Agent skill

Security Audit

by fossasia in fossasia/eventyay-interpretation

A skill your agent uses for security reviews of VoxBento code.

Apache-2.0Auto-check passedSecurity

Install Security Audit

skills CLI
$ npx skills add fossasia/eventyay-interpretation --skill security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install fossasia/eventyay-interpretation security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/fossasia/eventyay-interpretation.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-audit .claude/skills/security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-audit
GitHub stars
1.6k
Token cost
~1.3k tokens
SKILL.md length
483 words
Files
1
Skills in repo
38
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses for security reviews of VoxBento code.

  • Security reviews of VoxBento code
  • SKILL.md covers Threat Model, Security Checklist, Open Redirect Audit and Cookie Security Flags, plus 2 more sections
  • Needs SECRET_KEY and JWT_SECRET
  • Tasks that involve Security review

What it does

Security Audit is an agent skill from fossasia/eventyay-interpretation. Use this skill for security reviews of VoxBento code. Covers OWASP Top 10 and VoxBento-specific threat model.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review, Threat modeling and Web application vulnerabilities. The repository describes itself as: A plugin for live interpretation of video streams. The licence is Apache-2.0.

When your agent uses it

  • Security reviews of VoxBento code
  • Tasks that involve Security review
  • Tasks that involve Threat modeling

Example prompts

  • “/security-audit”

Requirements

  • Python 3
  • A credential in JWT_SECRET
  • A credential in SECRET_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 1ca0139. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SECRET_KEY
    • JWT_SECRET
    • API_KEY_ENCRYPTION_KEY
    • BOOTH_ACCESS_TOKEN
    • ADMIN_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Audit loads about 1.3k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 483 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from fossasia/eventyay-interpretation at commit 1ca0139, republished under its Apache-2.0 licence (© fossasia). 483 words, ~1,290 tokens.

Download SKILL.mdSave it as .claude/skills/security-audit/SKILL.md (or your agent's skills folder).
name
security-audit
description
Use this skill for security reviews of VoxBento code. Covers OWASP Top 10 and VoxBento-specific threat model.

Skill: Security Audit

Use this skill for security reviews of VoxBento code. Covers OWASP Top 10 and VoxBento-specific threat model.


Threat Model

ActorCapabilityRisk
Anonymous userReaches public routes (/, /register, /login, /healthz, /ws/captions/*)Low
Authenticated userJoins events they are assigned toLow
Malicious invite token holderUses token for different boothMitigated by WS scope check
Rogue interpreterTries to go live without being activeMitigated by _resolve_whip_url
Admin with accessFull event/user managementInherently trusted
Network attackerMITM on HTTP connectionsUse HTTPS/TLS in production

