Security Auditor
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
Pre-deployment security audit organized by OWASP Top 10. An agent skill from jamditis/claude-skills-journalism.
$ npx skills add jamditis/claude-skills-journalism --skill security-checklist -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jamditis/claude-skills-journalism security-checklist --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jamditis/claude-skills-journalism.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security-toolkit/skills/security-checklist .claude/skills/security-checklist && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-checklist" agent skill from https://github.com/jamditis/claude-skills-journalism/tree/master/security-toolkit/skills/security-checklist into .claude/skills/security-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-checklist", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jamditis/claude-skills-journalism/tree/master/security-toolkit/skills/security-checklistType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jamditis/claude-skills-journalism --skill security-checklist -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jamditis/claude-skills-journalism security-checklist --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jamditis/claude-skills-journalism.git skills-src && mkdir -p .agents/skills && cp -r skills-src/security-toolkit/skills/security-checklist .agents/skills/security-checklist && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-checklist" agent skill from https://github.com/jamditis/claude-skills-journalism/tree/master/security-toolkit/skills/security-checklist into .agents/skills/security-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-checklist", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jamditis/claude-skills-journalism --skill security-checklist -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jamditis/claude-skills-journalism security-checklist --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jamditis/claude-skills-journalism.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/security-toolkit/skills/security-checklist .cursor/skills/security-checklist && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-checklist" agent skill from https://github.com/jamditis/claude-skills-journalism/tree/master/security-toolkit/skills/security-checklist into .cursor/skills/security-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-checklist", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jamditis/claude-skills-journalism.git --path security-toolkit/skills/security-checklist--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jamditis/claude-skills-journalism --skill security-checklist -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jamditis/claude-skills-journalism security-checklist --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jamditis/claude-skills-journalism.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/security-toolkit/skills/security-checklist .gemini/skills/security-checklist && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-checklist" agent skill from https://github.com/jamditis/claude-skills-journalism/tree/master/security-toolkit/skills/security-checklist into .gemini/skills/security-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-checklist", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jamditis/claude-skills-journalism security-checklistInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jamditis/claude-skills-journalism --skill security-checklist -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jamditis/claude-skills-journalism.git skills-src && mkdir -p .github/skills && cp -r skills-src/security-toolkit/skills/security-checklist .github/skills/security-checklist && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-checklist" agent skill from https://github.com/jamditis/claude-skills-journalism/tree/master/security-toolkit/skills/security-checklist into .github/skills/security-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-checklist", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jamditis/claude-skills-journalism --skill security-checklist -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jamditis/claude-skills-journalism security-checklist --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jamditis/claude-skills-journalism.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/security-toolkit/skills/security-checklist .opencode/skills/security-checklist && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-checklist" agent skill from https://github.com/jamditis/claude-skills-journalism/tree/master/security-toolkit/skills/security-checklist into .opencode/skills/security-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-checklist", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-checklistPre-deployment security audit organized by OWASP Top 10. An agent skill from jamditis/claude-skills-journalism.
Security Checklist is an agent skill from jamditis/claude-skills-journalism. Pre-deployment security audit organized by OWASP Top 10. Use when reviewing code before shipping or going to production.
Its SKILL.md is about 8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Security, covering Security review and Web application vulnerabilities. The repository describes itself as: Claude Code skills for journalism, media, and academia - verification, FOIA, data journalism, academic writing, and more. The licence is MIT.
12 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e3e2172. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
owasp.orgcisa.govcwe.mitre.orgslsa.devcsrc.nist.govunitedhealthgroup.comsansec.iosec.okta.comcrowdstrike.comdatatracker.ietf.orgcheatsheetseries.owasp.orghaveibeenpwned.comsigstore.devecma-international.orgdocs.npmjs.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
JWT_SECRETAPI_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Checklist loads about 8k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 3,417 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
# .env (development only, never commit).env.env.local.env.*.localAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jamditis/claude-skills-journalism at commit e3e2172, republished under its MIT licence (© jamditis). 3,417 words, ~8,008 tokens.
