Agent skill

Generating Security Audit Reports

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Generate comprehensive security audit reports for applications and systems.

MITAuto-check passedSecurity

Install Generating Security Audit Reports

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-security-audit-reports -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace generating-security-audit-reports --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/generating-security-audit-reports .claude/skills/generating-security-audit-reports && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
generating-security-audit-reports
GitHub stars
2.8k
Token cost
~1.3k tokens
SKILL.md length
511 words
Files
7 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Generate comprehensive security audit reports for applications and systems.

  • Works in 10 steps: Inventory all available security data… → Parse vulnerability findings and… → Cross-reference each finding against… → …
  • You need to assess security posture
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Calls trivy

What it does

Generating Security Audit Reports is an agent skill from jeremylongshore/tons-of-skills-marketplace. Generate comprehensive security audit reports for applications and systems. Use when you need to assess security posture, identify vulnerabilities, evaluate compliance status, or create formal security documentation. Trigger with phrases like "create security audit report", "generate security assessment", "audit security posture", or "PCI-DSS compliance report".

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts, reference files and assets (for example `assets/README.md`, `references/README.md` and `references/errors.md`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Security review and Healthcare and finance regulation. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • You need to assess security posture
  • Identify vulnerabilities
  • Evaluate compliance status
  • Create formal security documentation

Example prompts

  • “create security audit report”
  • “generate security assessment”
  • “audit security posture”
  • “/generating-security-audit-reports”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Glob, Bash(security-scan:*), Bash(report-gen:*)

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Inventory all available security data sources by scanning ${CLAUDE_SKILL_DIR}/security/ for scanner outputs, log files, and configuration…
  2. Parse vulnerability findings and normalize severity using CVSS 3.1 base scores: Critical (9.0-10.0), High (7.0-8.9), Medium (4.0-6.9), Low…
  3. Cross-reference each finding against applicable compliance controls. Map to specific PCI-DSS requirements (e.g., Req 6.5 for injection…
  4. Deduplicate findings across scanners and merge related vulnerabilities into consolidated entries with all affected assets listed.
  5. Classify access control weaknesses, encryption gaps, and authentication deficiencies into separate report sections.
  6. Generate an executive summary including total findings by severity, overall risk score, and top-5 critical remediation priorities.
  7. Build a detailed findings table: finding ID, CWE number, affected component, CVSS score, compliance mapping, remediation steps, and…
  8. Produce a compliance status matrix showing pass/fail/partial for each applicable standard requirement.
  9. Create remediation recommendations with effort estimates (hours), priority ranking, and suggested timelines.
  10. Format the final report as Markdown to ${CLAUDE_SKILL_DIR}/reports/security-audit-YYYYMMDD.md. Optionally produce JSON for Jira/ServiceNow…

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Glob
    • Bash(security-scan:*)
    • Bash(report-gen:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • trivy

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • owasp.org
    • cwe.mitre.org
    • nist.gov
    • pcisecuritystandards.org
    • first.org
    • intentsolutions.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Generating Security Audit Reports loads about 1.3k tokens when it runs, and up to ~2.1k if it reads all its reference files. Until then it costs about 100 tokens; SKILL.md has 511 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 511 words, ~1,316 tokens.

Download SKILL.mdSave it as .claude/skills/generating-security-audit-reports/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
generating-security-audit-reports
description
Generate comprehensive security audit reports for applications and systems. Use when you need to assess security posture, identify vulnerabilities, evaluate compliance status, or create formal security documentation. Trigger with phrases like "create security audit report", "generate security assessment", "audit security posture", or "PCI-DSS compliance report".
allowed-tools
Read, Write, Edit, Grep, Glob, Bash(security-scan:*), Bash(report-gen:*)
compatibility
Designed for Claude Code
version
1.28.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
security, compliance, audit

Generating Security Audit Reports

Overview

Aggregate vulnerability scan results, configuration analyses, and compliance assessments into a structured, auditor-ready security report. Map every finding to a CVSS severity, applicable compliance control (PCI-DSS, HIPAA, SOC 2, GDPR), and a prioritized remediation timeline.

