Code Security
semgrep/skills
Security guidelines for writing secure code. An agent skill from semgrep/skills.
A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.
$ npx skills add jellydn/my-ai-tools --skill security-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jellydn/my-ai-tools security-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jellydn/my-ai-tools.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-audit .claude/skills/security-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-audit" agent skill from https://github.com/jellydn/my-ai-tools/tree/main/skills/security-audit into .claude/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jellydn/my-ai-tools/tree/main/skills/security-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jellydn/my-ai-tools --skill security-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jellydn/my-ai-tools security-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jellydn/my-ai-tools.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security-audit .agents/skills/security-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-audit" agent skill from https://github.com/jellydn/my-ai-tools/tree/main/skills/security-audit into .agents/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jellydn/my-ai-tools --skill security-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jellydn/my-ai-tools security-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jellydn/my-ai-tools.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security-audit .cursor/skills/security-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-audit" agent skill from https://github.com/jellydn/my-ai-tools/tree/main/skills/security-audit into .cursor/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jellydn/my-ai-tools.git --path skills/security-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jellydn/my-ai-tools --skill security-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jellydn/my-ai-tools security-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jellydn/my-ai-tools.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security-audit .gemini/skills/security-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/jellydn/my-ai-tools/tree/main/skills/security-audit into .gemini/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jellydn/my-ai-tools security-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jellydn/my-ai-tools --skill security-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jellydn/my-ai-tools.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security-audit .github/skills/security-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/jellydn/my-ai-tools/tree/main/skills/security-audit into .github/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jellydn/my-ai-tools --skill security-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jellydn/my-ai-tools security-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jellydn/my-ai-tools.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security-audit .opencode/skills/security-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/jellydn/my-ai-tools/tree/main/skills/security-audit into .opencode/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-auditA skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.
Security Audit is an agent skill from jellydn/my-ai-tools. Use when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files (for example `reference/devsecops.md`, `reference/nodejs-security.md` and `reference/owasp-asvs.md`). Compatibility notes: cline, claude, opencode, amp, codex, gemini, cursor, pi
It sits in Security, covering Security review, Secure coding and Cryptography. It works with Node.js. The repository describes itself as: Comprehensive configuration management for AI coding tools - Replicate my complete setup for Claude Code, OpenCode, Amp, Li, Codex and Claude Code Switch with custom… The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 62c9227. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitnpmjqFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
cline, claude, opencode, amp, codex, gemini, cursor, pi
From compatibility in the SKILL.md frontmatter.
Security Audit loads about 2.9k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 1,191 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
*.yaml' -o -name 'Dockerfile*' -o -name '.env*' \) -not -path './node_modules/*'Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jellydn/my-ai-tools at commit 62c9227, republished under its MIT licence (© jellydn). 1,191 words, ~2,901 tokens.
.claude/skills/security-audit/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Perform a structured security audit of code, configuration, and architecture. Identify vulnerabilities, rank them by severity, and recommend concrete fixes grounded in OWASP standards, framework-specific best practices, and DevSecOps controls.
This is a read-only analysis. Do not modify code — audit, then report.
/security-audit [scope]full to audit the whole repository for systemic issues.The audit draws on five reference areas. Load the relevant reference file when a finding needs grounding or when you need detailed requirements for a topic:
| Area | Reference | When to load |
|---|---|---|
| OWASP Top 10 | reference/owasp-top-10.md | Classifying a finding against the major vulnerability categories (2021 + 2025) |
| OWASP ASVS | reference/owasp-asvs.md | Deriving concrete security requirements or building a verification checklist |
| OWASP Cheat Sheet Series | reference/owasp-cheat-sheets.md | Needing practical implementation guidance (auth, JWT, file upload, CSRF, password storage) |
| Node.js Security | reference/nodejs-security.md | Auditing Express, NestJS, Fastify, or Node.js dependency/supply-chain issues |
| DevSecOps | reference/devsecops.md | Reviewing CI/CD pipeline security, dependency/container/secret/SAST/DAST scanning |
Use progressive disclosure: keep the reference files unloaded until a finding maps to them. Load only the file the current finding needs.
# Detect the default branch
BASE_BRANCH=$(git remote show origin 2>/dev/null | grep 'HEAD branch' | awk '{print $NF}' || echo main)
# Diff under audit
git diff "$BASE_BRANCH"...HEAD --stat
git diff "$BASE_BRANCH"...HEAD
# Dependency surface
cat package.json 2>/dev/null | jq '.dependencies, .devDependencies'
npm audit --json 2>/dev/null | jq '.metadata.vulnerabilities' 2>/dev/null
# Configuration surface
find . -maxdepth 2 \( -name '*.yml' -o -name '*.yaml' -o -name 'Dockerfile*' -o -name '.env*' \) -not -path './node_modules/*'For a full audit, also enumerate: auth/session code, input handlers, file upload paths, database query construction, crypto usage, CI/CD workflow files, and container definitions.