.claude/skills/security-checklist/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Pre-deployment security audit organized around the OWASP Top 10:2025 categories (released late 2025, succeeding the 2021 edition). This is the baseline that prevents obvious disasters, not a substitute for a real penetration test or threat model. For verification depth beyond this checklist, see OWASP ASVS 5.0 (https://owasp.org/www-project-application-security-verification-standard/). For API-specific scope, see OWASP API Security Top 10:2023 (https://owasp.org/API-Security/editions/2023/en/0x00-header/).
Security knowledge ages on a 6-12 month half-life. The recipes below were last verified on 2026-05-08; they may be stale by the time you read this. Before applying any pattern in this skill, fan out research scoped to the OWASP Top 10:2025 categories being audited so the recipes are interpreted against current authoritative sources, not against this file's snapshot.
Run the 4-angle research below by default. Skip ONLY when ALL of these hold:
Research skipped because <reason> note in your response."I think I know" / "moving fast" / "user wants this done quickly" / "already familiar" are NOT valid skip reasons. The whole point of this preamble is that future-you should not trust this skill body's defaults until current state is checked.
Each subagent returns ≤300 words of bullets with citations. Dispatch all 4 in a single message so they run concurrently.
Angle 1, Authoritative standards. Have NIST / OWASP / IETF (RFCs and Internet-Drafts) / W3C / CISA published anything new about the OWASP Top 10:2025 categories being audited in the last 6-12 months? Look for: spec finalizations, deprecations, replacement specs, RFC publications, draft revisions, NIST SP updates, OWASP project version bumps. Cite by document number + publication date.
Angle 2, Active exploitation. What's actively being exploited that targets the OWASP Top 10:2025 categories being audited? Pull from: CISA Known Exploited Vulnerabilities (KEV) catalog (filter to last 6-12 months), recent CVE / GHSA entries with high CVSS or in-the-wild exploitation, breach postmortems and incident reports (CSRB, vendor RCAs, security-vendor research). Surface CWE patterns dominating recent KEV adds. Cite by CVE number + advisory URL.
Angle 3, Tooling and library state. Are the libraries this skill recommends still current? What are the latest major versions in the relevant package registry (npm / PyPI / RubyGems / crates.io)? Have any been deprecated, replaced, or merged into another project? Have any flipped a secure default? Look up current versions in: registry.npmjs.org, pypi.org, rubygems.org, crates.io, pkg.go.dev. Cite by package + version + release date.
Angle 4, Practitioner discourse. What are practitioners and security teams talking about in the last 6 months? Pull from: OWASP Cheat Sheet Series (last-modified date matters), GitHub Security Lab posts, vendor security blogs (Cloudflare, Fastly, Snyk, Datadog, Wiz, GitGuardian), conference talks (Black Hat, DEF CON, OWASP Global AppSec, USENIX Security), SANS ISC, Krebs, recent OWASP project re-releases. Surface the patterns being adopted and the anti-patterns being called out. Cite by post URL + author + date.
After the 4 returns land, write a 1-paragraph "current state for the OWASP Top 10:2025 categories being audited, as of <today's date>" that names:
If the synthesis flags drift in this skill body's recipes (e.g., a spec finalized after 2026-05-08, a library now deprecated, a default flipped), call that out explicitly in your response and override the skill body where they conflict. The synthesis wins. The skill body is scaffolding, not scripture.
If subagents are not available in your runtime, the same shape applies in-line: do 4 sequential targeted searches (web search for standards, KEV catalog lookup, package registry version checks, recent cheat-sheet diff). Land the same 1-paragraph synthesis. Cost goes up; the protection does not change.
Walk all 10 categories before any production deployment. For each category: read the framing paragraph, run through the must-do items, and check the code-pattern references where they apply. After the walk, file findings as one issue per category with gaps. The flat 25-item Yes/No gate at the end is the pre-deploy summary, not the audit itself.
If you can't check an item, don't ship, fix it first.
