Security Audit
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
Handle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.).
$ npx skills add hardisgroupcom/sfdx-hardis --skill fix-security-issue -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install hardisgroupcom/sfdx-hardis fix-security-issue --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/hardisgroupcom/sfdx-hardis.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/fix-security-issue .claude/skills/fix-security-issue && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fix-security-issue" agent skill from https://github.com/hardisgroupcom/sfdx-hardis/tree/main/.claude/skills/fix-security-issue into .claude/skills/fix-security-issue/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-security-issue", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/hardisgroupcom/sfdx-hardis/tree/main/.claude/skills/fix-security-issueType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add hardisgroupcom/sfdx-hardis --skill fix-security-issue -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install hardisgroupcom/sfdx-hardis fix-security-issue --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hardisgroupcom/sfdx-hardis.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/fix-security-issue .agents/skills/fix-security-issue && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fix-security-issue" agent skill from https://github.com/hardisgroupcom/sfdx-hardis/tree/main/.claude/skills/fix-security-issue into .agents/skills/fix-security-issue/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-security-issue", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hardisgroupcom/sfdx-hardis --skill fix-security-issue -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install hardisgroupcom/sfdx-hardis fix-security-issue --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hardisgroupcom/sfdx-hardis.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/fix-security-issue .cursor/skills/fix-security-issue && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fix-security-issue" agent skill from https://github.com/hardisgroupcom/sfdx-hardis/tree/main/.claude/skills/fix-security-issue into .cursor/skills/fix-security-issue/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-security-issue", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/hardisgroupcom/sfdx-hardis.git --path .claude/skills/fix-security-issue--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add hardisgroupcom/sfdx-hardis --skill fix-security-issue -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install hardisgroupcom/sfdx-hardis fix-security-issue --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hardisgroupcom/sfdx-hardis.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/fix-security-issue .gemini/skills/fix-security-issue && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fix-security-issue" agent skill from https://github.com/hardisgroupcom/sfdx-hardis/tree/main/.claude/skills/fix-security-issue into .gemini/skills/fix-security-issue/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-security-issue", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install hardisgroupcom/sfdx-hardis fix-security-issueInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add hardisgroupcom/sfdx-hardis --skill fix-security-issue -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/hardisgroupcom/sfdx-hardis.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/fix-security-issue .github/skills/fix-security-issue && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fix-security-issue" agent skill from https://github.com/hardisgroupcom/sfdx-hardis/tree/main/.claude/skills/fix-security-issue into .github/skills/fix-security-issue/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-security-issue", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hardisgroupcom/sfdx-hardis --skill fix-security-issue -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install hardisgroupcom/sfdx-hardis fix-security-issue --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hardisgroupcom/sfdx-hardis.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/fix-security-issue .opencode/skills/fix-security-issue && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fix-security-issue" agent skill from https://github.com/hardisgroupcom/sfdx-hardis/tree/main/.claude/skills/fix-security-issue into .opencode/skills/fix-security-issue/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-security-issue", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fix-security-issueHandle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.).
Fix Security Issue is an agent skill from hardisgroupcom/sfdx-hardis. Handle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.). Tries to upgrade first; ignores only when safe and justified.
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Vulnerability scanning and Linting and formatting. It works with Trivy, npm and Python. The repository describes itself as: French-army-knife Toolbox for Salesforce. Orchestrates base commands and assist users with interactive wizards to make much more than native Salesforce CLI + Allows you to define…. The licence is AGPL-3.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9625b22. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadGrepGlobEditWriteBashWebFetchWebSearchFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
uvmakeFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
avd.aquasec.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fix Security Issue loads about 1.3k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 650 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Grep, Glob, Edit, Write, Bash, WebFetch, WebSearchAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from hardisgroupcom/sfdx-hardis at commit 9625b22, republished under its AGPL-3.0 licence (© hardisgroupcom). 650 words, ~1,283 tokens.
.claude/skills/fix-security-issue/SKILL.md (or your agent's skills folder).Investigate and fix the security issue $ARGUMENTS reported by trivy, osv-scanner, or another security linter.
Browse the internet to gather full context:
https://avd.aquasec.com/nvd/<cve-id>)Find where the vulnerable package comes from:
stdlib): check which linter binary embeds it — the scan output names the file (e.g. usr/bin/actionlint). Find the linter's descriptor in megalinter/descriptors/ and its pinned version.pyproject.toml, uv.lock, .config/python/dev/requirements.txt, server/requirements.txt.npm: blocks containing the package name.Check whether a fixed version is available and reachable:
pyproject.toml / requirements files, then run uv lock --python 3.12 to regenerate uv.lock.ARG ..._VERSION= line in the descriptor, then run make megalinter-build.package.json lists a fixed transitive version.If an upgrade is possible and available: do it, then stop here. No ignore entry needed.
