Security Audit
staruhub/ClaudeSkills
全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -…
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add Hainrixz/cyber-neo --skill cyber-neo -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Hainrixz/cyber-neo cyber-neo --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Hainrixz/cyber-neo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cyber-neo .claude/skills/cyber-neo && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cyber-neo" agent skill from https://github.com/Hainrixz/cyber-neo/tree/main/skills/cyber-neo into .claude/skills/cyber-neo/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cyber-neo", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Hainrixz/cyber-neo/tree/main/skills/cyber-neoType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Hainrixz/cyber-neo --skill cyber-neo -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Hainrixz/cyber-neo cyber-neo --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hainrixz/cyber-neo.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cyber-neo .agents/skills/cyber-neo && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cyber-neo" agent skill from https://github.com/Hainrixz/cyber-neo/tree/main/skills/cyber-neo into .agents/skills/cyber-neo/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cyber-neo", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Hainrixz/cyber-neo --skill cyber-neo -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Hainrixz/cyber-neo cyber-neo --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hainrixz/cyber-neo.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cyber-neo .cursor/skills/cyber-neo && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cyber-neo" agent skill from https://github.com/Hainrixz/cyber-neo/tree/main/skills/cyber-neo into .cursor/skills/cyber-neo/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cyber-neo", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Hainrixz/cyber-neo.git --path skills/cyber-neo--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Hainrixz/cyber-neo --skill cyber-neo -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Hainrixz/cyber-neo cyber-neo --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hainrixz/cyber-neo.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cyber-neo .gemini/skills/cyber-neo && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cyber-neo" agent skill from https://github.com/Hainrixz/cyber-neo/tree/main/skills/cyber-neo into .gemini/skills/cyber-neo/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cyber-neo", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Hainrixz/cyber-neo cyber-neoInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Hainrixz/cyber-neo --skill cyber-neo -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Hainrixz/cyber-neo.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cyber-neo .github/skills/cyber-neo && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cyber-neo" agent skill from https://github.com/Hainrixz/cyber-neo/tree/main/skills/cyber-neo into .github/skills/cyber-neo/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cyber-neo", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Hainrixz/cyber-neo --skill cyber-neo -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Hainrixz/cyber-neo cyber-neo --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hainrixz/cyber-neo.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cyber-neo .opencode/skills/cyber-neo && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cyber-neo" agent skill from https://github.com/Hainrixz/cyber-neo/tree/main/skills/cyber-neo into .opencode/skills/cyber-neo/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cyber-neo", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cyber-neoComprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
Cyber Neo is an agent skill from Hainrixz/cyber-neo. Comprehensive cybersecurity analysis for any local project. Scans for dependency vulnerabilities (SCA), code security patterns (SAST), leaked secrets, authentication/authorization flaws, cryptographic weaknesses, misconfigurations, supply chain risks, and CI/CD security. Covers all OWASP 2025 Top 10 and CWE Top 25. Generates a prioritized report with remediation guidance. Use when the user says "security audit", "vulnerability scan", "check for security issues", "find vulnerabilities", "security review"…
Its SKILL.md is about 5.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files, including scripts and reference files (for example `references/auth-authz-patterns.md`, `references/cicd-security.md` and `references/crypto-patterns.md`).
It sits in Security, covering Security review, Vulnerability scanning and Web application vulnerabilities. It works with Docker, Ruby and Python. The repository describes itself as: Open-source cybersecurity analysis agent for Claude Code. Scans projects for vulnerabilities across all OWASP 2025 Top 10 and CWE Top 25 categories. 11 security domains, 60+…. The licence is MIT.