Authorization failures are the most-exploited class on the web. The 2025 edition folds SSRF (Server-Side Request Forgery) into A01 because the underlying failure is the same: the server acts on a request it should have rejected. Active exemplars in 2024-2025 include broken object-level authorization in API endpoints (still the dominant API risk per OWASP API Top 10:2023 API1) and SSRF used as a pivot to cloud metadata endpoints.
localhost, 127.0.0.0/8, link-local (169.254.0.0/16), or cloud metadata IP (169.254.169.254) fetches; DNS rebinding protection on resolvers.-- Enable RLS on table
ALTER TABLE documents ENABLE ROW LEVEL SECURITY;
-- Users can only read their own documents
CREATE POLICY "Users can read own documents" ON documents
FOR SELECT USING (auth.uid() = user_id);
-- Users can only insert documents as themselves
CREATE POLICY "Users can insert own documents" ON documents
FOR INSERT WITH CHECK (auth.uid() = user_id);
-- Users can only update their own documents
CREATE POLICY "Users can update own documents" ON documents
FOR UPDATE USING (auth.uid() = user_id);
-- Users can only delete their own documents
CREATE POLICY "Users can delete own documents" ON documents
FOR DELETE USING (auth.uid() = user_id);Misconfiguration moved up the rankings (was A05 in 2021) because default-insecure framework settings keep shipping to production. The 2024 Snowflake / UNC5537 campaign is the canonical lesson: MFA was opt-in per tenant by default, and the campaign harvested credentials at scale before Snowflake flipped the default in 2024.
Access-Control-Allow-Origin: * flagged in production).debug=False, Django DEBUG=False, Express NODE_ENV=production, Rails RAILS_ENV=production.# .env (development only, never commit)
# Replace each <placeholder> with a real value generated locally.
# Generate JWT_SECRET with `openssl rand -hex 32` (256 bits).
DATABASE_URL=<your-database-connection-string>
JWT_SECRET=<32-byte-hex-secret>
API_KEY=<api-key-from-your-provider># .gitignore (mandatory)
.env
.env.local
.env.*.local
*.pem
*.key
credentials.json
secrets/// Reading environment variables (Node.js with dotenv)
require('dotenv').config();
const dbUrl = process.env.DATABASE_URL;
// Fail fast if missing
if (!process.env.JWT_SECRET) {
throw new Error('JWT_SECRET environment variable is required');
}const cors = require('cors');
// SAFE: specific origins
app.use(cors({
origin: ['https://myapp.com', 'https://www.myapp.com'],
methods: ['GET', 'POST', 'PUT', 'DELETE'],
allowedHeaders: ['Content-Type', 'Authorization'],
credentials: true
}));The unsafe pattern, cors() with no options, which sends Access-Control-Allow-Origin: *, is fine for dev but never for production with credentialed requests.
New category in 2025 that absorbs the old 2021 A06 "Vulnerable and Outdated Components." Broader than just patching: covers SBOM, build-system integrity, package provenance, and dependency-source trust. The xz-utils CVE-2024-3094 backdoor (March 2024) is the canonical "social-engineering of an open-source maintainer" lesson; Polyfill.io (June 2024) is the canonical "trusted CDN turned hostile" lesson.
latest in container images or ^x.y.z for security-critical libs).<script> and <link rel="stylesheet"> (Polyfill.io lesson, see A08 for the SRI checklist item).Compliance pointer: OMB M-26-05 (issued 2026-01-23) rescinded the federal-wide SBOM self-attestation mandate from M-22-18 + M-23-16. The EU Cyber Resilience Act (Reg 2024/2847) reporting obligations apply from 2026-09-11 and full obligations from 2027-12-11, don't treat the US rescission as global rescission.
Use vetted high-level libraries. Don't roll crypto. Don't compose AES-CBC + HMAC by hand, use libsodium, AWS Encryption SDK, or Tink. The 2026 normative ceiling is TLS 1.3 by default, TLS 1.2 minimum, TLS 1.0/1.1 disabled (RFC 8996 / BCP 195).
