Agent skill

Security Auditor

by eigent-ai in eigent-ai/eigent

Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

Apache-2.0Auto-check: notesSecurity

Install Security Auditor

skills CLI
$ npx skills add eigent-ai/eigent --skill skill-security-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install eigent-ai/eigent skill-security-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/eigent-ai/eigent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/resources/example-skills/skill-security-auditor .claude/skills/skill-security-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-security-auditor
GitHub stars
15k
Token cost
~1.8k tokens
SKILL.md length
418 words
Files
6 (incl. scripts, references)
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

  • Works in 6 steps: Reconnaissance → Secrets Detection → Vulnerability Scanning → …
  • Auditing a codebase for SQL injection, XSS or command injection
  • SKILL.md covers Overview, Quick Start, Audit Workflow and Report Format, plus 1 more section
  • Runs Python scripts from its folder; calls python, pip and npm; needs SECRET_KEY

What it does

The quick start runs `scripts/scan_project.py` against a project directory for a lightweight pass over hardcoded secrets, dangerous function calls and insecure patterns. A second script, `scripts/scan_secrets.py`, focuses on credentials, and both accept a text output format. For deeper work there is a longer audit workflow.

The workflow starts with reconnaissance: identify languages, frameworks and entry points, how authentication works, which external services are called and where user input is accepted. Secrets detection looks for API keys and tokens in source, database connection strings with passwords, committed private keys, plaintext `.env` files and secrets in CI configuration. Vulnerability scanning follows an OWASP Top 10 table covering broken access control, cryptographic failures, injection, insecure design, misconfiguration, vulnerable components and authentication failures. Two references list vulnerability and secret patterns, and the description adds dependency CVE checks and security reports.

When your agent uses it

  • Auditing a codebase for SQL injection, XSS or command injection
  • Finding hardcoded API keys and credentials before a release
  • Checking config files and dependencies for insecure defaults or known CVEs
  • Producing a security report for a project

Example prompts

  • “Run a security audit on this repo and list the highest-risk findings.”
  • “Scan the project for hardcoded secrets and committed .env files.”
  • “Check our dependencies for known CVEs and tell me what to upgrade.”
  • “Review the login and session code against the OWASP Top 10.”

Requirements

  • Python, to run the scan scripts

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Reconnaissance
  2. Secrets Detection
  3. Vulnerability Scanning
  4. Dependency Audit
  5. Configuration Review
  6. Authentication and Authorization Review

What it can do on your machine

Read from SKILL.md and the folder at commit 9c76fba. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • pip
    • npm
    • npx
    • trivy

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, npm and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Auditor loads about 1.8k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 142 tokens; SKILL.md has 418 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~142
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:61
    - `.env` files or config files with plaintext secrets

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from eigent-ai/eigent at commit 9c76fba, republished under its Apache-2.0 licence (© eigent-ai). 418 words, ~1,804 tokens.

Download SKILL.mdSave it as .claude/skills/skill-security-auditor/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
skill-security-auditor
description
Security auditing for code, configs, and infrastructure. Use when the user wants to audit or improve security: scan for vulnerabilities (SQL injection, XSS, command injection, path traversal), detect hardcoded secrets and credentials, review auth and authorization, check dependencies for known CVEs, audit config files for insecure defaults, or generate security reports. Trigger on "security audit", "vulnerability scan", "code review for security", "find secrets", "check for vulnerabilities", "OWASP", "CVE", or questions about code security.
license
Complete terms in LICENSE.txt

Security Auditor Guide

Overview

This guide covers security auditing workflows for source code, dependencies, and configurations. For detailed vulnerability patterns and detection rules, see references/vulnerability-patterns.md. For secrets detection patterns, see references/secrets-patterns.md.

Quick Start

Run the bundled scan script against a project directory:

bash
python scripts/scan_project.py /path/to/project

This performs a lightweight scan for common issues: hardcoded secrets, dangerous function calls, and insecure patterns. For deeper analysis, follow the workflows below.

