Agent skill

Security Audit

by jellydn in jellydn/my-ai-tools

A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

MITAuto-check: notesSecurity

Install Security Audit

skills CLI
$ npx skills add jellydn/my-ai-tools --skill security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jellydn/my-ai-tools security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jellydn/my-ai-tools.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-audit .claude/skills/security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-audit
GitHub stars
123
Token cost
~2.9k tokens
SKILL.md length
1,191 words
Files
6
Skills in repo
33
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

  • Works in 5 steps: Scope and gather context → Run the checklist → Framework-specific checks → …
  • Reviewing code for security vulnerabilities
  • SKILL.md covers Usage, Knowledge Base, Audit Process and Guidelines
  • Calls git, npm and jq

What it does

Security Audit is an agent skill from jellydn/my-ai-tools. Use when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files (for example `reference/devsecops.md`, `reference/nodejs-security.md` and `reference/owasp-asvs.md`). Compatibility notes: cline, claude, opencode, amp, codex, gemini, cursor, pi

It sits in Security, covering Security review, Secure coding and Cryptography. It works with Node.js. The repository describes itself as: Comprehensive configuration management for AI coding tools - Replicate my complete setup for Claude Code, OpenCode, Amp, Li, Codex and Claude Code Switch with custom… The licence is MIT.

When your agent uses it

  • Reviewing code for security vulnerabilities
  • Hardening an application
  • Deriving security requirements from OWASP/ASVS guidance

Example prompts

  • “/security-audit”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): cline, claude, opencode, amp, codex, gemini, cursor, pi

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Scope and gather context
  2. Run the checklist
  3. Framework-specific checks
  4. Pipeline & deployment checks
  5. Rank findings and report

What it can do on your machine

Read from SKILL.md and the folder at commit 62c9227. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • npm
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    cline, claude, opencode, amp, codex, gemini, cursor, pi

    From compatibility in the SKILL.md frontmatter.

Context cost

Security Audit loads about 2.9k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 1,191 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:60
    *.yaml' -o -name 'Dockerfile*' -o -name '.env*' \) -not -path './node_modules/*'

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jellydn/my-ai-tools at commit 62c9227, republished under its MIT licence (© jellydn). 1,191 words, ~2,901 tokens.

Download SKILL.mdSave it as .claude/skills/security-audit/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
security-audit
description
Use when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.
compatibility
cline, claude, opencode, amp, codex, gemini, cursor, pi
license
MIT
hint
Use when auditing code for security vulnerabilities or hardening an application
user-invocable
true
metadata.audience
all
metadata.workflow
security

Security Audit

Perform a structured security audit of code, configuration, and architecture. Identify vulnerabilities, rank them by severity, and recommend concrete fixes grounded in OWASP standards, framework-specific best practices, and DevSecOps controls.

This is a read-only analysis. Do not modify code — audit, then report.

Usage

bash
/security-audit [scope]
  • With no argument, audit the current branch's diff against the default branch.
  • With a path or module name, audit that scope.
  • Use full to audit the whole repository for systemic issues.

Knowledge Base

The audit draws on five reference areas. Load the relevant reference file when a finding needs grounding or when you need detailed requirements for a topic:

AreaReferenceWhen to load
OWASP Top 10reference/owasp-top-10.mdClassifying a finding against the major vulnerability categories (2021 + 2025)
OWASP ASVSreference/owasp-asvs.mdDeriving concrete security requirements or building a verification checklist
OWASP Cheat Sheet Seriesreference/owasp-cheat-sheets.mdNeeding practical implementation guidance (auth, JWT, file upload, CSRF, password storage)
Node.js Securityreference/nodejs-security.mdAuditing Express, NestJS, Fastify, or Node.js dependency/supply-chain issues
DevSecOpsreference/devsecops.mdReviewing CI/CD pipeline security, dependency/container/secret/SAST/DAST scanning

Use progressive disclosure: keep the reference files unloaded until a finding maps to them. Load only the file the current finding needs.

