Agent skill

Audit Scope

by forefy in forefy/.context

Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.

MITAuto-check passedSecurity

Install Audit Scope

skills CLI
$ npx skills add forefy/.context --skill audit-scope -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forefy/.context audit-scope --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunter-utils/audit-scope .claude/skills/audit-scope && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-scope
GitHub stars
152
Token cost
~2.3k tokens
SKILL.md length
1,198 words
Files
1
Skills in repo
20
Repo updated
First seen
Licence
MIT

At a glance

Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.

  • Works in 7 steps: Ingest repos → Explore repo structure → Identify discounts → …
  • Scoping a new engagement
  • SKILL.md covers Inputs, Constants (hardcoded, never…, Step-by-step execution and Example output shape, plus 2 more sections
  • Calls gh

What it does

Audit Scope is an agent skill from forefy/.context. Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table. Use when scoping a new engagement.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review. It works with GitHub. The repository describes itself as: AI Agent Skills, Goals and Dynamic Workflows for Security Auditing, Pentesting and Research. The licence is MIT.

When your agent uses it

  • Scoping a new engagement
  • Tasks that involve Security review

Example prompts

  • “/audit-scope”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Ingest repos
  2. Explore repo structure
  3. Identify discounts
  4. Estimate days per component
  5. Build narrative (3 lines, before table)
  6. Build scope table
  7. Output

What it can do on your machine

Read from SKILL.md and the folder at commit c8ff161. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Scope loads about 2.3k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 1,198 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from forefy/.context at commit c8ff161, republished under its MIT licence (© forefy). 1,198 words, ~2,286 tokens.

Download SKILL.mdSave it as .claude/skills/audit-scope/SKILL.md (or your agent's skills folder).
name
audit-scope
description
Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table. Use when scoping a new engagement.

Audit Scope Skill

Inputs

User provides one or more of:

  • GitHub repo URL(s)
  • API documentation / access description (no repo)
  • Named scope components (e.g. "also include the webhook service")

No report-days input needed - report writing is hardcoded (see Constants).

Constants (hardcoded, never ask user)

  • Report writing: always 1 day

Scope is measured in days. Do not attach monetary amounts to the output - days are the unit of measurement here.

Step-by-step execution

1. Ingest repos

For each GitHub repo URL provided:

  • Clone to /tmp/<repo-name>-audit via gh repo clone
  • Run cloc <repo> --quiet --not-match-f="(?i)(spec|test)" --not-match-d="(test|spec|__tests__|__mocks__)" --include-lang=TypeScript,JavaScript,Kotlin,Java,Go,Python,Rust,Solidity,HCL (exclude test/spec files and dirs, case-insensitive; adjust --include-lang for the repo's stack)
  • Record NSLOC per repo (source lines only - exclude test/spec files, Markdown, YAML, Gradle, shell)
  • Never estimate NSLOC manually - always run cloc

For API-only scope (no repo):

  • NSLOC = N/A
  • Estimate days from endpoint count and complexity description
2. Explore repo structure

Read enough to understand:

  • What the component does (SDK? API server? webhook handler?)
  • Core tech: cryptographic primitives, auth mechanisms, external dependencies
  • Language-specific security surface (JVM, Node, etc.)
  • Key files: entry point, signing/crypto logic, error handling, config/env
3. Identify discounts

Apply these automatically - do not ask user:

ConditionDiscount
Multiple repos audited back-to-back (streak)-0.5d lift-off discount
Multiple repos share same domain/features (similarity)-20-35% off affected component's days
Spec/rules doc in scope alongside backend that implements it-1-2d off backend (domain fluency pre-built)

Lift-off discount = negative row in table (streak saves ramp time). Similarity discount = bidirectional - applies whenever two components share significant overlapping attack surface, regardless of order. E.g. SDKs and backend sharing the same signing/API domain discount each other: SDKs get discounted because backend covers the server-side of the same flow; backend gets discounted because SDK work already mapped the signing trust boundary. Bake into the component day estimate directly (no separate row).

4. Estimate days per component

Base pace: ~300-400 NSLOC/day for deep manual security audit. Adjust for:

  • Cryptographic code: slower (~200 NSLOC/day)
  • Boilerplate-heavy languages (Kotlin, Java): filter ~30% noise
  • Framework-heavy TS backends (NestJS, etc.): DTOs, decorators, module definitions don't need line-by-line audit - pace ~400-500 NSLOC/day for those layers
  • Narrow attack surface (signer-only, no HTTP): faster
  • Wide attack surface (HTTP API, DB, auth): slower

Do not pace all NSLOC uniformly. First split the repo into trust-boundary vs non-audited code, then only price the trust boundary at audit depth. Raw cloc NSLOC != auditable NSLOC. This is the #1 source of overquoting - especially on web frontends, where most lines are presentational or read-only.