Testing the scripts
bash
python scripts/scan_project.py /path/to/some/project --format text
python scripts/scan_secrets.py /path/to/some/project --format text

Audit Workflow

1. Reconnaissance

Before auditing, understand the project:

bash
# Identify languages, frameworks, and entry points
find . -type f -name "*.py" -o -name "*.js" -o -name "*.ts" -o -name "*.go" -o -name "*.java" | head -20
cat package.json pyproject.toml requirements.txt go.mod pom.xml 2>/dev/null

Key questions:

  • What frameworks are used? (Express, Django, Flask, Spring, etc.)
  • Where are the entry points? (routes, controllers, API handlers)
  • How is authentication handled?
  • What external services are called?
  • Is user input accepted? Where?
2. Secrets Detection

Scan for hardcoded credentials, API keys, and tokens. See references/secrets-patterns.md for the full pattern list.

bash
python scripts/scan_secrets.py /path/to/project

Common patterns to check:

  • API keys and tokens in source files
  • Database connection strings with embedded passwords
  • Private keys or certificates committed to the repo
  • .env files or config files with plaintext secrets
  • Secrets in CI/CD configuration files
3. Vulnerability Scanning
OWASP Top 10 Checklist
#CategoryWhat to Look For
A01Broken Access ControlMissing auth checks, IDOR, privilege escalation
A02Cryptographic FailuresWeak algorithms, plaintext storage, missing TLS
A03InjectionSQL, NoSQL, OS command, LDAP, XSS
A04Insecure DesignMissing rate limits, business logic flaws
A05Security MisconfigurationDebug mode, default credentials, verbose errors
A06Vulnerable ComponentsOutdated dependencies with known CVEs
A07Auth FailuresWeak passwords, missing MFA, session issues
A08Data Integrity FailuresInsecure deserialization, unsigned updates
A09Logging FailuresMissing audit logs, sensitive data in logs
A10SSRFUnvalidated URLs in server-side requests
Show full SKILL.md (152 more words)Show less
Language-Specific Checks

Python

python
# Dangerous: SQL injection
cursor.execute(f"SELECT * FROM users WHERE id = {user_id}")
# Safe: Parameterized query
cursor.execute("SELECT * FROM users WHERE id = %s", (user_id,))

# Dangerous: Command injection
os.system(f"ping {hostname}")
# Safe: Use subprocess with list args
subprocess.run(["ping", hostname], capture_output=True)

# Dangerous: Path traversal
open(f"/data/{user_input}")
# Safe: Validate and resolve path
path = pathlib.Path("/data") / user_input
path.resolve().relative_to(pathlib.Path("/data").resolve())

JavaScript/TypeScript

javascript
// Dangerous: XSS via innerHTML
element.innerHTML = userInput;
// Safe: Use textContent or sanitize
element.textContent = userInput;

// Dangerous: Prototype pollution
Object.assign(target, JSON.parse(userInput));
// Safe: Validate input structure
const parsed = JSON.parse(userInput);
if (typeof parsed !== 'object' || Array.isArray(parsed)) throw new Error();
const sanitized = Object.fromEntries(
  Object.entries(parsed).filter(([k]) => !k.startsWith('__'))
);

// Dangerous: eval or Function constructor
eval(userInput);
// Safe: Never use eval with user input

Go

go
// Dangerous: SQL injection
db.Query("SELECT * FROM users WHERE id = " + id)
// Safe: Parameterized query
db.Query("SELECT * FROM users WHERE id = $1", id)

// Dangerous: Path traversal
http.ServeFile(w, r, filepath.Join(baseDir, r.URL.Path))
// Safe: Clean and validate path
cleaned := filepath.Clean(r.URL.Path)
full := filepath.Join(baseDir, cleaned)
if !strings.HasPrefix(full, baseDir) { http.Error(...) }
4. Dependency Audit

Check for known vulnerabilities in project dependencies:

bash
# Python
pip audit
safety check -r requirements.txt

# Node.js
npm audit
npx auditjs ossi

# Go
govulncheck ./...

# General (if Trivy is available)
trivy fs --scanners vuln /path/to/project

Review the output and categorize by severity (critical, high, medium, low). Critical and high severity findings should be addressed before deployment.

5. Configuration Review

Check for insecure defaults in configuration files:

yaml
# Common misconfigurations to flag:
DEBUG: true                    # Debug mode in production
ALLOWED_HOSTS: ["*"]          # Unrestricted host access
CORS_ALLOW_ALL_ORIGINS: true  # Open CORS policy
SECRET_KEY: "default"         # Default or weak secret key
SSL_VERIFY: false             # Disabled TLS verification

Check infrastructure configs:

  • Dockerfiles: Running as root, exposing unnecessary ports
  • CI/CD: Secrets in plaintext, overly permissive permissions
  • Cloud configs: Public S3 buckets, open security groups
6. Authentication and Authorization Review

Key areas to verify:

  • Password hashing uses strong algorithms (bcrypt, argon2, scrypt)
  • Sessions have appropriate timeouts and rotation
  • JWT tokens are validated properly (algorithm, expiry, signature)
  • API endpoints enforce authorization checks
  • Role-based access control is consistently applied
  • Rate limiting is in place for login and sensitive endpoints