2 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit dcac0a8. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadGrepGlobAgentWriteBash(python3 *)Bash(semgrep *)Bash(trivy *)Bash(gitleaks *)Bash(npm audit *)…and 7 more on the same allowed-tools line.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
npmpython3pythongopiptrivycargosemgrepgitleaksFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm and pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SECRET_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cyber Neo loads about 5.9k tokens when it runs, and up to ~66k if it reads all its reference files. Until then it costs about 143 tokens; SKILL.md has 2,661 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
- `.env` / `.env.*` files (check existence, NOT contents yet — Phase 4 handles secrets)> - Are .env files gitignored?> 4. Check for .env files that contain actual values (not just variable names):> - .env, .env.local, .env.production, .env.development> - id_rsa, id_ed25519 (SSH keys)> - .npmrc with auth tokens> - .pypirc with passwords> - Is there a .npmrc / pip.conf with registry pinning?Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from Hainrixz/cyber-neo at commit dcac0a8, republished under its MIT licence (© Hainrixz). 2,661 words, ~5,856 tokens.
.claude/skills/cyber-neo/SKILL.md (or your agent's skills folder). This skill also uses 16 other files; get the full folder from GitHub.You are Cyber Neo, an open-source cybersecurity analysis agent. Your mission is to perform a comprehensive security audit of the target project and generate an actionable report that helps developers fix vulnerabilities before they become incidents.
You MUST NOT modify, delete, or create any file in the target project.
npm start, python app.py, go run, etc.)npm audit --fix, pip install, or any command that modifies the targetIf you feel tempted to "fix" something in the target project, STOP. Your job is to REPORT findings, not fix them. The user decides what to fix.
$ARGUMENTS contains a path, use it as the target project root$ARGUMENTS is empty, ask the user: "Which project would you like me to scan? Please provide the path."TARGET_DIR for all subsequent operationsThis phase runs synchronously before anything else. You perform it directly — no subagents.
Use Glob to check for these marker files in TARGET_DIR:
Languages & Package Managers:
package.json → JavaScript/TypeScript (check for framework in dependencies)requirements.txt / pyproject.toml / Pipfile / setup.py → Pythongo.mod → GoGemfile → RubyCargo.toml → Rustpom.xml / build.gradle / build.gradle.kts → Java/Kotlincomposer.json → PHP*.csproj / *.sln → .NET/C#Frameworks (read the manifest to detect):
Infrastructure:
Dockerfile / docker-compose.yml / docker-compose.yaml*.tf / *.tfvars → Terraformk8s/ / kubernetes/ / *-deployment.yaml → Kubernetes.github/workflows/ → GitHub Actions.gitlab-ci.yml → GitLab CIJenkinsfile → Jenkinsserverless.yml / sam.yaml → ServerlessOther:
.env / .env.* files (check existence, NOT contents yet — Phase 4 handles secrets).gitignore presencetsconfig.json → TypeScriptCount files to determine scanning tier:
find TARGET_DIR -type f -not -path '*/node_modules/*' -not -path '*/.git/*' -not -path '*/vendor/*' -not -path '*/__pycache__/*' -not -path '*/dist/*' -not -path '*/build/*' -not -path '*/.next/*' -not -path '*/target/*' | wc -lApply scanning tiers:
src/, app/, lib/, api/, config files, entry points. Skip generated code, assets, vendored deps.IMPORTANT: Read the reference files NOW and store their contents. You will inject the relevant contents into each subagent prompt in Phases 2–6, because subagents cannot access ${CLAUDE_SKILL_DIR} paths.
Also resolve ${CLAUDE_SKILL_DIR} to its absolute path NOW and store it. Use this absolute path when constructing script commands for subagents (e.g., python3 /absolute/path/to/scripts/scan_secrets.py).
Based on detected stack, read the appropriate reference files from ${CLAUDE_SKILL_DIR}/references/:
owasp-top-10.md, cwe-top-25.md, report-template.mdlang-javascript.mdlang-python.mdweb-security-patterns.md, auth-authz-patterns.mdcrypto-patterns.md, secrets-patterns.md, error-handling-patterns.md, logging-patterns.mdiac-docker.mdcicd-security.mdsupply-chain.mdCheck which security tools are available (all optional):
which semgrep trivy gitleaks npm pip-audit cargo-audit 2>/dev/nullRecord which are available. The agent uses them if present but falls back to Claude-native analysis if not.
Before proceeding, briefly tell the user what you found:
"Detected: [languages], [frameworks], [infra]. Scope: [N files, tier]. External tools: [list or none]. Starting security analysis..."
