Security Auditor
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
Run security audit — dependency vulnerabilities, secret scanning, OWASP pattern detection, HTTP headers.
$ npx skills add Houseofmvps/ultraship --skill security-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Houseofmvps/ultraship security-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Houseofmvps/ultraship.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-audit .claude/skills/security-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-audit" agent skill from https://github.com/Houseofmvps/ultraship/tree/main/skills/security-audit into .claude/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Houseofmvps/ultraship/tree/main/skills/security-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Houseofmvps/ultraship --skill security-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Houseofmvps/ultraship security-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Houseofmvps/ultraship.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security-audit .agents/skills/security-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-audit" agent skill from https://github.com/Houseofmvps/ultraship/tree/main/skills/security-audit into .agents/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Houseofmvps/ultraship --skill security-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Houseofmvps/ultraship security-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Houseofmvps/ultraship.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security-audit .cursor/skills/security-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-audit" agent skill from https://github.com/Houseofmvps/ultraship/tree/main/skills/security-audit into .cursor/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Houseofmvps/ultraship.git --path skills/security-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Houseofmvps/ultraship --skill security-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Houseofmvps/ultraship security-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Houseofmvps/ultraship.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security-audit .gemini/skills/security-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/Houseofmvps/ultraship/tree/main/skills/security-audit into .gemini/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Houseofmvps/ultraship security-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Houseofmvps/ultraship --skill security-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Houseofmvps/ultraship.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security-audit .github/skills/security-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/Houseofmvps/ultraship/tree/main/skills/security-audit into .github/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Houseofmvps/ultraship --skill security-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Houseofmvps/ultraship security-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Houseofmvps/ultraship.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security-audit .opencode/skills/security-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/Houseofmvps/ultraship/tree/main/skills/security-audit into .opencode/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-auditRun security audit — dependency vulnerabilities, secret scanning, OWASP pattern detection, HTTP headers.
Security Audit is an agent skill from Houseofmvps/ultraship. Run security audit — dependency vulnerabilities, secret scanning, OWASP pattern detection, HTTP headers. Use when user wants to harden their project.
Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security review, Secrets management and Web application vulnerabilities. It works with Supabase. The repository describes itself as: "ULTRASHIP" Claude Code plugin — 39 skills, 33 tools, 11 agents for ship-ready workflows: planning, review, pentesting, safety guardrails, canary monitoring, SEO/AI-readiness… The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ed232cb. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadGrepGlobFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmpnpmnodeyarnFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, pnpm and yarn, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Audit loads about 3.9k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 1,905 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
ckage.json", "**/package-lock.json", "**/.env*", "**/Gemfile.lock", "**/requirements.txt"]- If .env is committed, add it to .gitignorefiles from the server — `/etc/passwd`, `.env`, private keys. The fix is to resolve the path and verify it starts with t- Add .env to .gitignore if missingallowed-tools: Bash, Read, Grep, GlobAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Houseofmvps/ultraship at commit ed232cb, republished under its MIT licence (© Houseofmvps). 1,905 words, ~3,858 tokens.
.claude/skills/security-audit/SKILL.md (or your agent's skills folder).Comprehensive security scan. Finds issues AND fixes them.