  • Excluded entirely (not in NSLOC, not priced): presentational React/Vue UI, charts, visualizers, layout/page JSX, styles, assets. These have no trust boundary. On a frontend this is often 60-80% of cloc's count.
  • Skim only (~0.5d flat, not per-NSLOC): read-only data-fetch and display logic - react-query hooks that fetch stats, *Stats mappers, APY/TVL math that only feeds charts, zustand stores, config/utils. Skim for leaked secrets, injection into outbound requests, and any value that feeds transaction sizing - then move on. Do NOT read line-by-line.
  • Full audit depth: the actual trust boundary - transaction/instruction construction, signing & approval flow, output/slippage guards, auth, proxy/SSRF surface, input validation on server routes. This is usually a minority of the lines but where all the findings are.

Contract/SDK out of scope -> frontend crypto pace is faster, not slower. If the on-chain program or signing SDK lives in a separate repo (imported dependency, not vendored), the frontend only orchestrates pre-built instructions. Don't apply the ~200 NSLOC/day crypto pace to it - the frontend can only validate at the guard layer, so those passes are firm but quick. Flag the separate contract/SDK repo as its own potential line item (that's where fund-safety bugs actually live).

4b. Sanity-check against common scope sizes

Before finalizing days, compare against typical engagement sizes below. These are calibration anchors - if a NSLOC-derived estimate lands well outside the range for its type, re-check the tiering in step 4 (usually display/read-only code priced at audit depth).

Engagement typeTypical days
Red team engagement~10-25
Security tool development services~15-20
Cloud misconfiguration review~8-12
Secure code review~10
Low-level secure code review~10
Web app penetration test~5-8
Android app pentest~5
SDK secure code review~3-5
Miniapp with lean backend~3-4
Incident response~2-5
2-day custom training (build time)~20

Web/frontend protocol audits track the "web app pentest" row (5-8d), not "secure code review" (~10d), unless the frontend vendors its own contracts/signing code.

Show full SKILL.md (479 more words)Show less
5. Build narrative (3 lines, before table)

Line 1 - Protocol mission + why audit needed: <Protocol name> is a <what it does>. <Scope components> are/is <role in system> - <why a flaw here = business impact>, making it <risk framing for the engagement>.

Scope components must be woven into this line with clear business justification for auditing them.

Line 2 - User story: A <user type> <does X> - <SDK/component> <does Y> and <delivers Z to downstream system>.

Line 3 - Attacker story + incentives: Attacker targets <attack surface> to <attack goal> - enabling <business-critical impact e.g. fund theft, unauthorized access, data breach>.

6. Build scope table

Columns: Component | NSLOC | Focus Areas | Days

Row order:

  1. One row per auditable component (repo or API surface)
  2. Lift-off discount row (if streak): Lift-off discount (streak) | - | - | -0.5
  3. Similarity discount already baked into component days (no separate row)
  4. Report writing row: Report writing | - | - | 1
  5. Total row: sum all days

Focus areas per component:

  • Name the specific crypto primitives, key-handling patterns, auth mechanisms, serialization paths, and language-specific risks
  • 4-6 items, comma-separated
7. Output

Print narrative (3 lines), blank line, then table. Nothing else.

Example output shape

Protocol: Acme is a payments infrastructure API enabling businesses to move digital assets across chains. The SDKs (sdk-lang1, sdk-lang2) are the sole cryptographic trust boundary between a business's private keys and the Acme API - any signing flaw directly enables fund theft or unauthorized wallet creation, making them the highest-risk component in the integration stack.

User story: A fintech backend creates a wallet and signs a transaction step - the SDK constructs and stamps the activity payload locally, returning a signature the app posts to the Acme API.

Attacker story & incentives: Attacker targets the private key or signing flow to forge activity stamps - enabling unauthorized wallet creation or hijacking transactions to redirect funds to attacker-controlled addresses.