Completion criteria:
full audits, the additional security-critical code paths are listed.Walk every changed or in-scope file against this checklist. Each item maps to an OWASP Top 10 category — use reference/owasp-top-10.md for the full category definitions and examples.
exec/spawn with user input; uses argument arraysdangerouslySetInnerHTML/v-html/|raw justified and sanitizedreference/owasp-cheat-sheets.md* with credentialscrypto.randomUUID()/crypto.randomBytes() — never Math.random() for securityreference/devsecops.md for secret scanningnpm ci used in CI; lockfile committed; --ignore-scripts consideredreference/owasp-cheat-sheets.mdCompletion criteria:
For Node.js projects, load reference/nodejs-security.md and check framework-specific concerns:
helmet(), express-rate-limit, cors allow-list, no X-Powered-By, body size limits, prototype pollution defensesValidationPipe with whitelist + forbidNonWhitelisted, ClassSerializerInterceptor to strip sensitive fields, Guards for authz, helmet middleware, throttler@fastify/helmet, @fastify/rate-limit, @fastify/cors with origin allow-list, schema validation on routes, @fastify/under-pressurenpm audit/Snyk/Socket, non-root container user, event-loop blocking (ReDoS, sync APIs), prototype pollutionCompletion criteria:
When the scope includes CI/CD or deployment, load reference/devsecops.md and verify:
Completion criteria:
| Level | Criteria | Examples |
|---|---|---|
| 🔴 Critical | Immediate, exploitable risk | SQL injection, RCE, exposed secrets, broken auth |
| 🟠 High | Significant concern, likely exploitable | auth bypass, IDOR, missing authz on sensitive data |
| 🟡 Medium | Potential vulnerability | missing validation, weak crypto, verbose errors |
| 🟢 Low | Defense-in-depth improvement | missing security header, better logging |
| ℹ️ Info | Awareness note | version end-of-life, future hardening |
## Executive Summary
- Overall posture: Secure / Needs attention / Critical issues
- N findings: 🔴 x 🟠 x 🟡 x 🟢 x ℹ️ x
- Top recommendations (ordered by impact)
## Findings
### [Severity] Title
- **OWASP**: A03:2021-Injection (and A05:2025 if reclassified)
- **Location**: `src/api/upload.ts:42`
- **Issue**: One-line description
- **Impact**: What an attacker can do
- **Recommendation**: Concrete fix with code snippet or config change
- **Reference**: OWASP Cheat Sheet — File Upload; ASVS v5.0.0-5.2.1
## Positive Practices
- Well-implemented controls worth keepingCite the relevant OWASP category, ASVS requirement ID (e.g. v5.0.0-6.2.3), and Cheat Sheet in each finding so the recommendation is traceable to a standard.
Completion criteria:
git diff, npm audit, cat, grep). If your environment provides an execute() wrapper, prefer it for read-only command execution.reference/owasp-top-10.md).© jellydn, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files in skills/security-audit of jellydn/my-ai-tools.
Open the folder on GitHubat commit 62c9227
Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Audit this skilljellydn/my-ai-tools | 123 | — | ~2.9k | Automated safety check: Notes | MIT | |
| Code Securitysemgrep/skills | 322 | — | ~1.2k | Automated safety check: Pass | Custom licence | |
| Security Reviewgithub/awesome-copilot | 40k | 1 repos | ~2.3k | Automated safety check: Notes | MIT | |
| Security And Hardeningdzhalaevd/Donatello | 135 | — | ~5.1k | Automated safety check: Notes | Apache-2.0 | |
| Discover Securityrand/cc-polymath | 181 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Security Audit Scannerruvnet/ruflo | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT |
semgrep/skills
Security guidelines for writing secure code. An agent skill from semgrep/skills.
github/awesome-copilot
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…
dzhalaevd/Donatello
Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.
rand/cc-polymath
Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management.
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
ZeroDeng01/sublinkPro
Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.
jellydn/my-ai-tools
A skill your agent uses when monitoring an open GitHub PR for CI failures, review feedback, mergeability, and safe retries or fixes.
jellydn/my-ai-tools
Posts a concise visual outline as a GitHub pull request comment.
jellydn/my-ai-tools
Manage project knowledge with qmd — captures learnings, decisions, and conventions
jellydn/my-ai-tools
Generate Product Requirements Documents from feature ideas — plans specs and requirements
jellydn/my-ai-tools
Build an interactive report or experiment when the user asks to explore model capabilities.
jellydn/my-ai-tools
Fix PR review comments by implementing requested changes. An agent skill from jellydn/my-ai-tools.
Works with
Categories
A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance. Security Audit is an agent skill from jellydn/my-ai-tools. Use when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.
Security Audit fits situations like: reviewing code for security vulnerabilities; hardening an application; deriving security requirements from OWASP/ASVS guidance.
Run `npx skills add jellydn/my-ai-tools --skill security-audit -a claude-code`. Or copy the skill folder (skills/security-audit in jellydn/my-ai-tools) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jellydn/my-ai-tools --skill security-audit -a codex`. Or copy the skill folder (skills/security-audit in jellydn/my-ai-tools) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jellydn/my-ai-tools --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.
Going by SKILL.md and its folder, Security Audit needs the command-line tools its instructions call (git, npm and jq). Our summary lists: Node.js. Compatibility (from SKILL.md): cline, claude, opencode, amp, codex, gemini, cursor, pi.
SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Security Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Audit: Code Security (semgrep/skills, 322 stars), Security Review (github/awesome-copilot, 40k stars), Security And Hardening (dzhalaevd/Donatello, 135 stars) and Discover Security (rand/cc-polymath, 181 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jellydn (a GitHub user) maintains it in jellydn/my-ai-tools, which has 123 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 9, 2026.
Source: jellydn/my-ai-tools on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.