Agent skill

Audit Desktop Client Security

by cyberful in cyberful/cyberful

Audit desktop client source, binaries, packaging, updater, local storage, IPC, protocol handlers, WebViews, plugins, native bridges, credential use, and OS integration for trust-boundary failures.

AGPL-3.0Auto-check passedSecurity

Install Audit Desktop Client Security

skills CLI
$ npx skills add cyberful/cyberful --skill audit-desktop-client-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cyberful/cyberful audit-desktop-client-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cyberful/cyberful.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cyberful/builtin/skills/audit-desktop-client-security .claude/skills/audit-desktop-client-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-desktop-client-security
GitHub stars
135
Token cost
~637 tokens
SKILL.md length
195 words
Files
4 (incl. references, assets)
Skills in repo
85
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Audit desktop client source, binaries, packaging, updater, local storage, IPC, protocol handlers, WebViews, plugins, native bridges, credential use, and OS integration for trust-boundary failures.

  • Linux application code and artifact review
  • SKILL.md covers Map entry and privilege…, Trace untrusted data to effects and Deliver
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Audit Desktop Client Security is an agent skill from cyberful/cyberful. Audit desktop client source, binaries, packaging, updater, local storage, IPC, protocol handlers, WebViews, plugins, native bridges, credential use, and OS integration for trust-boundary failures. Use for Windows, macOS, or Linux application code and artifact review.

Its SKILL.md is about 640 tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files and assets (for example `agents/openai.yaml`, `assets/desktop-boundary-matrix.template.json` and `references/desktop-client-audit.md`).

It sits in Security. It works with Linux and macOS. The repository describes itself as: Cyberful is an open-source AI Red Team for discovering, exploiting, verifying, and remediating vulnerabilities. The licence is AGPL-3.0.

When your agent uses it

  • Linux application code and artifact review

Example prompts

  • “/audit-desktop-client-security”

What it can do on your machine

Read from SKILL.md and the folder at commit ec598a6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Desktop Client Security loads about 637 tokens when it runs, and up to ~953 if it reads all its reference files. Until then it costs about 74 tokens; SKILL.md has 195 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~637
With references · SKILL.md plus every file in references/, read only if the agent opens them
~953

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cyberful/cyberful at commit ec598a6, republished under its AGPL-3.0 licence (© cyberful). 195 words, ~637 tokens.

Download SKILL.mdSave it as .claude/skills/audit-desktop-client-security/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
audit-desktop-client-security
description
Audit desktop client source, binaries, packaging, updater, local storage, IPC, protocol handlers, WebViews, plugins, native bridges, credential use, and OS integration for trust-boundary failures. Use for Windows, macOS, or Linux application code and artifact review.
metadata.domain
application-security
metadata.subdomain
desktop-client-security
metadata.triggers
audit desktop client security, Electron application security audit, desktop updater security review, native client IPC audit, desktop credential storage review
metadata.tags
desktop, Electron, IPC, updater, protocol-handlers, native-bridge

Audit Desktop Client Security

Audit the installed client as an OS-integrated trust graph. A server-side permission does not protect local IPC, update, file, protocol, plugin, WebView, credential, or privileged-helper boundaries.

Map entry and privilege boundaries

Inventory executables, packages, signatures, update channels, services and helpers, IPC endpoints, custom protocols, file associations, deep links, drag-and-drop and clipboard inputs, local databases, credential stores, browser or WebView contexts, preload and native bridges, plugins, dynamic loading, and command execution paths.

Copy assets/desktop-boundary-matrix.template.json into the workarea. Read references/desktop-client-audit.md when reconciling source assumptions with installed or packaged behavior.

Trace untrusted data to effects

Follow origins, files, URLs, messages, update metadata, local users, and remote content through parsing, canonicalization, authorization, process boundaries, privilege changes, filesystem writes, credential access, and native calls. Test mentally for cross-user, cross-origin, cross-profile, and downgrade or rollback confusion.

Route binary reversing to operate-binary-analysis-toolchain, browser-specific behavior to browser specialists, and memory-unsafe native code to audit-native-memory-safety. Keep this audit focused on desktop composition and OS integration.

Deliver

Report the producer, consumer, canonical form, identity, authorization owner, resulting OS or application effect, deployment prerequisites, source or artifact evidence, and narrowest safe validation. Separate local self-impact from cross-user, privilege, persistence, or remote impact.

© cyberful, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references, assets) in cyberful/builtin/skills/audit-desktop-client-security of cyberful/cyberful.