Expected output table example:

ComponentNSLOCFocus AreasDays
sdk-lang1 audit943P-256 stamp construction, key isolation, body serialization, input validation, logger redaction1.5
sdk-lang2 audit (similarity discount)1,764Signing parity with sdk-lang1, JVM key handling, coroutine error propagation, serialization safety2
Lift-off discount (streak)---0.5
Report writing--1
Total2,7074

Edge cases

  • Single repo, no streak: no lift-off row, no similarity discount
  • 3+ repos: apply lift-off once (-0.5d), apply similarity discount to each repo after the first
  • API-only scope: NSLOC = N/A, days from endpoint/complexity estimate, note estimation method
  • Mixed repo + API: repo gets cloc, API gets endpoint-based estimate; both in same table
  • Web/frontend repo: expect raw cloc to be dominated by presentational UI. Report NSLOC as the auditable surface (trust boundary + skim), not raw cloc, and say so. The trust boundary is: what the app builds & signs, output/slippage guards, wallet/session handling, and any server/proxy routes (SSRF, allowlists, rate-limit, secret exposure). A frontend audit is typically 4-6 days even at 20k+ raw NSLOC; if the estimate exceeds that, check whether display/read-only code got priced at audit depth.

© forefy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunter-utils/audit-scope of forefy/.context.

Open the folder on GitHubat commit c8ff161

Compare with similar skills

Audit Scope next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Scope compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Scope this skillforefy/.context152—~2.3kAutomated safety check: PassMIT
Agentic GitHub Actions Auditortrailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0
Codebase Audit Pre Pushsickn33/agentic-awesome-skills47k2 repos~2.1kAutomated safety check: NotesMIT
Security SecretsIgorWarzocha/Opencode-Workflows122—~1.2kAutomated safety check: NotesNone
Hunter 22aeonfun/aeon767—~1.7kAutomated safety check: PassMIT
Repo SentinelMathews-Tom/armory327—~2.2kAutomated safety check: PassMIT

Similar skills

  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.4k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • Codebase Audit Pre Push

    sickn33/agentic-awesome-skills

    Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues.

    47k GitHub starsUsed in 2 repos~2.1k tokens
    SecurityAuto-check: notes
  • Security Secrets

    IgorWarzocha/Opencode-Workflows

    Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.

    122 GitHub stars~1.2k tokensUpdated 8 mo ago
    SecurityAuto-check: notes
  • Hunter 22

    aeonfun/aeon

    Scan the ClawHunter agent bounty marketplace for opportunities that genuinely match this agent's real capabilities (code, security research, writing) and surface only real matches — never a raw…

    767 GitHub stars~1.7k tokensUpdated today
    SecurityAuto-check passed
  • Repo Sentinel

    Mathews-Tom/armory

    Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses.

    327 GitHub stars~2.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed

More from forefy/.context

All 20 skills in this repo
  • Builds and formats security audit reports in Google Docs through the Docs API, with fixes for index drift, code styling and cross-reference links.

    152 GitHub stars~951 tokensUpdated 2 days ago
    Auto-check passed
  • Audits the Safe multisig wallets of DeFi protocols for governance misconfigurations, scoring each against a finding library and producing a severity-ranked report.

    152 GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed
  • Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.

    152 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • External Enumeration

    forefy/.context

    Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.

    152 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    Auto-check passed
  • Infrastructure Audit

    forefy/.context

    Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations.

    152 GitHub stars~3.7k tokensUpdated 2 days ago
    Auto-check: notes

Works with

Categories

Questions about Audit Scope

What does Audit Scope do?

Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table. context. Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.

When should I use Audit Scope?

Audit Scope fits situations like: scoping a new engagement; tasks that involve Security review.

How do I install Audit Scope in Claude Code?

Run `npx skills add forefy/.context --skill audit-scope -a claude-code`. Or copy the skill folder (skills/hunter-utils/audit-scope in forefy/.context) into .claude/skills/audit-scope in your project. Claude Code loads it when a task matches its description.

How do I install Audit Scope in Codex?

Run `npx skills add forefy/.context --skill audit-scope -a codex`. Or copy the skill folder (skills/hunter-utils/audit-scope in forefy/.context) into .agents/skills/audit-scope in your project. Codex loads it when a task matches its description.

Can I use Audit Scope in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forefy/.context --skill audit-scope -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-scope, .gemini/skills/audit-scope, .github/skills/audit-scope and .opencode/skills/audit-scope in your project.

What does Audit Scope need to run?

Going by SKILL.md and its folder, Audit Scope needs the command-line tools its instructions call (gh).

Does Audit Scope access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Audit Scope safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Scope use?

Audit Scope is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Scope use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Scope?

Skills that share tags, products or a category with Audit Scope: Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars), Codebase Audit Pre Push (sickn33/agentic-awesome-skills, 47k stars), Security Secrets (IgorWarzocha/Opencode-Workflows, 122 stars) and Hunter 22 (aeonfun/aeon, 767 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Scope?

forefy (a GitHub user) maintains it in forefy/.context, which has 152 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 4, 2026.

Source: forefy/.context on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.