Convex Security Audit
waynesutton/builder-skills
Deep security review of a Convex app: authorization model, data access paths per table, HTTP action exposure, rate limiting, file storage access, scheduled function trust, and a written findings…
"보안 점검", "security check", "security audit", "취약점 분석", "vulnerability scan", "보안 감사", "시크릿 노출", "API 보안", "인증 점검", "rate limit" 등 보안 관련 코드 리뷰나 취약점 감사 시 사용하세요.
$ npx skills add imgompanda/fireauto --skill fireauto-secure-guide -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install imgompanda/fireauto fireauto-secure-guide --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/imgompanda/fireauto.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugin/skills/fireauto-secure-guide .claude/skills/fireauto-secure-guide && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fireauto-secure-guide" agent skill from https://github.com/imgompanda/fireauto/tree/main/plugin/skills/fireauto-secure-guide into .claude/skills/fireauto-secure-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fireauto-secure-guide", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/imgompanda/fireauto/tree/main/plugin/skills/fireauto-secure-guideType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add imgompanda/fireauto --skill fireauto-secure-guide -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install imgompanda/fireauto fireauto-secure-guide --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/imgompanda/fireauto.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugin/skills/fireauto-secure-guide .agents/skills/fireauto-secure-guide && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fireauto-secure-guide" agent skill from https://github.com/imgompanda/fireauto/tree/main/plugin/skills/fireauto-secure-guide into .agents/skills/fireauto-secure-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fireauto-secure-guide", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add imgompanda/fireauto --skill fireauto-secure-guide -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install imgompanda/fireauto fireauto-secure-guide --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/imgompanda/fireauto.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugin/skills/fireauto-secure-guide .cursor/skills/fireauto-secure-guide && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fireauto-secure-guide" agent skill from https://github.com/imgompanda/fireauto/tree/main/plugin/skills/fireauto-secure-guide into .cursor/skills/fireauto-secure-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fireauto-secure-guide", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/imgompanda/fireauto.git --path plugin/skills/fireauto-secure-guide--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add imgompanda/fireauto --skill fireauto-secure-guide -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install imgompanda/fireauto fireauto-secure-guide --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/imgompanda/fireauto.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugin/skills/fireauto-secure-guide .gemini/skills/fireauto-secure-guide && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fireauto-secure-guide" agent skill from https://github.com/imgompanda/fireauto/tree/main/plugin/skills/fireauto-secure-guide into .gemini/skills/fireauto-secure-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fireauto-secure-guide", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install imgompanda/fireauto fireauto-secure-guideInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add imgompanda/fireauto --skill fireauto-secure-guide -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/imgompanda/fireauto.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugin/skills/fireauto-secure-guide .github/skills/fireauto-secure-guide && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fireauto-secure-guide" agent skill from https://github.com/imgompanda/fireauto/tree/main/plugin/skills/fireauto-secure-guide into .github/skills/fireauto-secure-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fireauto-secure-guide", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add imgompanda/fireauto --skill fireauto-secure-guide -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install imgompanda/fireauto fireauto-secure-guide --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/imgompanda/fireauto.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugin/skills/fireauto-secure-guide .opencode/skills/fireauto-secure-guide && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fireauto-secure-guide" agent skill from https://github.com/imgompanda/fireauto/tree/main/plugin/skills/fireauto-secure-guide into .opencode/skills/fireauto-secure-guide/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fireauto-secure-guide", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fireauto-secure-guide"보안 점검", "security check", "security audit", "취약점 분석", "vulnerability scan", "보안 감사", "시크릿 노출", "API 보안", "인증 점검", "rate limit" 등 보안 관련 코드 리뷰나 취약점 감사 시 사용하세요.
Fireauto Secure Guide is an agent skill from imgompanda/fireauto. "보안 점검", "security check", "security audit", "취약점 분석", "vulnerability scan", "보안 감사", "시크릿 노출", "API 보안", "인증 점검", "rate limit" 등 보안 관련 코드 리뷰나 취약점 감사 시 사용하세요.