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload (2 years).Secure, HttpOnly, SameSite=Lax or Strict).secure-auth skill in this bundle, link from here.const helmet = require('helmet');
app.use(helmet({
contentSecurityPolicy: {
directives: {
defaultSrc: ["'self'"],
scriptSrc: ["'self'"],
styleSrc: ["'self'", "'unsafe-inline'"],
imgSrc: ["'self'", "data:", "https:"],
frameAncestors: ["'none'"]
},
},
hsts: {
maxAge: 63072000,
includeSubDomains: true,
preload: true
}
}));// Manual headers, modern set
res.setHeader('X-Content-Type-Options', 'nosniff');
res.setHeader('Strict-Transport-Security', 'max-age=63072000; includeSubDomains; preload');
res.setHeader('Content-Security-Policy', "default-src 'self'; frame-ancestors 'none'");
// Note: X-Frame-Options is replaced by CSP frame-ancestors. The legacy XSS-protection header is deprecated, modern browsers ignore it.CWE-78 OS command injection dominates CISA KEV in 2024-2025 (14 entries in 2024, 18 in 2025), eclipsing classic SQL injection by volume. CWE-22 path traversal also climbed (9 in 2024, 13 in 2025). MOVEit CVE-2023-34362 remains the canonical SQLi exemplar.
The unsafe pattern, interpolating user input into a SQL template string and calling db.query on the result, is CWE-89. Always parameterize.
// SAFE: parameterized query, user input bound as $1
db.query('SELECT * FROM users WHERE id = $1', [req.params.id]);# SAFE: parameterized query, user input bound as %s placeholder
cursor.execute("SELECT * FROM users WHERE id = %s", [user_id])The unsafe pattern, building the SQL string with an f-string that interpolates user input, is CWE-89.
The Node child_process module exposes a shell-execution primitive (the one that runs a command string through /bin/sh) and an argv-list primitive (the spawn family with shell: false). For any input that touches user data, use the argv-list primitive.
const { spawn } = require('child_process');
// SAFE: argv-list invocation, shell disabled
// userInput is treated as a single argument, never re-parsed by a shell
spawn('convert', [userInput, 'output.png'], { shell: false });The unsafe pattern, passing a template string with interpolated user input to the shell-execution primitive, is CWE-78. Don't do it. If you absolutely need shell features, allowlist-validate every component of the command first.
Python exposes shell-execution primitives (the OS shell-out function and subprocess.run(..., shell=True)) and an argv-list primitive (subprocess.run([...], shell=False)). For any input that touches user data, use the argv-list primitive.
import subprocess
# SAFE: argv-list invocation, shell disabled
# user_input is treated as a single argument, never re-parsed by a shell
subprocess.run(["convert", user_input, "output.png"], shell=False, check=True)The unsafe patterns, passing an f-string with interpolated user input to the OS shell-out function or to a subprocess call with shell=True, are CWE-78. Don't do them. Allowlist-validate any path or filename component before it reaches a shell-out boundary.
React auto-escapes JSX child content. The framework also exposes dangerouslySetInnerHTML, a prop whose name explicitly warns you what happens if you pass user data through it. Default to rendering as a child; reach for the dangerous prop only with a vetted sanitizer in front.
// DO NOT USE: dangerouslySetInnerHTML on user content with no sanitizer
<div dangerouslySetInnerHTML={{ __html: userContent }} />
// SAFE: React escapes content automatically when rendered as a child
<div>{userContent}</div>
// SAFE: when raw HTML is genuinely required, sanitize through DOMPurify first
import DOMPurify from 'dompurify';
<div dangerouslySetInnerHTML={{ __html: DOMPurify.sanitize(userContent) }} />For server-rendered HTML, use a template engine with auto-escaping (EJS <%= %>, Nunjucks {{ }} with autoescape on, etc.) rather than building strings by hand.
// DO NOT USE: template-string interpolation of user input into HTML
res.send(`<h1>Hello ${req.query.name}</h1>`);
// SAFE: template engine with auto-escaping
res.render('greeting', { name: req.query.name });Threat-modeling and secure defaults belong in the design phase, not retrofitted post-incident. Snowflake's MFA-opt-in default (until 2024) is the canonical "secure default" lesson, features that ship insecure by default and require opt-in to be safe are misuse-prone.