Detect package manager from lockfile and run audit:
pnpm-lock.yaml → pnpm auditpackage-lock.json → npm audityarn.lock → yarn auditIf critical/high vulnerabilities found, run the appropriate fix command (non-breaking only):
pnpm audit --fix # or npm audit fixnode ${CLAUDE_PLUGIN_ROOT}/tools/secret-scanner.mjs <project-directory>For any findings:
Generic secret scanning misses the context mistakes that leak whole databases (the Moltbook breach class). Run the Sentinel:
node ${CLAUDE_PLUGIN_ROOT}/tools/vibe-security-scanner.mjs <project-directory>It flags only categorical mistakes / decoded proof (zero false positives):
public-prefixed-secret-name / public-prefixed-secret-value — a server-only secret behind NEXT_PUBLIC_/VITE_/EXPO_PUBLIC_/etc. Fix: rename without the public prefix, read it server-side only, and rotate the key (it was in the browser bundle).public-supabase-service-role-key — a decoded Supabase service_role JWT exposed to the client. Fix: rotate immediately; use the anon key on the client, service_role only on the server.service-role-in-client — a service_role key referenced in a "use client" component. Fix: move that Supabase call to a server action / route handler.supabase-table-without-rls — a table created with no Row Level Security. Fix: alter table <t> enable row level security; plus create policy rules. With the anon key public, an RLS-less table is world-readable/writable.mutation-routes-no-auth-lib (advisory) — confirm each POST/PUT/DELETE checks identity and is rate-limited.Use Grep to scan source files for dangerous patterns:
eval( → Suggest safer alternatives
new Function( → Suggest safer alternatives
.innerHTML = → Suggest textContent or sanitized HTML
dangerouslySetInnerHTML → Verify sanitization
SQL + variable → Suggest parameterized queries
http:// → Suggest https:// (mixed content)Scan the codebase for auth-related weaknesses. These are the most exploited vulnerability class in web applications — a single flaw here typically means full account takeover.
Access-Control-Allow-Origin: * or origin: '*' or cors({ origin: true }). An allow-all CORS policy lets any malicious site make authenticated requests on behalf of your users. The fix is an explicit allowlist of trusted origins, never a wildcard when credentials are involved.express-rate-limit, Hono rateLimiter, Redis-backed sliding window), these endpoints are vulnerable to credential stuffing and brute force. Recommend per-IP and per-account limits (e.g., 5 attempts per minute per IP on login, 3 password resets per hour per email).jwt.sign and check for missing expiresIn option — a token without expiry is a permanent credential. Check for HS256 with secrets shorter than 256 bits (32 bytes); attackers can brute-force short HS256 secrets offline. Recommend RS256/ES256 for production, or HS256 with a cryptographically random secret of at least 32 bytes. Also check that jwt.verify does not pass algorithms: ['none'] or accept unsigned tokens.SameSite=Strict or SameSite=Lax cookie attribute, and no custom header requirement (e.g., X-Requested-With), these endpoints are exploitable via cross-site request forgery. SPAs using Authorization: Bearer headers are inherently CSRF-safe, but cookie-based auth requires explicit protection./api/users/:id, /api/orders/:id, /api/invoices/:id where the ID comes from the URL or request body. If the handler does not verify that the authenticated user owns or has permission to access that resource (e.g., WHERE id = :id AND userId = :currentUser), any authenticated user can access any other user's data by changing the ID. This is consistently in the OWASP Top 10 as "Broken Access Control."Scan for injection vectors beyond basic SQL concatenation. Injection flaws remain the most dangerous vulnerability class because they allow attackers to execute arbitrary operations within your application's context.
\SELECT * FROM users WHERE id = ${id}`), string building with + operators near SQL keywords, and ORM raw query methods (knex.raw(), prisma.$queryRawUnsafe(), sequelize.query()` without bind parameters). Even ORMs are vulnerable when developers use raw query escape hatches.fs.readFile, fs.readFileSync, fs.createReadStream, path.join, path.resolve, or res.sendFile. If the input is not validated against ../ sequences (or null bytes on older Node versions), attackers can read arbitrary files from the server — /etc/passwd, .env, private keys. The fix is to resolve the path and verify it starts with the intended base directory.child_process.exec, child_process.execSync, shell: true in spawn options, or any function that passes user input to a shell. An attacker who controls even part of a shell command can chain arbitrary commands with ;, &&, |, or backticks. The fix is execFile/execFileSync (no shell) with arguments as an array, never string interpolation.fetch, axios, http.get, or any HTTP client. Without validation, an attacker can make your server request internal services (http://169.254.169.254 for cloud metadata, http://localhost:6379 for Redis, internal microservices). Validate that URLs resolve to public IP addresses and use an allowlist of permitted schemes and hosts.xml2js, libxmljs, fast-xml-parser, DOMParser), check that external entity processing is disabled. XXE allows attackers to read local files, perform SSRF, or cause denial of service via billion-laughs expansion. Most modern parsers disable XXE by default, but verify the configuration explicitly.Object.assign({}, userInput), _.merge({}, userInput), _.defaultsDeep, JSON.parse results used in deep merge operations, and __proto__ or constructor.prototype in request bodies. Prototype pollution lets attackers inject properties into Object.prototype, which can escalate to RCE in some frameworks (e.g., via EJS template engine gadgets). The fix is Object.create(null) for dictionary objects, input schema validation, and Object.freeze(Object.prototype) in hardened environments.Modern applications pull in hundreds of transitive dependencies. A single compromised package in the dependency tree can execute arbitrary code on every developer machine and CI server.