Audit Process

1. Scope and gather context
bash
# Detect the default branch
BASE_BRANCH=$(git remote show origin 2>/dev/null | grep 'HEAD branch' | awk '{print $NF}' || echo main)

# Diff under audit
git diff "$BASE_BRANCH"...HEAD --stat
git diff "$BASE_BRANCH"...HEAD

# Dependency surface
cat package.json 2>/dev/null | jq '.dependencies, .devDependencies'
npm audit --json 2>/dev/null | jq '.metadata.vulnerabilities' 2>/dev/null

# Configuration surface
find . -maxdepth 2 \( -name '*.yml' -o -name '*.yaml' -o -name 'Dockerfile*' -o -name '.env*' \) -not -path './node_modules/*'

For a full audit, also enumerate: auth/session code, input handlers, file upload paths, database query construction, crypto usage, CI/CD workflow files, and container definitions.

Completion criteria:

  • Default branch and diff under audit are identified.
  • Dependency and configuration surfaces are enumerated for the selected scope.
  • For full audits, the additional security-critical code paths are listed.
2. Run the checklist

Walk every changed or in-scope file against this checklist. Each item maps to an OWASP Top 10 category — use reference/owasp-top-10.md for the full category definitions and examples.

Input validation & injection (A03:2021 Injection, A05:2025 Injection; A02:2021 Cryptographic Failures, A04:2025 Cryptographic Failures)
  • All external input (body, query, params, headers, cookies) is validated with an allow-list schema (zod, joi, ajv, class-validator)
  • SQL/NoSQL queries use parameterized queries or ORM builders — no string concatenation
  • OS command execution avoids exec/spawn with user input; uses argument arrays
  • Output encoding is applied contextually (HTML, JS, URL, CSS) to prevent XSS
  • Template engines use auto-escaping; dangerouslySetInnerHTML/v-html/|raw justified and sanitized
  • Path traversal prevented — user input never reaches file path construction unsanitized
  • SSRF prevented — outbound URLs validated against an allow-list, internal IPs blocked
Authentication & session (A07:2021 Identification and Authentication Failures, A07:2025 Authentication Failures)
  • Passwords hashed with bcrypt/argon2/scrypt — never MD5/SHA1/plain text
  • MFA available; credential recovery does not leak account existence
  • Session IDs are high-entropy, rotated on login, invalidated on logout
  • JWTs (if used) verified for signature, expiry, audience; secrets strong and rotated — see reference/owasp-cheat-sheets.md
  • Brute-force protection (rate limiting, lockout) on auth endpoints
  • No default or weak credentials
Authorization & access control (A01:2021 Broken Access Control, A01:2025 Broken Access Control)
  • Deny by default; explicit allow on every protected resource
  • Object-level (IDOR) checks — user cannot access other users' records by ID
  • Role checks at the right layer (middleware/guard), not scattered in handlers
  • No privilege escalation paths; admin functions gated
  • CORS configured with an explicit origin allow-list — never * with credentials
Data protection & cryptography (A02:2021 Cryptographic Failures, A04:2025 Cryptographic Failures; A08:2021/2025 Software and Data Integrity Failures)
  • TLS enforced everywhere; HSTS enabled; weak ciphers disabled
  • Sensitive data encrypted at rest; secrets in a vault/env, never committed
  • No sensitive data in logs, error messages, or URLs
  • Strong algorithms only (AES-GCM, ChaCha20); no deprecated crypto (DES, RC4, ECB)
  • Random values use crypto.randomUUID()/crypto.randomBytes() — never Math.random() for security
  • Deserialization of untrusted data avoided or integrity-checked
Configuration & dependencies (A05:2021 Security Misconfiguration, A02:2025 Security Misconfiguration; A06:2021 Vulnerable and Outdated Components, A03:2025 Software Supply Chain Failures; A04:2021/A06:2025 Insecure Design)
  • No hardcoded secrets, tokens, or API keys — see reference/devsecops.md for secret scanning
  • Debug/verbose error pages disabled in production; stack traces not exposed
  • Security headers present (CSP, HSTS, X-Frame-Options, X-Content-Type-Options) — helmet/ equivalents
  • Dependencies pinned and audited; no known high/critical CVEs
  • npm ci used in CI; lockfile committed; --ignore-scripts considered
  • File uploads validated (type, size, content); stored outside web root — see reference/owasp-cheat-sheets.md
  • Rate limiting on API and auth endpoints
Logging & error handling (A09:2021 Security Logging and Monitoring Failures, A09:2025 Security Logging and Alerting Failures; A10:2025 Mishandling of Exceptional Conditions)
  • Security events logged (auth failures, access denials, input validation failures)
  • Logs do not contain passwords, tokens, or PII
  • Errors fail closed (deny) not open (allow) on unexpected conditions
  • Generic error messages to users; details server-side only
  • NULL/missing-parameter paths handled, not crashing or leaking info