Renamed from "Identification and Authentication Failures" in 2021. Defaults live in the secure-auth skill in this bundle, checklist items here reference, don't duplicate. NIST SP 800-63B-4 went final 2025-07-31 (https://csrc.nist.gov/pubs/sp/800/63/b/4/final).
crypto.randomBytes or equivalent).Anchor lessons: Change Healthcare Feb 2024 (no MFA on the Citrix remote-access portal, https://www.unitedhealthgroup.com/newsroom/2024/2024-04-22-uhg-update-on-change-healthcare-cyberattack.html), Snowflake / UNC5537 2024 (default-on MFA was opt-in per tenant), Storm-0558 2023 (full token validation; CSRB review at https://www.cisa.gov/resources-tools/resources/CSRB-Review-Summer-2023-MEO-Intrusion), 23andMe 2023 (graph-traversal blast radius across linked accounts).
Note: "Software or Data", the OR is load-bearing. Covers CI/CD pipeline integrity, signed update channels, and deserialization safety. CWE-502 (deserialization) dominates KEV in 2024-2025 (11 in 2024, 14 in 2025).
<script> and <link rel="stylesheet"> (Polyfill.io lesson, https://sansec.io/research/polyfill-supply-chain-attack).Python's native binary-deserialization primitive executes arbitrary code on untrusted input, loads runs object constructors, including any __reduce__ payload an attacker has crafted. JSON does not. Across any trust boundary, use JSON. Same hazard for YAML: the bare loader runs Python code; use safe_load.
import json
import yaml
# DO NOT USE: pickle.loads runs arbitrary code on untrusted input,
# any object's __reduce__ method executes at parse time. CWE-502 sink.
# import pickle
# obj = pickle.loads(request.body)
# DO NOT USE: yaml.load with no Loader argument is equivalent to yaml.Loader and runs code:
# config = yaml.load(request.body)
# SAFE: JSON parsing returns plain data (dict / list / str / number / bool / None)
data = json.loads(request.body)
# SAFE: when YAML is genuinely required, use safe_load
config = yaml.safe_load(request.body)CWE-502 (deserialization of untrusted data) dominated the CISA KEV catalog in 2024-2025 (11 in 2024, 14 in 2025). The same warning applies in Java (ObjectInputStream.readObject), .NET (BinaryFormatter, NetDataContractSerializer, LosFormatter, SoapFormatter), and any Node package that "unserializes" arbitrary objects. JSON is the only safe choice for cross-trust-boundary input.
<!-- SAFE: SRI hash pinned -->
<script src="https://cdn.example.com/lib.js"
integrity="sha384-oqVuAfXRKap7fdgcCY5uykM6+R9GqQ8K/uxy9rx7HNQlGYl1kPzQho1wx4JwY8wC"
crossorigin="anonymous"></script>The unsafe pattern, referencing an external script with no integrity attribute, means any change at the CDN runs in your origin's context. Polyfill.io 2024 was exactly this.
Note: "Alerting", not "Monitoring", the 2025 edition reframes around active response, not just collection. The Okta HAR incident (2023) is the anchor lesson: customer-uploaded debug artifacts contained live session tokens because sanitization at log boundaries was inadequate.
Anchor lesson: Okta HAR file incident, https://sec.okta.com/articles/harfiles/
// SAFE: structured logging with field allowlist
console.log('Login attempt:', { email, success: false, reason: 'invalid_password' });
console.log('Request:', { endpoint: req.path, method: req.method, userId: req.user?.id });The unsafe pattern, logging the full request body or a credentials object, leaks every secret a user supplies. Never log password fields, token fields, full request bodies, or session identifiers.
New category in 2025. CWE catalog assigned CWE-1445 to this category, covering CWE-209/234/274/476/636 among 24 CWEs. The CrowdStrike Channel File 291 incident (July 2024) is the anchor lesson: production deployment of an unvalidated config file caused 8.5M Windows hosts to BSOD.