npm pkg get scripts.postinstall or grep lockfile for "postinstall" hooks in dependencies. Malicious packages use postinstall scripts to exfiltrate environment variables, SSH keys, or install backdoors. Legitimate packages that need postinstall (e.g., esbuild, sharp for native binaries) should be audited individually.lodas vs lodash), scope confusion (@internal/utils vs internal-utils), and hyphen/underscore variants. Typosquatted packages typically mirror the real package's API while adding a backdoor.package.json. A missing or manipulated lockfile means builds are not reproducible and dependency resolution could pull in malicious versions. Run pnpm install --frozen-lockfile (or npm ci) in CI to enforce lockfile integrity.npm config set ignore-scripts true in CI environments, then explicitly allowlist packages that need install scripts. This prevents supply chain attacks via postinstall hooks from newly added or compromised dependencies.If a dev server is running, use curl or fetch to check response headers:
If missing, generate middleware snippet for the project's framework:
app.use('*', secureHeaders())node ${CLAUDE_PLUGIN_ROOT}/tools/dep-doctor.mjs <project-directory>Report:
Weak or misused cryptography is often invisible until a breach. These checks catch the most common mistakes that silently undermine the security of authentication, token generation, and data protection.
createHash('md5'), createHash('sha1'), or any use of MD5/SHA1 for security purposes (password hashing, token generation, integrity verification). MD5 has practical collision attacks; SHA1 is deprecated by NIST since 2011. These are acceptable only for non-security checksums (e.g., cache keys, ETags). For integrity, use SHA-256 or SHA-3. For passwords, use bcrypt or argon2 exclusively.createCipheriv, createDecipheriv, and check whether the key or IV is a string literal, hex constant, or imported from a non-env source. Hardcoded keys mean every deployment shares the same key, and anyone with source code access (including leaked repos) can decrypt all data. Keys must come from environment variables or a secrets manager, and IVs must be randomly generated per encryption operation.Math.random() used anywhere near token generation, session IDs, OTP codes, password reset links, or API keys. Math.random() is not cryptographically secure — its output is predictable given enough samples. The fix is crypto.randomBytes() or crypto.randomUUID() for Node.js, or crypto.getRandomValues() for browser contexts.createHash used on passwords — this means passwords are hashed with a fast algorithm (SHA-256, MD5) without salting or key stretching, making them trivially crackable with rainbow tables or GPU brute force. Also check bcrypt cost factors below 10, which are insufficient for modern hardware.Data leakage is the silent breach — it does not trip alarms, does not require exploits, and often goes unnoticed until the data appears on a paste site. These checks catch the most common ways applications hemorrhage sensitive information.