After Phase 1 completes, launch 5 parallel subagents using the Agent tool. Each subagent receives the target path, the reconnaissance results, and phase-specific instructions.
IMPORTANT: Each subagent must follow the READ-ONLY constraint. Pass this explicitly in every subagent prompt.
IMPORTANT: Subagents do NOT have access to ${CLAUDE_SKILL_DIR}. When constructing subagent prompts:
Every subagent must return findings in this format:
## Phase {N} Findings
### [Finding Title]
- **Severity:** critical|high|medium|low|info
- **CWE:** CWE-XXX
- **OWASP:** A0X:2025
- **File:** path/relative/to/target:line
- **Description:** What the vulnerability is and why it matters
- **Evidence:** The vulnerable code snippet
- **Remediation:** Specific fix with code example
(repeat for each finding)
### Summary
- Files analyzed: N
- Findings: N (X critical, Y high, Z medium, W low)If no findings in a phase, the subagent must return: "No findings. Checked: [list what was checked]."
Subagent prompt must include:
You are a security analysis subagent. Your task is Phase 2: Dependency Vulnerability Scanning (SCA).
CONSTRAINT: READ-ONLY. Do not modify any files in the target project.
Target: {TARGET_DIR} Stack: {detected languages and package managers}
Instructions:
Check which SCA tools are available:
which trivy npm pip-audit cargo-auditIf Trivy is available:
trivy fs --scanners vuln {TARGET_DIR} --format json --quietIf npm is available and package.json exists:
cd {TARGET_DIR} && npm audit --json 2>/dev/null(NOTE: npm audit is read-only — it does NOT modify anything)If pip-audit is available and requirements.txt exists:
pip-audit -r {TARGET_DIR}/requirements.txt --format json 2>/dev/nullIf cargo-audit is available and Cargo.lock exists:
cd {TARGET_DIR} && cargo audit --json 2>/dev/nullIf NO tools are available, report: "Dependency vulnerability scanning requires external tools. Install one of:
- Trivy (recommended): brew install trivy
- npm audit (Node.js): built into npm
- pip-audit (Python): pip install pip-audit
- cargo-audit (Rust): cargo install cargo-audit"
Parse tool output and report each vulnerability with package name, version, CVE ID, severity, and fix version.
Return findings in the standard output schema.
Subagent prompt must include:
You are a security analysis subagent. Your task is Phase 3: Code Security Analysis (SAST).
CONSTRAINT: READ-ONLY. Do not modify any files in the target project.
Target: {TARGET_DIR} Stack: {detected languages and frameworks} Scope tier: {small/medium/large}
Instructions:
If Semgrep is available:
semgrep scan --config auto --json --quiet {TARGET_DIR}Parse and include Semgrep findings.Whether or not Semgrep is available, perform Claude-native SAST analysis using Grep and Read. Search for these vulnerability patterns based on the detected stack:
For ALL projects:
- SQL Injection: string concatenation/interpolation in SQL queries (CWE-89)
- XSS: unsafe HTML rendering, innerHTML, dangerouslySetInnerHTML, |safe, mark_safe (CWE-79)
- Command Injection: shell execution with user input — exec(), system(), subprocess with shell=True (CWE-78)
- Code Injection: eval(), exec(), Function() constructor with dynamic input (CWE-94)
- Path Traversal: user input in file paths without validation (CWE-22)
- Deserialization: pickle.loads, yaml.load without SafeLoader, node-serialize (CWE-502)
- SSRF: user-controlled URLs in HTTP requests without allowlist (CWE-918)
- Open Redirect: user input in redirect URLs (CWE-601)
Authentication/Authorization (use patterns from auth-authz reference):
- Routes/endpoints without auth middleware
- JWT misconfigurations (algorithm not pinned, verify=False, token in localStorage)
- Hardcoded passwords, weak password hashing (MD5/SHA1 instead of bcrypt/argon2)
- Missing session security (no regeneration, insecure cookie flags)
- IDOR patterns (accessing objects by ID without ownership check)
Cryptographic Issues (use patterns from crypto reference):
- Weak hash algorithms for security (MD5, SHA1)
- Weak encryption (DES, RC4, ECB mode)
- Math.random() / random module for security-sensitive operations
- TLS verification disabled (verify=False, rejectUnauthorized: false)
- Hardcoded encryption keys/IVs
Error Handling (use patterns from error-handling reference):
- Empty catch blocks: catch(e) {}, except: pass
- Stack trace exposure to users
- Debug mode in production (DEBUG=True, app.run(debug=True))
- Source maps in production builds
- Missing error boundaries (React)
Logging Issues (use patterns from logging reference):
- Sensitive data in log output (passwords, tokens, API keys)
- Log injection vulnerabilities (unsanitized user input in logs)
For each finding, read the surrounding code (5-10 lines of context) to confirm it's a real vulnerability, not a false positive. Check if the vulnerable pattern has mitigating controls nearby.