Exception blocks don't swallow security-relevant failures silently.Anchor lesson: CrowdStrike Falcon Channel File 291 RCA, https://www.crowdstrike.com/en-us/blog/falcon-content-update-preliminary-post-incident-report/
Run this at the end of the audit. If any answer is N, don't ship.
max-age=63072000; includeSubDomains; preload? Y/Nframe-ancestors? Y/N* in prod)? Y/Ndebug=False, NODE_ENV=production, etc.)? Y/Nsecure-auth skill).git filter-repo (preferred over git filter-branch) or BFG Repo-Cleaner to remove from history.console.log, logger., print(.You likely need to care about:
Minimum for any user data:
© jamditis, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in security-toolkit/skills/security-checklist of jamditis/claude-skills-journalism.
Open the folder on GitHubat commit e3e2172
Security Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Checklist this skilljamditis/claude-skills-journalism | 416 | — | ~8k | Automated safety check: Notes | MIT | |
| Security Auditoreigent-ai/eigent | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | |
| Security Reviewjewbetcha/opentrace | 116 | 17 repos | ~3.1k | Automated safety check: Notes | MIT | |
| Strix Code Vulnerability Scanusestrix/strix | 67k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Code Audit3stoneBrother/code-audit | 893 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence |
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
usestrix/strix
Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
jamditis/claude-skills-journalism
A skill your agent uses when creating distinct website directions, a client review picker, asset catalog, previews, and Cloudflare-ready handoffs.
jamditis/claude-skills-journalism
Builds an Open Knowledge Format (OKF) knowledge base from existing docs, notes, or a repo.
jamditis/claude-skills-journalism
Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.
jamditis/claude-skills-journalism
Acquire, clean, analyze, verify, visualize, and explain data for journalism.
jamditis/claude-skills-journalism
Creates print-ready HTML that exports to PDF. An agent skill from jamditis/claude-skills-journalism.
jamditis/claude-skills-journalism
Establishes how to find and use skills, requiring Skill tool invocation before any response.
Categories
Pre-deployment security audit organized by OWASP Top 10. An agent skill from jamditis/claude-skills-journalism. Security Checklist is an agent skill from jamditis/claude-skills-journalism. Pre-deployment security audit organized by OWASP Top 10.
Security Checklist fits situations like: reviewing code before shipping; going to production.
Run `npx skills add jamditis/claude-skills-journalism --skill security-checklist -a claude-code`. Or copy the skill folder (security-toolkit/skills/security-checklist in jamditis/claude-skills-journalism) into .claude/skills/security-checklist in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jamditis/claude-skills-journalism --skill security-checklist -a codex`. Or copy the skill folder (security-toolkit/skills/security-checklist in jamditis/claude-skills-journalism) into .agents/skills/security-checklist in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jamditis/claude-skills-journalism --skill security-checklist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-checklist, .gemini/skills/security-checklist, .github/skills/security-checklist and .opencode/skills/security-checklist in your project.
Going by SKILL.md and its folder, Security Checklist needs the command-line tools its instructions call (git) and credentials named JWT_SECRET and API_KEY. Our summary lists: Python 3; Node.js; A credential in JWT_SECRET; A credential in API_KEY.
SKILL.md names 15 domains. As links in the text: owasp.org, cisa.gov, cwe.mitre.org, slsa.dev, csrc.nist.gov, unitedhealthgroup.com, sansec.io, sec.okta.com, crowdstrike.com, datatracker.ietf.org, cheatsheetseries.owasp.org, haveibeenpwned.com, sigstore.dev, ecma-international.org and docs.npmjs.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Security Checklist is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 8k tokens (SKILL.md is roughly 32k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Checklist: Security Auditor (eigent-ai/eigent, 15k stars), Security Review (jewbetcha/opentrace, 116 stars), Strix Code Vulnerability Scan (usestrix/strix, 67k stars) and Code Audit (3stoneBrother/code-audit, 893 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jamditis (a GitHub user) maintains it in jamditis/claude-skills-journalism, which has 416 GitHub stars. The repository holds 53 skills in this directory. The repository was last updated on October 4, 2026.
Source: jamditis/claude-skills-journalism on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.