Security Checklist

A01 — Broken Access Control
  • All admin routes use Depends(require_admin).
  • require_admin checks user_token (is_admin or event_admin) then admin_token.
  • WHIP URL only returned to active interpreter (check_publish_permission in BoothRegistry).
  • WS booth:set-active: only coordinator or current active can reassign.
  • WS token scope: session_token.event_slug + language_code must match booth_id.
  • WS role: session.granted_role used — never data['role'].
  • Booth page: granted_role = None → 403 (not just redirect).
A02 — Cryptographic Failures
  • JWT_SECRET / SECRET_KEY are not default values in production.
  • API_KEY_ENCRYPTION_KEY is not "change-this-encryption-key-in-production" (raises RuntimeError if default).
  • API keys stored Fernet-encrypted in DB; never plaintext.
  • Passwords hashed with bcrypt (cost factor determined by bcrypt defaults ~12).
  • admin_password / jwt_secret not logged.
  • HTTPS enforced by reverse proxy (Caddyfile provided).
A03 — Injection
  • SQLAlchemy ORM with parameterized queries used throughout — no raw string SQL.
  • Event slug and language code validated by regex before DB write (validate_event_slug, validate_language_code).
  • Invite token is a 64-char hex string — no user-controlled content in PK.
  • Form input passed to template is escaped by Jinja2 autoescaping.
A05 — Security Misconfiguration
  • debug: bool = True in default settings — must be False in production.
  • BOOTH_ACCESS_TOKEN unset = no token guard on API; set it in production if API is public.
  • ADMIN_PASSWORD must be set; empty string disables admin login (see portal/routers/auth.py).
  • database_url default is SQLite — use PostgreSQL in production.
  • SECRET_KEY: str = 'change-me' — must be overridden.
Show full SKILL.md (184 more words)Show less
A07 — Identification and Authentication Failures
  • No rate limiting on /login or /register (see TD-08 in TECHNICAL_DEBT_REPORT.md).
  • user.is_active checked on login — deactivated users cannot log in.
  • JWT expiry is enforced (jwt_expiry_seconds default 86400 = 24h).
  • Cookie flags: httponly=True, samesite='lax' on all auth cookies.
  • No secure=True on cookies in code — must be added for HTTPS deployments or handled by reverse proxy.
A10 — Server-Side Request Forgery (SSRF)
  • _check_mediamtx() and _ensure_mediamtx_path() use settings.mediamtx_api_base — hardcoded from config, not user input.
  • Jitsi URL construction: _make_jitsi_url(base_url, room) — base_url is from settings; room is from DB (admin-entered, not end-user).
  • No user-controlled URLs are fetched by the server.

Open Redirect Audit

All redirects in portal/routers/ must use safe_redirect(url):

python
def safe_redirect(url: str, status_code: int) -> RedirectResponse:
    url = url.replace('\\', '').strip()
    parsed = urlparse(url)
    if url and not parsed.netloc and not parsed.scheme and url.startswith('/'):
        return RedirectResponse(url=url, status_code=status_code)
    return RedirectResponse(url='/', status_code=status_code)

Check next_url / next parameter usage:

bash
grep -rn "next_url\|next=" portal/routers/

Ensure all uses pass through safe_redirect.


Cookiehttponlysamesitesecure
session_token✓lax✗ (set by reverse proxy TLS)
user_token✓lax✗
admin_token✓lax✗

Production hardening: ensure TLS termination at Caddy/nginx level; add Strict-Transport-Security header.


Prompt Injection Detection

VoxBento does not directly pass user input to LLM APIs. Transcription providers receive audio (PCM bytes), not text, from the server. There is no LLM chain in the current implementation.


Security Quick Checks

bash
# Check for raw redirects (should be none)
grep -rn "RedirectResponse(url=" portal/routers/ | grep -v safe_redirect

# Check for debug=True in production settings
grep -n "debug" portal/config.py

# Check JWT secret default
grep -n "change-me\|secret_key" portal/config.py

# Check no inline scripts in templates
grep -rn "<script>" templates/

© fossasia, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/security-audit of fossasia/eventyay-interpretation.

Open the folder on GitHubat commit 1ca0139

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in fossasia/eventyay-interpretation, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Audit this skillfossasia/eventyay-interpretation1.6k—~1.3kAutomated safety check: PassApache-2.0
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
CybersecurityAgriciDaniel/claude-cybersecurity228—~11kAutomated safety check: WarnMIT
Securitygaragon/nanostack207—~3.7kAutomated safety check: NotesApache-2.0
Csono-session/pstack135—~12kAutomated safety check: NotesMIT
007sickn33/agentic-awesome-skills47k2 repos~410Automated safety check: PassMIT

Similar skills

  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Cybersecurity

    AgriciDaniel/claude-cybersecurity

    Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.

    228 GitHub stars~11k tokensUpdated 5 mo ago
    SecurityAuto-check: warnings
  • Security

    garagon/nanostack

    Use before shipping to production. An agent skill from garagon/nanostack.