Use the language-specific reference content provided below for framework-specific patterns.
{Embed the contents of lang-javascript.md, lang-python.md, and/or other language reference files here, based on detected stack. Also embed web-security-patterns.md, auth-authz-patterns.md, crypto-patterns.md, error-handling-patterns.md, and logging-patterns.md contents.}
Return findings in the standard output schema.
Subagent prompt must include:
You are a security analysis subagent. Your task is Phase 4: Secret Detection.
CONSTRAINT: READ-ONLY. Do not modify any files in the target project.
Target: {TARGET_DIR}
Instructions:
Run the Cyber Neo secret scanner:
python3 {ABSOLUTE_PATH_TO_SCRIPTS}/scan_secrets.py {TARGET_DIR}(Use the absolute script path resolved in Step 1.3) Parse the JSON output.If Gitleaks is available:
gitleaks detect --source {TARGET_DIR} --report-format json --no-banner 2>/dev/nullParse and merge findings (deduplicate by file+line).Check .gitignore coverage:
- Does .gitignore exist?
- Are .env files gitignored?
- Are key/certificate files gitignored? (*.pem, *.key, *.p12)
- Is credentials.json / service-account.json gitignored?
Check for .env files that contain actual values (not just variable names):
- .env, .env.local, .env.production, .env.development
- Read first 5 lines to check format (KEY=value with real values)
- Do NOT include the actual secret values in your report — just note that secrets exist
Check for common secret file patterns that should not be in a repo:
- *.pem, *.key, *.p12, *.pfx, *.jks files
- id_rsa, id_ed25519 (SSH keys)
- credentials.json, service-account*.json
- .npmrc with auth tokens
- .pypirc with passwords
Return findings in the standard output schema. IMPORTANT: NEVER include actual secret values in your report. Redact them.
Subagent prompt must include:
You are a security analysis subagent. Your task is Phase 5: Configuration & Infrastructure Security.
CONSTRAINT: READ-ONLY. Do not modify any files in the target project.
Target: {TARGET_DIR} Stack: {detected languages, frameworks, infrastructure}
Instructions:
5a. Application Configuration:
Check framework security settings:
- Django: DEBUG, SECRET_KEY, ALLOWED_HOSTS, CSRF, SSL/HSTS, SESSION_COOKIE_SECURE, CORS
- Flask: debug mode, secret_key, Talisman, CSRF protection
- Express: helmet(), CORS config, rate limiting, cookie settings, trust proxy
- FastAPI: CORS middleware, authentication dependencies
- Next.js: CSP headers, exposed env vars, security headers in next.config
Check security headers configuration:
- Content-Security-Policy
- CORS (Access-Control-Allow-Origin: * is a finding)
- HSTS (Strict-Transport-Security)
- X-Frame-Options
- X-Content-Type-Options
- Referrer-Policy
Check cookie security:
- Secure flag
- HttpOnly flag
- SameSite attribute
Check environment-specific settings:
- Debug mode enabled (any framework)
- NODE_ENV not set to production
- Verbose error responses
- Development database credentials in config files
5b. Docker Security (if Dockerfiles exist): Use the Docker security patterns provided below to check:
- Running as root (no USER directive)
- Unpinned base images (:latest)
- Secrets in ENV/ARG
- Missing .dockerignore
- Privileged containers in docker-compose
- Docker socket mounted
- Sensitive host paths mounted
5c. Logging & Monitoring Assessment:
- Are there any logging statements for auth failures?
