}'`",
      "remediation": "Use parameterized queries: db.query('SELECT * FROM users WHERE name = $1', [input])",
      "references": ["https://owasp.org/www-community/attacks/SQL_Injection"]
    }
  ],
  "recommendations": [
    "Implement parameterized queries across all database access",
    "Add input validation layer",
    "Enable SQL query logging for monitoring"
  ]
}

CI/CD Integration

GitHub Actions Example
yaml
security-scan:
  runs-on: ubuntu-latest
  steps:
    - uses: actions/checkout@v4
    - name: Run security audit
      run: |
        npm audit --json > audit.json
        ./scripts/detect-secrets.sh . > secrets.json
        ./scripts/generate-report.py
    - name: Fail on critical
      run: |
        if jq '.summary.critical > 0' report.json; then
          echo "Critical vulnerabilities found!"
          exit 1
        fi

Scripts (in scripts/ folder)

ScriptPurpose
full-audit.shComprehensive security scan
detect-secrets.shHigh-entropy string and pattern detection
owasp-check.pyOWASP Top 10 static analysis
generate-report.pyCombine findings into unified report

Expert vs Novice Approach

NoviceExpert
Runs audit once before releaseCI/CD integration, every commit
Focuses on tool output onlyUnderstands vulnerability context
Fixes everything or nothingTriages by exploitability
Uses one scannerLayers multiple tools
Ignores false positivesTunes detection rules

Success Metrics

MetricTarget
Critical/High pre-production0
Mean time to remediate critical< 24 hours
False positive rate< 10%
Scan coverage100% of deployable code

Reference Files

  • references/owasp-top-10-2024.md - Detailed OWASP guidance
  • references/secret-patterns.md - Comprehensive regex patterns
  • references/remediation-playbook.md - Fix guidance by vulnerability type
  • references/ci-cd-templates.md - Integration examples
  • scripts/ - Working security scanning scripts

Detects: Dependency CVEs | Secret leaks | Injection vulnerabilities | OWASP violations | Security misconfigurations

Use with: site-reliability-engineer (deployment gates) | code-review (PR security checks)

© curiositech, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in .claude/skills/security-auditor of curiositech/some_claude_skills.

  • SKILL.md
  • .claude-plugin/plugin.json
  • references/owasp-top-10-2024.md
  • scripts/detect-secrets.sh
  • scripts/full-audit.sh
  • scripts/owasp-check.py

Open the folder on GitHubat commit 6713fc7

Compare with similar skills

Security Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Auditor this skillcuriositech/some_claude_skills243—~2.2kAutomated safety check: PassMIT
Senior Secopsalirezarezvani/claude-skills28k1 repos~4kAutomated safety check: PassMIT
Security Auditoraiskillstore/marketplace4306 repos~2.6kAutomated safety check: PassNone
Security Checkgocronx-team/gocron808—~690Automated safety check: PassMIT
Cyber NeoHainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT
Security Auditstaruhub/ClaudeSkills727—~1.3kAutomated safety check: NotesMIT

Similar skills

  • Senior Secops

    alirezarezvani/claude-skills

    Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices.

    28k GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed
  • Security Auditor

    aiskillstore/marketplace

    Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.

    430 GitHub starsUsed in 6 repos~2.6k tokens
    SecurityAuto-check passed
  • Security Check

    gocronx-team/gocron

    Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

    808 GitHub stars~690 tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    281 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Security Audit

    staruhub/ClaudeSkills

    全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -…

    727 GitHub stars~1.3k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

    241 GitHub starsUsed in 2 repos~3.6k tokens
    SecurityAuto-check passed

More from curiositech/some_claude_skills

All 109 skills in this repo
  • Crisis Detection Intervention AI

    curiositech/some_claude_skills

    Detect crisis signals in user content using NLP, mental health sentiment analysis, and safe intervention protocols.

    243 GitHub starsUsed in 3 repos~3.8k tokens
    Auto-check passed
  • Form Validation Architect

    curiositech/some_claude_skills

    End-to-end form handling with react-hook-form, Zod schemas, validation patterns, error messaging, field arrays, and multi-step wizards.

    243 GitHub stars~3.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Competitive Cartographer

    curiositech/some_claude_skills

    Strategic analyst that maps competitive landscapes, identifies white space opportunities, and provides positioning recommendations.

    243 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • GitHub Actions Pipeline Builder

    curiositech/some_claude_skills

    Build production CI/CD pipelines with GitHub Actions. An agent skill from curiositech/some_claude_skills.

    243 GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • Computer Vision Pipeline

    curiositech/some_claude_skills

    Build production computer vision pipelines for object detection, tracking, and video analysis.

    243 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Design Archivist

    curiositech/some_claude_skills

    Long-running design anthropologist that builds comprehensive visual databases from 500-1000 real-world examples, extracting color palettes, typography patterns, layout systems, and interaction…

    243 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check passed

Categories

Questions about Security Auditor

What does Security Auditor do?

Security vulnerability scanner and OWASP compliance auditor for codebases. Security Auditor is an agent skill from curiositech/some_claude_skills. Security vulnerability scanner and OWASP compliance auditor for codebases.

When should I use Security Auditor?

Security Auditor fits situations like: tasks that involve Web application vulnerabilities; tasks that involve Security review; tasks that involve Vulnerability scanning.

How do I install Security Auditor in Claude Code?

Run `npx skills add curiositech/some_claude_skills --skill security-auditor -a claude-code`. Or copy the skill folder (.claude/skills/security-auditor in curiositech/some_claude_skills) into .claude/skills/security-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Security Auditor in Codex?

Run `npx skills add curiositech/some_claude_skills --skill security-auditor -a codex`. Or copy the skill folder (.claude/skills/security-auditor in curiositech/some_claude_skills) into .agents/skills/security-auditor in your project. Codex loads it when a task matches its description.

Can I use Security Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add curiositech/some_claude_skills --skill security-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-auditor, .gemini/skills/security-auditor, .github/skills/security-auditor and .opencode/skills/security-auditor in your project.

What does Security Auditor need to run?

Going by SKILL.md and its folder, Security Auditor needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (npm, yarn and cargo). Our summary lists: Python 3; A Bash shell. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(npm audit:*,pip-audit:*,grep:*,find:*), Grep, Glob.

Does Security Auditor access the network?

SKILL.md names 1 domain. In commands or code: owasp.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Security Auditor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Auditor use?

Security Auditor is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Auditor use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Security Auditor?

Skills that share tags, products or a category with Security Auditor: Senior Secops (alirezarezvani/claude-skills, 28k stars), Security Auditor (aiskillstore/marketplace, 430 stars), Security Check (gocronx-team/gocron, 808 stars) and Cyber Neo (Hainrixz/cyber-neo, 281 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Auditor?

curiositech (a GitHub organization) maintains it in curiositech/some_claude_skills, which has 243 GitHub stars. The repository holds 109 skills in this directory. The repository was last updated on September 6, 2026.

Source: curiositech/some_claude_skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.