Agent skill

Audit Gitbook Integration

by GitbookIO in GitbookIO/integrations

Audit GitBook integrations for script injection, sensitive-data access, unsafe requests, authorization gaps, and manifest or dependency risk.

No licenceAuto-check passedSecurity

Install Audit Gitbook Integration

skills CLI
$ npx skills add GitbookIO/integrations --skill audit-gitbook-integration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install GitbookIO/integrations audit-gitbook-integration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/GitbookIO/integrations.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/audit-gitbook-integration .claude/skills/audit-gitbook-integration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-gitbook-integration
GitHub stars
131
Token cost
~1.2k tokens
SKILL.md length
616 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
None found

At a glance

Audit GitBook integrations for script injection, sensitive-data access, unsafe requests, authorization gaps, and manifest or dependency risk.

  • Works in 4 steps: Ask the user which integration to audit → Inspect the Integration → Provide a report → …
  • A requested integration security review
  • SKILL.md covers Context, Goal of this skill, Step 1: Ask the user which… and Step 2: Inspect the Integration, plus 2 more sections
  • Needs CLOUDFLARE_API_TOKEN

What it does

Audit Gitbook Integration is an agent skill from GitbookIO/integrations. Audit GitBook integrations for script injection, sensitive-data access, unsafe requests, authorization gaps, and manifest or dependency risk. Use for a requested integration security review, not routine feature work.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review. It works with TypeScript and Cloudflare. The repository describes itself as: Toolkit to build integrations on GitBook.

When your agent uses it

  • A requested integration security review
  • Not routine feature work

Example prompts

  • “/audit-gitbook-integration”

Requirements

  • A credential in CLOUDFLARE_API_TOKEN

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Ask the user which integration to audit
  2. Inspect the Integration
  3. Provide a report
  4. Provide an overall security score and maliciousness rating

What it can do on your machine

Read from SKILL.md and the folder at commit 8b5d669. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • gitbook.com
    • api.cloudflare.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CLOUDFLARE_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Gitbook Integration loads about 1.2k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 616 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 616 words (~1,214 tokens).

“GitBook is a platform for creating and publishing documentation sites. Integrations are installable extensions to a customer's documentation site and run in the Cloudflare Workers for Platform service. Integrations extend docs sites with outside tools, custom UI, and automated workflows.”

— opening of SKILL.md by GitbookIO
name
audit-gitbook-integration

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .agents/skills/audit-gitbook-integration of GitbookIO/integrations.

Open the folder on GitHubat commit 8b5d669

Compare with similar skills

Audit Gitbook Integration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Gitbook Integration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Gitbook Integration this skillGitbookIO/integrations131—~1.2kAutomated safety check: PassNone
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Myrqenstijnswapped/Myrqen137—~2.1kAutomated safety check: PassCustom licence
Security Audittheopenco/llmgateway1.7k—~1.8kAutomated safety check: PassCustom licence
Security Reviewdeadlock-mod-manager/deadlock-mod-manager574—~1.8kAutomated safety check: PassCC-BY-SA-4.0
Openai Security Best Practicestrailofbits/skills-curated5129 repos~2.2kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated today
    SecurityAuto-check: notes
  • Myrqen

    stijnswapped/Myrqen

    Run an authorized, local-first application security assessment on the current project using this agent's own reasoning.

    137 GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security Audit

    theopenco/llmgateway

    Security best practices, vulnerability review, and full security audits for LLM Gateway.

    1.7k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Security Review

    deadlock-mod-manager/deadlock-mod-manager

    Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.

    574 GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Openai Security Best Practices

    trailofbits/skills-curated

    Official

    Perform language and framework specific security best-practice reviews and suggest improvements.

    512 GitHub starsUsed in 9 repos~2.2k tokens
    SecurityAuto-check: notes
  • Security rules for eserstack in TypeScript and Go: secrets, output hygiene, input validation, authorization, injection, SSRF, error sanitization, httpfx hardening, tokens, passwords, cookies…

    128 GitHub stars~598 tokensUpdated 4 days ago
    SecurityAuto-check passed

Categories

Questions about Audit Gitbook Integration

What does Audit Gitbook Integration do?

Audit GitBook integrations for script injection, sensitive-data access, unsafe requests, authorization gaps, and manifest or dependency risk. Audit Gitbook Integration is an agent skill from GitbookIO/integrations. Audit GitBook integrations for script injection, sensitive-data access, unsafe requests, authorization gaps, and manifest or dependency risk.

When should I use Audit Gitbook Integration?

Audit Gitbook Integration fits situations like: A requested integration security review; not routine feature work.

How do I install Audit Gitbook Integration in Claude Code?

Run `npx skills add GitbookIO/integrations --skill audit-gitbook-integration -a claude-code`. Or copy the skill folder (.agents/skills/audit-gitbook-integration in GitbookIO/integrations) into .claude/skills/audit-gitbook-integration in your project. Claude Code loads it when a task matches its description.

How do I install Audit Gitbook Integration in Codex?

Run `npx skills add GitbookIO/integrations --skill audit-gitbook-integration -a codex`. Or copy the skill folder (.agents/skills/audit-gitbook-integration in GitbookIO/integrations) into .agents/skills/audit-gitbook-integration in your project. Codex loads it when a task matches its description.

Can I use Audit Gitbook Integration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add GitbookIO/integrations --skill audit-gitbook-integration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-gitbook-integration, .gemini/skills/audit-gitbook-integration, .github/skills/audit-gitbook-integration and .opencode/skills/audit-gitbook-integration in your project.

What does Audit Gitbook Integration need to run?

Going by SKILL.md and its folder, Audit Gitbook Integration needs credentials named CLOUDFLARE_API_TOKEN. Our summary lists: A credential in CLOUDFLARE_API_TOKEN.

Does Audit Gitbook Integration access the network?

SKILL.md names 2 domains. As links in the text: gitbook.com and api.cloudflare.com. This is read from the text; nothing was executed.

Is Audit Gitbook Integration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Gitbook Integration use?

No licence was found for Audit Gitbook Integration or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Audit Gitbook Integration use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Gitbook Integration?

Skills that share tags, products or a category with Audit Gitbook Integration: CodeQL Security Scan (trailofbits/skills, 7.4k stars), Myrqen (stijnswapped/Myrqen, 137 stars), Security Audit (theopenco/llmgateway, 1.7k stars) and Security Review (deadlock-mod-manager/deadlock-mod-manager, 574 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Gitbook Integration?

GitbookIO (a GitHub organization) maintains it in GitbookIO/integrations, which has 131 GitHub stars. The repository was last updated on October 7, 2026.

Source: GitbookIO/integrations on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.