Agent skill

Security Auditor

by dralgorhythm in dralgorhythm/claude-agentic-framework

Assess vulnerabilities and audit for security compliance using OWASP and STRIDE methodology — a user-invoked Security Auditor workflow.

No licenceAuto-check passedSecurity

Install Security Auditor

skills CLI
$ npx skills add dralgorhythm/claude-agentic-framework --skill security-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dralgorhythm/claude-agentic-framework security-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dralgorhythm/claude-agentic-framework.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/security-auditor .claude/skills/security-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-auditor
GitHub stars
125
Token cost
~496 tokens
SKILL.md length
208 words
Files
1
Skills in repo
20
Repo updated
First seen
Licence
None found

At a glance

Assess vulnerabilities and audit for security compliance using OWASP and STRIDE methodology — a user-invoked Security Auditor workflow.

  • Works in 5 steps: Map surface — Use Grep and Glob to… → Enumerate threats — Apply STRIDE per the… → Trace data — Use Grep to trace data flow… → …
  • Tasks that involve Threat modeling
  • SKILL.md covers Method, MCP Tools, Audit Workflow and Audit Checklist, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Auditor is an agent skill from dralgorhythm/claude-agentic-framework. Assess vulnerabilities and audit for security compliance using OWASP and STRIDE methodology — a user-invoked Security Auditor workflow.

Its SKILL.md is about 500 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Threat modeling, Web application vulnerabilities and SOC 2 and security compliance. It works with GitHub. The repository describes itself as: A More Effective Agent Harness for Claude.

When your agent uses it

  • Tasks that involve Threat modeling
  • Tasks that involve Web application vulnerabilities
  • Tasks that involve SOC 2 and security compliance

Example prompts

  • “/security-auditor”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Map surface — Use Grep and Glob to identify entry points
  2. Enumerate threats — Apply STRIDE per the threat-modeling skill
  3. Trace data — Use Grep to trace data flow through handlers for injection, broken access control, and the other OWASP risk categories…
  4. Document — Create findings with severity ratings
  5. Track — Use GitHub MCP to create issues for remediation

What it can do on your machine

Read from SKILL.md and the folder at commit 6436a20. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Auditor loads about 496 tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 208 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~496

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 208 words (~496 tokens).

“Role entry point for security compliance and vulnerability assessment.”

— opening of SKILL.md by dralgorhythm
name
security-auditor
argument-hint
[scope-or-component]
disable-model-invocation
true

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .claude/skills/security-auditor of dralgorhythm/claude-agentic-framework.

Open the folder on GitHubat commit 6436a20

Compare with similar skills

Security Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Auditor this skilldralgorhythm/claude-agentic-framework125—~496Automated safety check: PassNone
Security Auditoraiskillstore/marketplace4306 repos~2.6kAutomated safety check: PassNone
CybersecurityAgriciDaniel/claude-cybersecurity227—~11kAutomated safety check: WarnMIT
Security Auditorcuriositech/some_claude_skills243—~2.2kAutomated safety check: PassMIT
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT

Similar skills

  • Security Auditor

    aiskillstore/marketplace

    Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.

    430 GitHub starsUsed in 6 repos~2.6k tokens
    SecurityAuto-check passed
  • Cybersecurity

    AgriciDaniel/claude-cybersecurity

    Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.

    227 GitHub stars~11k tokensUpdated 5 mo ago
    SecurityAuto-check: warnings
  • Security Auditor

    curiositech/some_claude_skills

    Security vulnerability scanner and OWASP compliance auditor for codebases.

    243 GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Security and Hardening

    addyosmani/agent-skills

    Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

    103k GitHub starsUsed in 1 repo~4.4k tokens
    SecurityAuto-check: notes

More from dralgorhythm/claude-agentic-framework

All 20 skills in this repo
  • Swarm Coordination

    dralgorhythm/claude-agentic-framework

    Rules for several agents sharing one repository: an orchestrator tracks work in two tiers, workers write to scratch files, and every handoff leaves a pointer to an artifact.

    125 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Threat Modeling

    dralgorhythm/claude-agentic-framework

    Finds security threats in a design with a STRIDE pass per component, rates severity and records fixes, with extra checks for AI agent and tool risks.

    125 GitHub stars~581 tokensUpdated 2 mo ago
    Auto-check passed
  • Architecture Decision Record Writer

    dralgorhythm/claude-agentic-framework

    Writes Architecture Decision Records with title, status, context, decision, rationale and consequences for significant technical choices, kept short and numbered.

    125 GitHub stars~529 tokensUpdated 2 mo ago
    Auto-check passed
  • Codebase Health Auditor

    dralgorhythm/claude-agentic-framework

    Runs a user-invoked, swarm-style audit of a whole codebase for SOLID and DRY violations, code smells, complexity, dead code and pattern consistency, with a prioritized report.

    125 GitHub stars~980 tokensUpdated 2 mo ago
    Auto-check passed
  • Dependency Upgrade Protocol

    dralgorhythm/claude-agentic-framework

    Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.

    125 GitHub stars~1.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Designing Systems

    dralgorhythm/claude-agentic-framework

    Produces this framework's ADR and system-design artifacts from bundled templates with trade-off analysis.

    125 GitHub stars~458 tokensUpdated 2 mo ago
    Auto-check passed

Works with

Categories

Questions about Security Auditor

What does Security Auditor do?

Assess vulnerabilities and audit for security compliance using OWASP and STRIDE methodology — a user-invoked Security Auditor workflow. Security Auditor is an agent skill from dralgorhythm/claude-agentic-framework. Assess vulnerabilities and audit for security compliance using OWASP and STRIDE methodology — a user-invoked Security Auditor workflow.

When should I use Security Auditor?

Security Auditor fits situations like: tasks that involve Threat modeling; tasks that involve Web application vulnerabilities; tasks that involve SOC 2 and security compliance.

How do I install Security Auditor in Claude Code?

Run `npx skills add dralgorhythm/claude-agentic-framework --skill security-auditor -a claude-code`. Or copy the skill folder (.claude/skills/security-auditor in dralgorhythm/claude-agentic-framework) into .claude/skills/security-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Security Auditor in Codex?

Run `npx skills add dralgorhythm/claude-agentic-framework --skill security-auditor -a codex`. Or copy the skill folder (.claude/skills/security-auditor in dralgorhythm/claude-agentic-framework) into .agents/skills/security-auditor in your project. Codex loads it when a task matches its description.

Can I use Security Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dralgorhythm/claude-agentic-framework --skill security-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-auditor, .gemini/skills/security-auditor, .github/skills/security-auditor and .opencode/skills/security-auditor in your project.

What does Security Auditor need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Auditor is instructions for the agent only.

Does Security Auditor access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Auditor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Auditor use?

No licence was found for Security Auditor or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Security Auditor use?

About 496 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Auditor?

Skills that share tags, products or a category with Security Auditor: Security Auditor (aiskillstore/marketplace, 430 stars), Cybersecurity (AgriciDaniel/claude-cybersecurity, 227 stars), Security Auditor (curiositech/some_claude_skills, 243 stars) and Security And Hardening (penpot/penpot, 61k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Auditor?

dralgorhythm (a GitHub user) maintains it in dralgorhythm/claude-agentic-framework, which has 125 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on July 24, 2026.

Source: dralgorhythm/claude-agentic-framework on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.