Report Format

When generating a security audit report, use this structure:

markdown
# Security Audit Report

## Summary
- **Project**: [name]
- **Date**: [date]
- **Scope**: [what was audited]
- **Risk Level**: [Critical/High/Medium/Low]

## Findings

### [SEVERITY] Finding Title
- **Category**: [OWASP category]
- **Location**: [file:line]
- **Description**: [what the issue is]
- **Impact**: [what could happen if exploited]
- **Recommendation**: [how to fix]

## Statistics
- Total findings: [count]
- Critical: [count] | High: [count] | Medium: [count] | Low: [count]

Next Steps

  • For detailed vulnerability patterns and code examples, see references/vulnerability-patterns.md
  • For secrets detection regex patterns, see references/secrets-patterns.md

© eigent-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in resources/example-skills/skill-security-auditor of eigent-ai/eigent.

  • SKILL.md
  • LICENSE.txt
  • references/secrets-patterns.md
  • references/vulnerability-patterns.md
  • scripts/scan_project.py
  • scripts/scan_secrets.py

Open the folder on GitHubat commit 9c76fba

Compare with similar skills

Security Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Auditor this skilleigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Cyber NeoHainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT
Sast BanditAgentSecOps/SecOpsAgentKit2201 repos~2.6kAutomated safety check: PassCustom licence
Security AuditHouseofmvps/ultraship123—~3.9kAutomated safety check: NotesMIT
Senior Secopsborghei/Claude-Skills881—~1.7kAutomated safety check: PassMIT

Similar skills

  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    281 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Sast Bandit

    AgentSecOps/SecOpsAgentKit

    Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping.

    220 GitHub starsUsed in 1 repo~2.6k tokens
    SecurityAuto-check passed
  • Security Audit

    Houseofmvps/ultraship

    Run security audit — dependency vulnerabilities, secret scanning, OWASP pattern detection, HTTP headers.

    123 GitHub stars~3.9k tokensUpdated 3 mo ago
    SecurityAuto-check: notes
  • Senior Secops

    borghei/Claude-Skills

    SecOps for application security, vulnerability management, compliance, and secure development.

    881 GitHub stars~1.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    430 GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check: notes

Works with

Categories

Questions about Security Auditor

What does Security Auditor do?

Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist. py` against a project directory for a lightweight pass over hardcoded secrets, dangerous function calls and insecure patterns.py`, focuses on credentials, and both accept a text output format.

When should I use Security Auditor?

Security Auditor fits situations like: auditing a codebase for SQL injection, XSS or command injection; finding hardcoded API keys and credentials before a release; checking config files and dependencies for insecure defaults or known CVEs; producing a security report for a project.

How do I install Security Auditor in Claude Code?

Run `npx skills add eigent-ai/eigent --skill skill-security-auditor -a claude-code`. Or copy the skill folder (resources/example-skills/skill-security-auditor in eigent-ai/eigent) into .claude/skills/skill-security-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Security Auditor in Codex?

Run `npx skills add eigent-ai/eigent --skill skill-security-auditor -a codex`. Or copy the skill folder (resources/example-skills/skill-security-auditor in eigent-ai/eigent) into .agents/skills/skill-security-auditor in your project. Codex loads it when a task matches its description.

Can I use Security Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add eigent-ai/eigent --skill skill-security-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-security-auditor, .gemini/skills/skill-security-auditor, .github/skills/skill-security-auditor and .opencode/skills/skill-security-auditor in your project.

What does Security Auditor need to run?

Going by SKILL.md and its folder, Security Auditor needs Python for the scripts in its folder, the command-line tools its instructions call (python, pip, npm, npx and trivy) and credentials named SECRET_KEY. Our summary lists: Python, to run the scan scripts.

Does Security Auditor access the network?

SKILL.md contains no URLs. Its commands use pip, npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Auditor safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Auditor use?

Security Auditor is published under the Apache-2.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Auditor use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.9k tokens, read only when the agent opens those files.

What are the alternatives to Security Auditor?

Skills that share tags, products or a category with Security Auditor: Security Review (github/awesome-copilot, 40k stars), Cyber Neo (Hainrixz/cyber-neo, 281 stars), Sast Bandit (AgentSecOps/SecOpsAgentKit, 220 stars) and Security Audit (Houseofmvps/ultraship, 123 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Auditor?

eigent-ai (a GitHub organization) maintains it in eigent-ai/eigent, which has 15,469 GitHub stars. The repository was last updated on October 8, 2026.

Source: eigent-ai/eigent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.