Its SKILL.md is about 370 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/patterns.md`).
It sits in Security, covering Rate limiting and Security review. The repository describes itself as: Claude Code 자동화 플러그인 — SEO, 보안, 팀 에이전트, PRD, 레딧 리서치를 커맨드 하나로. The licence is MIT.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 694d941. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fireauto Secure Guide loads about 371 tokens when it runs, and up to ~1k if it reads all its reference files. Until then it costs about 45 tokens; SKILL.md has 159 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
1. **환경변수/시크릿 노출** — .env 파일, 하드코딩된 키, NEXT_PUBLIC_ 오용Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from imgompanda/fireauto at commit 694d941, republished under its MIT licence (© imgompanda). 159 words, ~371 tokens.
.claude/skills/fireauto-secure-guide/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.실제 SaaS 프로젝트에서 총 18개 취약점을 발견한 패턴을 기반으로 한 보안 감사 방법론.
| 심각도 | 기준 |
|---|---|
| CRITICAL | 즉시 조치. 데이터 유출, 인증 우회, 시크릿 노출 |
| HIGH | 빠른 조치. 서비스 장애, 비용 발생 가능 |
| MEDIUM | 계획적 조치. 특정 조건에서 악용 가능 |
| LOW | 개선 권장. 보안 강화 목적 |
"sk-", "sk_live", "sk_test" → API 키
"password.*=", "secret.*=", "token.*=" → 하드코딩
"NEXT_PUBLIC_.*SERVICE" → 서비스 키 클라이언트 노출API 라우트에서 아래 패턴이 없으면 인증 미적용:
"getSession", "getUser", "auth()", "cookies()"AI 호출: "openai", "anthropic", "claude", "gpt"
같은 파일에 "ratelimit"이 없으면 취약content: `...${userInput}...`
→ 시스템 프롬프트와 사용자 메시지가 분리되어야 함우선순위 = 심각도 점수 × 구현 용이성
/fireauto-secure 실행으로 전체 보안 감사를 시작한다.
상세 검색 패턴과 수정 가이드: references/patterns.md
© imgompanda, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in plugin/skills/fireauto-secure-guide of imgompanda/fireauto.
Open the folder on GitHubat commit 694d941
Fireauto Secure Guide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fireauto Secure Guide this skillimgompanda/fireauto | 140 | — | ~371 | Automated safety check: Notes | MIT | |
| Convex Security Auditwaynesutton/builder-skills | 404 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| Security Reviewaffaan-m/ECC | 274k | 1 repos | ~3.2k | Automated safety check: Notes | MIT | |
| MCP Implementation Security Reviewgithub/awesome-copilot | 40k | — | ~5.2k | Automated safety check: Pass | MIT | |
| Better Auth Security Best PracticesEpicenterHQ/epicenter | 4.8k | — | ~896 | Automated safety check: Pass | Custom licence | |
| API Security ReviewOWASP/secure-agent-playbook | 186 | — | ~744 | Automated safety check: Pass | CC-BY-4.0 |
waynesutton/builder-skills
Deep security review of a Convex app: authorization model, data access paths per table, HTTP action exposure, rate limiting, file storage access, scheduled function trust, and a written findings…
affaan-m/ECC
Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın.
github/awesome-copilot
Review the implementation source code of MCP (Model Context Protocol) servers, clients, and tool handlers against a security baseline — authentication, sessions, rate limiting, input-schema…
EpicenterHQ/epicenter
Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.