Prerequisites

  • Vulnerability scanner outputs (Nmap, Nessus, OpenVAS, OWASP ZAP) available in ${CLAUDE_SKILL_DIR}/security/
  • Application and infrastructure configuration files accessible
  • SAST/DAST tool results (e.g., Semgrep, Snyk, Trivy, Bandit)
  • Applicable compliance framework documentation identified (PCI-DSS v4.0, HIPAA Security Rule, SOC 2 TSC, GDPR)
  • Write permissions for report output directory ${CLAUDE_SKILL_DIR}/reports/

Instructions

  1. Inventory all available security data sources by scanning ${CLAUDE_SKILL_DIR}/security/ for scanner outputs, log files, and configuration exports.
  2. Parse vulnerability findings and normalize severity using CVSS 3.1 base scores: Critical (9.0-10.0), High (7.0-8.9), Medium (4.0-6.9), Low (0.1-3.9).
  3. Cross-reference each finding against applicable compliance controls. Map to specific PCI-DSS requirements (e.g., Req 6.5 for injection flaws), HIPAA safeguards, or SOC 2 Common Criteria.
  4. Deduplicate findings across scanners and merge related vulnerabilities into consolidated entries with all affected assets listed.
  5. Classify access control weaknesses, encryption gaps, and authentication deficiencies into separate report sections.
  6. Generate an executive summary including total findings by severity, overall risk score, and top-5 critical remediation priorities.
  7. Build a detailed findings table: finding ID, CWE number, affected component, CVSS score, compliance mapping, remediation steps, and evidence links.
  8. Produce a compliance status matrix showing pass/fail/partial for each applicable standard requirement.
  9. Create remediation recommendations with effort estimates (hours), priority ranking, and suggested timelines.
  10. Format the final report as Markdown to ${CLAUDE_SKILL_DIR}/reports/security-audit-YYYYMMDD.md. Optionally produce JSON for Jira/ServiceNow import.

See ${CLAUDE_SKILL_DIR}/references/implementation.md for the detailed four-phase implementation workflow.

Output

  • Audit Report: ${CLAUDE_SKILL_DIR}/reports/security-audit-YYYYMMDD.md containing executive summary, detailed findings, compliance matrix, and remediation plan
  • Findings JSON: Machine-readable findings for ticketing system import
  • Compliance Matrix: Per-requirement pass/fail/partial status for each applicable framework
  • Remediation Backlog: Prioritized list with effort estimates and owner assignments
Show full SKILL.md (199 more words)Show less

Error Handling

ErrorCauseSolution
No security scan results foundScanner outputs missing from ${CLAUDE_SKILL_DIR}/security/Specify alternate data source paths or run preliminary scans with nmap -sV or trivy fs .
Cannot assess compliance -- requirements unavailableCompliance framework checklist not providedFall back to OWASP Top 10 and CWE Top 25 as baseline; note limitation in report
Permission denied reading config filesInsufficient filesystem accessRequest elevated permissions or provide exported configuration snapshots
Scan results exceed processing capacityThousands of findings from multiple scannersProcess in batches by severity (Critical/High first), then merge
Conflicting severity ratings across scannersDifferent tools score the same vulnerability differentlyUse CVSS 3.1 base score as canonical severity; note discrepancies in appendix

Examples

  • "Generate a SOC 2 security audit report for the API using scan results in ${CLAUDE_SKILL_DIR}/security/."
  • "Create a PCI-DSS compliance-focused security assessment with a prioritized remediation plan for all Critical and High findings."
  • "Produce a HIPAA security audit from the Nessus and Trivy outputs, mapping each finding to the relevant HIPAA safeguard."