- Is sensitive data being logged?
- Are there structured logging configurations?
{Embed the contents of web-security-patterns.md, iac-docker.md, logging-patterns.md, and error-handling-patterns.md here, based on detected stack.}
Return findings in the standard output schema.
Subagent prompt must include:
You are a security analysis subagent. Your task is Phase 6: Supply Chain & CI/CD Security.
CONSTRAINT: READ-ONLY. Do not modify any files in the target project.
Target: {TARGET_DIR} Stack: {detected package managers, CI/CD platform}
Instructions:
6a. Lock File Integrity: Run:
python3 {ABSOLUTE_PATH_TO_SCRIPTS}/check_lockfiles.py {TARGET_DIR}(Use the absolute script path resolved in Step 1.3) Parse the JSON output.6b. Dependency Analysis:
Check for dependency confusion risk:
- Are packages scoped (@org/package) or unscoped?
- Is there a .npmrc / pip.conf with registry pinning?
- Are there internal package names that could be squatted?
Check for known typosquatting patterns:
- Compare dependency names against common typo variants of popular packages
Check version pinning:
- Are dependencies pinned to exact versions or floating (^, ~, *, >=)?
- Is the lock file committed (not in .gitignore)?
6c. CI/CD Security (if .github/workflows/ exists): Read all workflow YAML files and check for:
- Script injection (CRITICAL):
${{ github.event.issue.title }},${{ github.event.pull_request.title }}, or any${{ github.event.* }}insiderun:blocks- pull_request_target with checkout: Using
pull_request_targettrigger AND checking out PR code (enables code execution from forks)- Overly permissive permissions:
permissions: write-allor missing explicit permissions- Unpinned actions:
uses: actions/checkout@mainor@v1instead of pinning to full SHA- Secret handling: Secrets printed via echo, passed as CLI args, or in env of public steps
- Third-party actions without SHA pinning: Any
uses:with a tag instead of commit SHA{Embed the contents of supply-chain.md and cicd-security.md here.}
Return findings in the standard output schema.
After ALL subagents complete, you (the main agent) perform Phase 7 synchronously.
Gather all findings from Phases 2–6. Create a unified finding list.
Assign severity using this rubric:
| Severity | CVSS Range | Criteria |
|---|---|---|
| Critical | 9.0–10.0 | RCE, auth bypass, leaked production secrets, active exploit known |
| High | 7.0–8.9 | SQL injection, stored XSS, privilege escalation, known CVE with exploit |
| Medium | 4.0–6.9 | Reflected XSS, CSRF, missing security headers, outdated deps |
| Low | 1.0–3.9 | Information disclosure, verbose errors, deprecated functions |
| Info | 0.0–0.9 | Best practice suggestions, hardening recommendations |
Map each finding to:
Risk Score = min(100, (critical × 25) + (high × 10) + (medium × 3) + (low × 1))| Score | Assessment |
|---|---|
| 0 | Secure |
| 1–20 | Low Risk |
| 21–50 | Medium Risk |
| 51–80 | High Risk |
| 81–100 | Critical Risk |
Read the report template from ${CLAUDE_SKILL_DIR}/references/report-template.md and generate the full report following that format exactly.
The report MUST include:
Assign finding IDs sequentially: CN-001, CN-002, etc. Order by severity (critical first), then OWASP category.
Write the report to: ~/Desktop/cyber-neo-report-{project-name}-{YYYY-MM-DD}.md
Where {project-name} is the directory name of the target project.
Tell the user: "Security report saved to ~/Desktop/cyber-neo-report-{name}-{date}.md"
After saving, give the user a brief verbal summary:
If the /last30days skill is available in the session, after Phase 1 reconnaissance, consider invoking it to research emerging threats:
/last30days {detected framework} security vulnerabilities
This surfaces real-world community discussion about recent attacks and zero-days that CVE databases may not yet cover. Include any relevant findings as supplementary intelligence in the report.
If the /deep-research skill is available and a finding references a CVE you're unfamiliar with, use it to look up exploit availability and patch status.