Completion criteria:

  • Every changed or in-scope file is checked against all relevant checklist sections.
  • Each unchecked item is either confirmed not applicable or recorded as a finding.
Show full SKILL.md (442 more words)Show less
3. Framework-specific checks

For Node.js projects, load reference/nodejs-security.md and check framework-specific concerns:

  • Express: helmet(), express-rate-limit, cors allow-list, no X-Powered-By, body size limits, prototype pollution defenses
  • NestJS: ValidationPipe with whitelist + forbidNonWhitelisted, ClassSerializerInterceptor to strip sensitive fields, Guards for authz, helmet middleware, throttler
  • Fastify: @fastify/helmet, @fastify/rate-limit, @fastify/cors with origin allow-list, schema validation on routes, @fastify/under-pressure
  • All: dependency pinning, npm audit/Snyk/Socket, non-root container user, event-loop blocking (ReDoS, sync APIs), prototype pollution

Completion criteria:

  • The active framework stack is identified.
  • Matching framework checks are reviewed and any gaps are captured as findings.
4. Pipeline & deployment checks

When the scope includes CI/CD or deployment, load reference/devsecops.md and verify:

  • Dependency scanning (npm audit / Snyk / Dependabot / Trivy) runs in CI and gates on high/critical
  • Secret scanning (Gitleaks pre-commit, TruffleHog in CI) prevents leaked credentials
  • Container scanning (Trivy / Grype) on built images; base image minimal (distroless/slim)
  • SAST (Semgrep / CodeQL) runs on PRs; results triaged
  • DAST (OWASP ZAP) against staging on deploys
  • IaC scanning (Checkov / tfsec) on Terraform/K8s manifests
  • Least privilege: non-root container, read-only FS, dropped capabilities
  • SBOM generated (CycloneDX / SPDX) for supply-chain traceability

Completion criteria:

  • CI/CD and deployment controls in scope are reviewed against this checklist.
  • Missing controls are documented with severity and remediation guidance.
5. Rank findings and report
Severity
LevelCriteriaExamples
🔴 CriticalImmediate, exploitable riskSQL injection, RCE, exposed secrets, broken auth
🟠 HighSignificant concern, likely exploitableauth bypass, IDOR, missing authz on sensitive data
🟡 MediumPotential vulnerabilitymissing validation, weak crypto, verbose errors
🟢 LowDefense-in-depth improvementmissing security header, better logging
ℹ️ InfoAwareness noteversion end-of-life, future hardening
Output format
markdown
## Executive Summary

- Overall posture: Secure / Needs attention / Critical issues
- N findings: 🔴 x  🟠 x  🟡 x  🟢 x  ℹ️ x
- Top recommendations (ordered by impact)

## Findings

### [Severity] Title
- **OWASP**: A03:2021-Injection (and A05:2025 if reclassified)
- **Location**: `src/api/upload.ts:42`
- **Issue**: One-line description
- **Impact**: What an attacker can do
- **Recommendation**: Concrete fix with code snippet or config change
- **Reference**: OWASP Cheat Sheet — File Upload; ASVS v5.0.0-5.2.1

## Positive Practices

- Well-implemented controls worth keeping

Cite the relevant OWASP category, ASVS requirement ID (e.g. v5.0.0-6.2.3), and Cheat Sheet in each finding so the recommendation is traceable to a standard.

Completion criteria:

  • Every finding has severity, location, impact, recommendation, and standard references.
  • Executive summary totals match the findings list.