If no fixed version exists yet (latest release is still affected), analyze whether the vulnerability is exploitable in MegaLinter's context:
Ask:
Stop and warn the user if:
Add an exception only when the CVE is genuinely not exploitable in MegaLinter's context. Acceptable reasons:
crypto/tls in a tool that makes no TLS calls)cilium-bugtool) in a package imported only for its data types.trivyignore (for trivy findings)Append to the appropriate section (or create a new one):
# <linter/package>: <one-line explanation of why not exploitable in MegaLinter>
CVE-XXXX-XXXXXosv-scanner config (for osv-scanner findings)Check for an osv-scanner config file (e.g. .osv-scanner.toml or osv-scanner.toml) and add an ignore entry following its schema.
Always include:
<linter> releases a version compiled with Go X.Y.Z")Do not update CHANGELOG.md for:
If you made a real behavior change (e.g. a linter disabled due to a security incident, a config workaround added), add one line under Fixes in the beta section:
- Fix <linter/component>: <what changed and why, one sentence for users>© hardisgroupcom, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/fix-security-issue of hardisgroupcom/sfdx-hardis.
Open the folder on GitHubat commit 9625b22
Fix Security Issue next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fix Security Issue this skillhardisgroupcom/sfdx-hardis | 401 | — | ~1.3k | Automated safety check: Notes | AGPL-3.0 | |
| Security AuditTheDecipherist/claude-code-mastery | 550 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Upgrade Java Depsnvuillam/npm-groovy-lint | 248 | — | ~1.9k | Automated safety check: Notes | MIT | |
| npm Supply Chain Checkmajiayu000/spellbook | 286 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Sca TrivyAgentSecOps/SecOpsAgentKit | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Custom licence | |
| Tracing Transitive Vulnerabilitiesjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~2.2k | Automated safety check: Notes | MIT |
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
nvuillam/npm-groovy-lint
Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…
majiayu000/spellbook
Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
jeremylongshore/tons-of-skills-marketplace
Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies.
jwynia/agent-skills
Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.
hardisgroupcom/sfdx-hardis
Walks the sfdx-hardis training course end to end as a learner would, against a real Developer Edition org and fork, fixing broken steps and screenshots that no longer match.
hardisgroupcom/sfdx-hardis
Runs a full end-to-end test of sfdx-hardis promotion branches and backpromote against real Salesforce orgs and a throwaway repository, then writes a report.
hardisgroupcom/sfdx-hardis
Explains how the sfdx-hardis Salesforce CLI plugin is built: its TypeScript and Oclif stack, command layout, agent-mode flag and provider classes for git, notifications and AI.
hardisgroupcom/sfdx-hardis
Style rules for adding CHANGELOG.md entries: short, user-facing bullets grouped by command under the beta section, each linking the command's docs page.
hardisgroupcom/sfdx-hardis
Documentation standards for sfdx-hardis commands (description format with Command Behavior and Technical explanations sections, MkDocs site, build:doc).
hardisgroupcom/sfdx-hardis
Decision framework for fixing jscpd (copy-paste detector) errors.
Categories
Handle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.). Fix Security Issue is an agent skill from hardisgroupcom/sfdx-hardis.).
Fix Security Issue fits situations like: tasks that involve Vulnerability scanning; tasks that involve Linting and formatting.
Run `npx skills add hardisgroupcom/sfdx-hardis --skill fix-security-issue -a claude-code`. Or copy the skill folder (.claude/skills/fix-security-issue in hardisgroupcom/sfdx-hardis) into .claude/skills/fix-security-issue in your project. Claude Code loads it when a task matches its description.
Run `npx skills add hardisgroupcom/sfdx-hardis --skill fix-security-issue -a codex`. Or copy the skill folder (.claude/skills/fix-security-issue in hardisgroupcom/sfdx-hardis) into .agents/skills/fix-security-issue in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hardisgroupcom/sfdx-hardis --skill fix-security-issue -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fix-security-issue, .gemini/skills/fix-security-issue, .github/skills/fix-security-issue and .opencode/skills/fix-security-issue in your project.
Going by SKILL.md and its folder, Fix Security Issue needs the command-line tools its instructions call (uv and make). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Grep, Glob, Edit, Write, Bash, WebFetch, WebSearch.
SKILL.md names 1 domain. In commands or code: avd.aquasec.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Fix Security Issue is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Fix Security Issue: Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Upgrade Java Deps (nvuillam/npm-groovy-lint, 248 stars), npm Supply Chain Check (majiayu000/spellbook, 286 stars) and Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
hardisgroupcom (a GitHub organization) maintains it in hardisgroupcom/sfdx-hardis, which has 401 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 8, 2026.
Source: hardisgroupcom/sfdx-hardis on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.