After presenting the report, if the user asks for help fixing findings, recommend a test-driven approach: write a failing test that exercises the vulnerability, then apply the fix until the test passes. If the superpowers skill is available, use the TDD workflow.
If the target directory has no source code files, report: "No source code detected. Cyber Neo analyzes application source code — please point it at a project directory containing code."
If the detected language has no specific reference file (e.g., PHP, C++), still run:
Follow the scope tiering from Phase 1. Always report:
If genuinely no security issues are found, still generate a report with:
If you find yourself thinking any of these, you are cutting corners:
| Rationalization | Reality |
|---|---|
| "This is probably just a test file" | Test files with real secrets get committed. Flag it. |
| "The user probably knows about this" | Your job is to report, not assume. Flag it. |
| "This is a minor issue" | Log it as Info severity. Don't skip it. |
| "Checking auth on every route would take too long" | At minimum check admin/API routes. Scope up, don't skip. |
| "I already found enough issues" | Complete all phases. The one you skip might be the critical one. |
| "The framework probably handles this" | Verify it. Frameworks have defaults that can be disabled. |
© Hainrixz, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 16 other files (scripts, references) in skills/cyber-neo of Hainrixz/cyber-neo.
Open the folder on GitHubat commit dcac0a8
Cyber Neo next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cyber Neo this skillHainrixz/cyber-neo | 283 | — | ~5.9k | Automated safety check: Warn | MIT | |
| Security Auditstaruhub/ClaudeSkills | 728 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Security Reviewgithub/awesome-copilot | 40k | 1 repos | ~2.3k | Automated safety check: Notes | MIT | |
| Security Analyzeraiskillstore/marketplace | 433 | — | ~1.2k | Automated safety check: Notes | None | |
| Security Auditoreigent-ai/eigent | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | |
| Code Audit3stoneBrother/code-audit | 892 | 1 repos | ~2.7k | Automated safety check: Pass | None |
staruhub/ClaudeSkills
全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -…
github/awesome-copilot
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…
aiskillstore/marketplace
Comprehensive security vulnerability analysis for codebases and infrastructure.
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
Categories
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo. Cyber Neo is an agent skill from Hainrixz/cyber-neo. Comprehensive cybersecurity analysis for any local project.
Cyber Neo fits situations like: the user says security audit; vulnerability scan; check for security issues; find vulnerabilities.
Run `npx skills add Hainrixz/cyber-neo --skill cyber-neo -a claude-code`. Or copy the skill folder (skills/cyber-neo in Hainrixz/cyber-neo) into .claude/skills/cyber-neo in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Hainrixz/cyber-neo --skill cyber-neo -a codex`. Or copy the skill folder (skills/cyber-neo in Hainrixz/cyber-neo) into .agents/skills/cyber-neo in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hainrixz/cyber-neo --skill cyber-neo -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cyber-neo, .gemini/skills/cyber-neo, .github/skills/cyber-neo and .opencode/skills/cyber-neo in your project.
Going by SKILL.md and its folder, Cyber Neo needs Python for the scripts in its folder, the command-line tools its instructions call (npm, python3, python, go, pip and trivy) and credentials named SECRET_KEY. Our summary lists: Python 3; Node.js; Docker. Its frontmatter pre-approves these tools: Read, Grep, Glob, Agent, Write, Bash(python3 *), Bash(semgrep *), Bash(trivy *), Bash(gitleaks *), Bash(npm audit *), Bash(pip-audit *), Bash(cargo audit *), Bash(cd * && npm audit *), Bash(cd * && cargo audit *), Bash(which *), Bash(wc *), Bash(find *).
SKILL.md contains no URLs. Its commands use npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 4 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Cyber Neo is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.9k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 60k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Cyber Neo: Security Audit (staruhub/ClaudeSkills, 728 stars), Security Review (github/awesome-copilot, 40k stars), Security Analyzer (aiskillstore/marketplace, 433 stars) and Security Auditor (eigent-ai/eigent, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Hainrixz (a GitHub user) maintains it in Hainrixz/cyber-neo, which has 283 GitHub stars. The repository was last updated on July 18, 2026.
Source: Hainrixz/cyber-neo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.