Guidelines

  • Be concrete: every finding needs a fix the developer can act on, not just a description of the problem.
  • Map to standards: cite the OWASP Top 10 category and, where relevant, the ASVS requirement ID and Cheat Sheet. This makes findings auditable and educational.
  • Verify, don't assume: read the actual code before flagging. A pattern that looks vulnerable may be mitigated elsewhere — confirm the mitigation is missing before reporting.
  • Prioritize by exploitability: a Critical finding that requires no auth and is internet-reachable outranks a theoretical issue behind admin auth.
  • Stay read-only: never modify code during an audit. Use inspection-only commands (git diff, npm audit, cat, grep). If your environment provides an execute() wrapper, prefer it for read-only command execution.
  • Note the version: when citing OWASP Top 10, state whether you are using the 2021 or 2025 edition — they differ (see reference/owasp-top-10.md).

© jellydn, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files in skills/security-audit of jellydn/my-ai-tools.

  • SKILL.md
  • reference/devsecops.md
  • reference/nodejs-security.md
  • reference/owasp-asvs.md
  • reference/owasp-cheat-sheets.md
  • reference/owasp-top-10.md

Open the folder on GitHubat commit 62c9227

Compare with similar skills

Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Audit this skilljellydn/my-ai-tools123—~2.9kAutomated safety check: NotesMIT
Code Securitysemgrep/skills322—~1.2kAutomated safety check: PassCustom licence
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Security And Hardeningdzhalaevd/Donatello135—~5.1kAutomated safety check: NotesApache-2.0
Discover Securityrand/cc-polymath181—~1.9kAutomated safety check: PassMIT
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT

Similar skills

  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    322 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Security And Hardening

    dzhalaevd/Donatello

    Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.

    135 GitHub stars~5.1k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Discover Security

    rand/cc-polymath

    Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management.

    181 GitHub stars~1.9k tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Security Review Checklist

    ZeroDeng01/sublinkPro

    Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

    1.7k GitHub stars~2.3k tokensUpdated today
    SecurityAuto-check passed

More from jellydn/my-ai-tools

All 33 skills in this repo
  • Babysit PR

    jellydn/my-ai-tools

    A skill your agent uses when monitoring an open GitHub PR for CI failures, review feedback, mergeability, and safe retries or fixes.

    123 GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Visual PR

    jellydn/my-ai-tools

    Posts a concise visual outline as a GitHub pull request comment.

    123 GitHub stars~764 tokensUpdated today
    Auto-check passed
  • Qmd Knowledge

    jellydn/my-ai-tools

    Manage project knowledge with qmd — captures learnings, decisions, and conventions

    123 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Prd

    jellydn/my-ai-tools

    Generate Product Requirements Documents from feature ideas — plans specs and requirements

    123 GitHub starsUsed in 4 repos~1.8k tokens
    Auto-check passed
  • Capability Experiments

    jellydn/my-ai-tools

    Build an interactive report or experiment when the user asks to explore model capabilities.

    123 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • PR Review

    jellydn/my-ai-tools

    Fix PR review comments by implementing requested changes. An agent skill from jellydn/my-ai-tools.

    123 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Security Audit

What does Security Audit do?

A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance. Security Audit is an agent skill from jellydn/my-ai-tools. Use when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

When should I use Security Audit?

Security Audit fits situations like: reviewing code for security vulnerabilities; hardening an application; deriving security requirements from OWASP/ASVS guidance.

How do I install Security Audit in Claude Code?

Run `npx skills add jellydn/my-ai-tools --skill security-audit -a claude-code`. Or copy the skill folder (skills/security-audit in jellydn/my-ai-tools) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Security Audit in Codex?

Run `npx skills add jellydn/my-ai-tools --skill security-audit -a codex`. Or copy the skill folder (skills/security-audit in jellydn/my-ai-tools) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.

Can I use Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jellydn/my-ai-tools --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.

What does Security Audit need to run?

Going by SKILL.md and its folder, Security Audit needs the command-line tools its instructions call (git, npm and jq). Our summary lists: Node.js. Compatibility (from SKILL.md): cline, claude, opencode, amp, codex, gemini, cursor, pi.

Does Security Audit access the network?

SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Audit use?

Security Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Audit use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Audit?

Skills that share tags, products or a category with Security Audit: Code Security (semgrep/skills, 322 stars), Security Review (github/awesome-copilot, 40k stars), Security And Hardening (dzhalaevd/Donatello, 135 stars) and Discover Security (rand/cc-polymath, 181 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Audit?

jellydn (a GitHub user) maintains it in jellydn/my-ai-tools, which has 123 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 9, 2026.

Source: jellydn/my-ai-tools on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.