    207 GitHub stars~3.7k tokensUpdated 28 days ago
    SecurityAuto-check: notes
  • Cso

    no-session/pstack

    Chief Security Officer mode. An agent skill from no-session/pstack.

    135 GitHub stars~12k tokensUpdated 6 mo ago
    SecurityAuto-check: notes
  • 007

    sickn33/agentic-awesome-skills

    Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

    47k GitHub starsUsed in 2 repos~410 tokens
    SecurityAuto-check passed
  • Security And Hardening

    dzhalaevd/Donatello

    Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.

    135 GitHub stars~5.1k tokensUpdated 5 days ago
    SecurityAuto-check: notes

More from fossasia/eventyay-interpretation

All 38 skills in this repo
  • Git Guardrails Claude Code

    fossasia/eventyay-interpretation

    Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute.

    1.6k GitHub starsUsed in 12 repos~578 tokens
    Auto-check passed
  • Diagnosing Bugs

    fossasia/eventyay-interpretation

    Diagnosis loop for hard bugs and performance regressions. An agent skill from fossasia/eventyay-interpretation.

    1.6k GitHub starsUsed in 32 repos~2.1k tokens
    Auto-check passed
  • Domain Modeling

    fossasia/eventyay-interpretation

    Build and sharpen a project's domain model. An agent skill from fossasia/eventyay-interpretation.

    1.6k GitHub starsUsed in 31 repos~821 tokens
    Auto-check passed
  • Improve

    fossasia/eventyay-interpretation

    Survey any codebase as a senior advisor and produce prioritized, self-contained implementation plans for OTHER models/agents to execute.

    1.6k GitHub starsUsed in 10 repos~3.7k tokens
    Auto-check: warnings
  • Migrate To Shoehorn

    fossasia/eventyay-interpretation

    Migrate test files from as type assertions to @total-typescript/shoehorn.

    1.6k GitHub starsUsed in 12 repos~698 tokens
    Auto-check passed
  • Setup Pre Commit

    fossasia/eventyay-interpretation

    Set up Husky pre-commit hooks with lint-staged (Prettier), type checking, and tests in the current repo.

    1.6k GitHub starsUsed in 12 repos~565 tokens
    Auto-check passed

Categories

Questions about Security Audit

What does Security Audit do?

A skill your agent uses for security reviews of VoxBento code. Security Audit is an agent skill from fossasia/eventyay-interpretation. Use this skill for security reviews of VoxBento code.

When should I use Security Audit?

Security Audit fits situations like: security reviews of VoxBento code; tasks that involve Security review; tasks that involve Threat modeling.

How do I install Security Audit in Claude Code?

Run `npx skills add fossasia/eventyay-interpretation --skill security-audit -a claude-code`. Or copy the skill folder (.agents/skills/security-audit in fossasia/eventyay-interpretation) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Security Audit in Codex?

Run `npx skills add fossasia/eventyay-interpretation --skill security-audit -a codex`. Or copy the skill folder (.agents/skills/security-audit in fossasia/eventyay-interpretation) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.

Can I use Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fossasia/eventyay-interpretation --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.

What does Security Audit need to run?

Going by SKILL.md and its folder, Security Audit needs credentials named SECRET_KEY, JWT_SECRET, API_KEY_ENCRYPTION_KEY and BOOTH_ACCESS_TOKEN. Our summary lists: Python 3; A credential in JWT_SECRET; A credential in SECRET_KEY.

Does Security Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Audit use?

Security Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Audit use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Audit?

Skills that share tags, products or a category with Security Audit: Security Audit Scanner (ruvnet/ruflo, 74k stars), Cybersecurity (AgriciDaniel/claude-cybersecurity, 228 stars), Security (garagon/nanostack, 207 stars) and Cso (no-session/pstack, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Audit?

fossasia (a GitHub organization) maintains it in fossasia/eventyay-interpretation, which has 1,551 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 5, 2026.

Source: fossasia/eventyay-interpretation on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.