OWASP/secure-agent-playbook
Comprehensive API security review against OWASP API Security Top 10 (2023).
aiskillstore/marketplace
Run defensive pre-release security tests for Python web applications.
imgompanda/fireauto
"DaisyUI", "daisyui", "UI 마이그레이션", "UI migration", "shadcn to daisyui", "테마 설정", "theme", "컴포넌트 변환", "DaisyUI 테마", "DaisyUI 컴포넌트" 등 DaisyUI 기반 UI 구축이나 shadcn/ui 마이그레이션 시 사용하세요.
imgompanda/fireauto
"정의로 이동", "참조 찾기", "심볼 검색", "타입 확인", "호출 계층", "코드 찾기", "함수 찾기", "어디서 쓰이는지", "어디에 정의된", "구현체 찾기", "인터페이스 구현", "코드 추적", "코드 탐색" 등 코드 탐색이나 심볼 검색이 필요할 때 자동으로 LSP 도구를 우선 사용하세요.
imgompanda/fireauto
프로젝트 생성, 마일스톤 관리, 태스크 추적이 필요할 때 사용하세요. An agent skill from imgompanda/fireauto.
imgompanda/fireauto
"팀 에이전트", "team agent", "병렬 작업", "parallel work", "워크스트림", "workstream", "여러 에이전트", "동시에 작업", "에이전트 팀", "에이전트 간 대화", "team chat", "컴퍼니", "company model" 등 멀티 에이전트 병렬 작업이나 에이전트 간 협업 시 사용하세요.
imgompanda/fireauto
"레딧 리서치", "reddit research", "수요조사", "시장조사", "리드 스코어링", "lead scoring", "market research", "레딧에서 고객 찾기", "레딧 데이터 수집", "reddit lead generation" 등 레딧 기반 시장 조사나 고객 발굴 시 사용하세요.
imgompanda/fireauto
"SEO 감사", "SEO audit", "기술 SEO", "technical SEO", "구조화 데이터", "schema markup", "JSON-LD", "robots.txt", "sitemap", "메타 태그", "검색엔진 최적화", "pSEO", "Rich Results", "Core Web Vitals" 등 SEO 관련 최적화나 감사 시…
Categories
"보안 점검", "security check", "security audit", "취약점 분석", "vulnerability scan", "보안 감사", "시크릿 노출", "API 보안", "인증 점검", "rate limit" 등 보안 관련 코드 리뷰나 취약점 감사 시 사용하세요. Fireauto Secure Guide is an agent skill from imgompanda/fireauto. "보안 점검", "security check", "security audit", "취약점 분석", "vulnerability scan", "보안 감사", "시크릿 노출", "API 보안", "인증 점검", "rate limit" 등 보안 관련 코드 리뷰나 취약점 감사 시 사용하세요.
Fireauto Secure Guide fits situations like: tasks that involve Rate limiting; tasks that involve Security review.
Run `npx skills add imgompanda/fireauto --skill fireauto-secure-guide -a claude-code`. Or copy the skill folder (plugin/skills/fireauto-secure-guide in imgompanda/fireauto) into .claude/skills/fireauto-secure-guide in your project. Claude Code loads it when a task matches its description.
Run `npx skills add imgompanda/fireauto --skill fireauto-secure-guide -a codex`. Or copy the skill folder (plugin/skills/fireauto-secure-guide in imgompanda/fireauto) into .agents/skills/fireauto-secure-guide in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add imgompanda/fireauto --skill fireauto-secure-guide -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fireauto-secure-guide, .gemini/skills/fireauto-secure-guide, .github/skills/fireauto-secure-guide and .opencode/skills/fireauto-secure-guide in your project.
SKILL.md names no scripts, command-line tools or credentials: Fireauto Secure Guide is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Fireauto Secure Guide is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 371 tokens (SKILL.md is roughly 1.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 668 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Fireauto Secure Guide: Convex Security Audit (waynesutton/builder-skills, 404 stars), Security Review (affaan-m/ECC, 274k stars), MCP Implementation Security Review (github/awesome-copilot, 40k stars) and Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
imgompanda (a GitHub user) maintains it in imgompanda/fireauto, which has 140 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on April 9, 2026.
Source: imgompanda/fireauto on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.