NODE_ENV conditional logic. If err.stack, err.message, or raw error objects are sent in HTTP responses without checking the environment, attackers get free reconnaissance — internal file paths, framework versions, database connection strings, and query structures. The fix is a generic error response in production with a correlation ID for internal log lookup.console.log, logger.info, logger.debug, and logging library calls that include request bodies, user objects, or variables named email, phone, password, ssn, token, secret, creditCard, or ip. Logs are often stored in plain text, shipped to third-party log aggregators, and retained long past their usefulness. Recommend structured logging with explicit field allowlists and automatic PII redaction.res.json(user) where user is a Drizzle/Prisma/Sequelize model), it likely leaks internal fields: passwordHash, resetToken, internalNotes, stripeCustomerId, createdAt metadata, or soft-delete flags. The fix is explicit response DTOs or select/pick at the query level — never return the raw model.unsafe-inline, unsafe-eval, and wildcard sources (*) in existing CSPs. A baseline CSP should at minimum set default-src 'self', script-src 'self', and object-src 'none'. Report-only mode (Content-Security-Policy-Report-Only) is a safe way to deploy CSP incrementally without breaking existing functionality.Think like an attacker. For every endpoint, ask: "What happens if I send unexpected input?" For every data flow, ask: "What if this is intercepted?" For every dependency, ask: "What if this is compromised?" Fix what you find. Document what you can't fix. Treat security as a spectrum, not a checkbox.
© Houseofmvps, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/security-audit of Houseofmvps/ultraship.
Open the folder on GitHubat commit ed232cb
Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Audit this skillHouseofmvps/ultraship | 123 | — | ~3.9k | Automated safety check: Notes | MIT | |
| Security Auditoreigent-ai/eigent | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | |
| Security Reviewgithub/awesome-copilot | 40k | 1 repos | ~2.3k | Automated safety check: Notes | MIT | |
| Security Auditbybren-llc/safe-agentic-workflow | 421 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Discover Securityrand/cc-polymath | 181 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Security Reviewjewbetcha/opentrace | 116 | 17 repos | ~3.1k | Automated safety check: Notes | MIT |
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
github/awesome-copilot
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…
bybren-llc/safe-agentic-workflow
RLS validation, security audits, OWASP compliance, and vulnerability scanning.
rand/cc-polymath
Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management.
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
Houseofmvps/ultraship
A skill your agent uses when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions
Houseofmvps/ultraship
Accessibility audit + auto-fix (WCAG 2.2 A/AA). An agent skill from Houseofmvps/ultraship.
Houseofmvps/ultraship
Living Architecture Map — auto-generate Mermaid diagrams of your codebase.
Houseofmvps/ultraship
Learn From the Best — analyze patterns from any codebase and apply them to yours.
Houseofmvps/ultraship
Code review with principal-engineer-level depth. An agent skill from Houseofmvps/ultraship.
Houseofmvps/ultraship
Competitive X-Ray — analyze any competitor URL vs your site.
Works with
Categories
Run security audit — dependency vulnerabilities, secret scanning, OWASP pattern detection, HTTP headers. Security Audit is an agent skill from Houseofmvps/ultraship. Run security audit — dependency vulnerabilities, secret scanning, OWASP pattern detection, HTTP headers.
Security Audit fits situations like: user wants to harden their project; tasks that involve Security review; tasks that involve Secrets management.
Run `npx skills add Houseofmvps/ultraship --skill security-audit -a claude-code`. Or copy the skill folder (skills/security-audit in Houseofmvps/ultraship) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Houseofmvps/ultraship --skill security-audit -a codex`. Or copy the skill folder (skills/security-audit in Houseofmvps/ultraship) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Houseofmvps/ultraship --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.
Going by SKILL.md and its folder, Security Audit needs the command-line tools its instructions call (npm, pnpm, node and yarn). Its frontmatter pre-approves these tools: Bash, Read, Grep, Glob.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.9k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Audit: Security Auditor (eigent-ai/eigent, 15k stars), Security Review (github/awesome-copilot, 40k stars), Security Audit (bybren-llc/safe-agentic-workflow, 421 stars) and Discover Security (rand/cc-polymath, 181 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Houseofmvps (a GitHub user) maintains it in Houseofmvps/ultraship, which has 123 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on July 8, 2026.
Source: Houseofmvps/ultraship on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.