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references, assets) in skills/.curated/generating-security-audit-reports of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • references/README.md
  • references/errors.md
  • references/examples.md
  • references/implementation.md
  • scripts/README.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Generating Security Audit Reports next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Generating Security Audit Reports compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Generating Security Audit Reports this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: PassMIT
Senior Secopsalirezarezvani/claude-skills28k1 repos~4kAutomated safety check: PassMIT
Senior Secopsborghei/Claude-Skills891—~1.7kAutomated safety check: PassMIT
Data Breach Blast Radiusgithub/awesome-copilot40k1 repos~3.6kAutomated safety check: NotesMIT
Security Auditorcuriositech/some_claude_skills244—~2.2kAutomated safety check: PassMIT
AI SAFE2 Secure Build CopilotCyberStrategyInstitute/ai-safe2-framework147—~1.2kAutomated safety check: PassCustom licence

Similar skills

  • Senior Secops

    alirezarezvani/claude-skills

    Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices.

    28k GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed
  • Senior Secops

    borghei/Claude-Skills

    SecOps for application security, vulnerability management, compliance, and secure development.

    891 GitHub stars~1.7k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Data Breach Blast Radius

    github/awesome-copilot

    Official

    Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges…

    40k GitHub starsUsed in 1 repo~3.6k tokens
    Legal & ComplianceAuto-check: notes
  • Security Auditor

    curiositech/some_claude_skills

    Security vulnerability scanner and OWASP compliance auditor for codebases.

    244 GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • AI SAFE2 Secure Build Copilot

    CyberStrategyInstitute/ai-safe2-framework

    Applies the AI SAFE2 framework to security reviews, code reviews and compliance mapping for AI agents, RAG pipelines and MCP servers.

    147 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check passed
  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 10 days ago
    SecurityAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Generating Security Audit Reports

What does Generating Security Audit Reports do?

Generate comprehensive security audit reports for applications and systems. Generating Security Audit Reports is an agent skill from jeremylongshore/tons-of-skills-marketplace. Generate comprehensive security audit reports for applications and systems.

When should I use Generating Security Audit Reports?

Generating Security Audit Reports fits situations like: you need to assess security posture; identify vulnerabilities; evaluate compliance status; create formal security documentation.

How do I install Generating Security Audit Reports in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-security-audit-reports -a claude-code`. Or copy the skill folder (skills/.curated/generating-security-audit-reports in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/generating-security-audit-reports in your project. Claude Code loads it when a task matches its description.

How do I install Generating Security Audit Reports in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-security-audit-reports -a codex`. Or copy the skill folder (skills/.curated/generating-security-audit-reports in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/generating-security-audit-reports in your project. Codex loads it when a task matches its description.

Can I use Generating Security Audit Reports in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-security-audit-reports -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/generating-security-audit-reports, .gemini/skills/generating-security-audit-reports, .github/skills/generating-security-audit-reports and .opencode/skills/generating-security-audit-reports in your project.

What does Generating Security Audit Reports need to run?

Going by SKILL.md and its folder, Generating Security Audit Reports needs the command-line tools its instructions call (trivy). Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(security-scan:*), Bash(report-gen:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Generating Security Audit Reports access the network?

SKILL.md names 6 domains. As links in the text: owasp.org, cwe.mitre.org, nist.gov, pcisecuritystandards.org, first.org and intentsolutions.io. This is read from the text; nothing was executed.

Is Generating Security Audit Reports safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Generating Security Audit Reports use?

Generating Security Audit Reports is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Generating Security Audit Reports use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 764 tokens, read only when the agent opens those files.

What are the alternatives to Generating Security Audit Reports?

Skills that share tags, products or a category with Generating Security Audit Reports: Senior Secops (alirezarezvani/claude-skills, 28k stars), Senior Secops (borghei/Claude-Skills, 891 stars), Data Breach Blast Radius (github/awesome-copilot, 40k stars) and Security Auditor (curiositech/some_claude_skills, 244 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Generating Security Audit Reports?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.