  • SKILL.md
  • agents/openai.yaml
  • assets/desktop-boundary-matrix.template.json
  • references/desktop-client-audit.md

Open the folder on GitHubat commit ec598a6

Compare with similar skills

Audit Desktop Client Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Desktop Client Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Desktop Client Security this skillcyberful/cyberful135—~637Automated safety check: PassAGPL-3.0
Game Automationrehan-remade/universal-modder5.8k—~1.9kAutomated safety check: PassMIT
Ctf Cryptoljagiello/ctf-skills3.4k—~11kAutomated safety check: NotesMIT
Os Hardware Inventorycdxgen/cdxgen1.1k—~1.5kAutomated safety check: PassApache-2.0
Forensics OsqueryAgentSecOps/SecOpsAgentKit2201 repos~4.9kAutomated safety check: NotesCustom licence
Bumblebeesickn33/agentic-awesome-skills47k1 repos~2.5kAutomated safety check: NotesMIT

Similar skills

  • Game Automation

    rehan-remade/universal-modder

    Launch, see and drive a real game so an agent can test its own mods.

    5.8k GitHub stars~1.9k tokensUpdated today
    SecurityAuto-check passed
  • Ctf Crypto

    ljagiello/ctf-skills

    Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.

    3.4k GitHub stars~11k tokensUpdated 25 days ago
    SecurityAuto-check: notes
  • Collects live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents using the cdxgen obom and hbom commands, including osquery-backed runtime artifacts, Linux…

    1.1k GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Forensics Osquery

    AgentSecOps/SecOpsAgentKit

    SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.

    220 GitHub starsUsed in 1 repo~4.9k tokens
    SecurityAuto-check: notes
  • Bumblebee

    sickn33/agentic-awesome-skills

    Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    SecurityAuto-check: notes
  • Performing Memory Forensics With Volatility3 Plugins

    mukul975/Anthropic-Cybersecurity-Skills

    Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from cyberful/cyberful

All 85 skills in this repo
  • Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence.

    135 GitHub stars~649 tokensUpdated 1 mo ago
    Auto-check passed
  • Audit Kubernetes admission and policy-as-code enforcement against local workload manifests, exception paths, namespace scope, and deployment evidence.

    135 GitHub stars~610 tokensUpdated 1 mo ago
    Auto-check passed
  • Audit PCI DSS penetration-test methodology, scope, internal and external reports, segmentation results, tester independence, remediation, retesting, retention, and multi-tenant support evidence.

    135 GitHub stars~1k tokensUpdated 1 mo ago
    Auto-check passed
  • Operate Content Discovery

    cyberful/cyberful

    Design and interpret advanced content discovery with ffuf and complementary web fuzzers.

    135 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Operate Network Recon

    cyberful/cyberful

    Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up.

    135 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Operate Sast Toolchain

    cyberful/cyberful

    Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits.

    135 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Audit Desktop Client Security

What does Audit Desktop Client Security do?

Audit desktop client source, binaries, packaging, updater, local storage, IPC, protocol handlers, WebViews, plugins, native bridges, credential use, and OS integration for trust-boundary failures. Audit Desktop Client Security is an agent skill from cyberful/cyberful. Audit desktop client source, binaries, packaging, updater, local storage, IPC, protocol handlers, WebViews, plugins, native bridges, credential use, and OS integration for trust-boundary failures.

When should I use Audit Desktop Client Security?

Audit Desktop Client Security fits situations like: linux application code and artifact review.

How do I install Audit Desktop Client Security in Claude Code?

Run `npx skills add cyberful/cyberful --skill audit-desktop-client-security -a claude-code`. Or copy the skill folder (cyberful/builtin/skills/audit-desktop-client-security in cyberful/cyberful) into .claude/skills/audit-desktop-client-security in your project. Claude Code loads it when a task matches its description.

How do I install Audit Desktop Client Security in Codex?

Run `npx skills add cyberful/cyberful --skill audit-desktop-client-security -a codex`. Or copy the skill folder (cyberful/builtin/skills/audit-desktop-client-security in cyberful/cyberful) into .agents/skills/audit-desktop-client-security in your project. Codex loads it when a task matches its description.

Can I use Audit Desktop Client Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cyberful/cyberful --skill audit-desktop-client-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-desktop-client-security, .gemini/skills/audit-desktop-client-security, .github/skills/audit-desktop-client-security and .opencode/skills/audit-desktop-client-security in your project.

What does Audit Desktop Client Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit Desktop Client Security is instructions for the agent only.

Does Audit Desktop Client Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Desktop Client Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Desktop Client Security use?

Audit Desktop Client Security is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Desktop Client Security use?

About 637 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 316 tokens, read only when the agent opens those files.

What are the alternatives to Audit Desktop Client Security?

Skills that share tags, products or a category with Audit Desktop Client Security: Game Automation (rehan-remade/universal-modder, 5.8k stars), Ctf Crypto (ljagiello/ctf-skills, 3.4k stars), Os Hardware Inventory (cdxgen/cdxgen, 1.1k stars) and Forensics Osquery (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Desktop Client Security?

cyberful (a GitHub organization) maintains it in cyberful/cyberful, which has 135 GitHub stars. The repository holds 85 skills in this directory. The repository was last updated on August 24, 2026.

Source: cyberful/cyberful on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.