Full security audit — secrets, dependencies, IAM, auth, injection, XSS, HTTPS, rate limiting, public storage.

MITAuto-check: notesSecurity

Install Warden Audit

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace warden-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ai-agency/tonone/skills/warden-audit .claude/skills/warden-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
warden-audit
GitHub stars
2.8k
Token cost
~910 tokens
SKILL.md length
367 words
Files
2
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Full security audit — secrets, dependencies, IAM, auth, injection, XSS, HTTPS, rate limiting, public storage.

  • Works in 6 steps: Detect Environment → Scan for Hardcoded Secrets → Scan Dependencies → …
  • Asked for security audit
  • SKILL.md covers Steps and Delivery
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Warden Audit is an agent skill from jeremylongshore/tons-of-skills-marketplace. Full security audit — secrets, dependencies, IAM, auth, injection, XSS, HTTPS, rate limiting, public storage. Use when asked for "security audit", "check for vulnerabilities", "security review", or "are we secure".

Its SKILL.md is about 910 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `.claude-plugin/plugin.json`).

It sits in Security, covering Security review, Web application vulnerabilities and Rate limiting. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Asked for security audit
  • Check for vulnerabilities
  • Security review

Example prompts

  • “security audit”
  • “check for vulnerabilities”
  • “security review”
  • “/warden-audit”

Requirements

  • Pre-approved tools (allowed-tools): Read, Bash, Glob, Grep, WebFetch, WebSearch, AskUserQuestion

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Detect Environment
  2. Scan for Hardcoded Secrets
  3. Scan Dependencies
  4. Check IAM and Access Control
  5. Check Application Security
  6. Report by Severity

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash
    • Glob
    • Grep
    • WebFetch
    • WebSearch
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Warden Audit loads about 910 tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 367 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~910

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:32
    ns, passwords in source files (not just `.env`)
  • NoteMentions a .env fileSKILL.md:34
    - Check `.env` files committed to git (should be in `.gitignore`)
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Bash, Glob, Grep, WebFetch, WebSearch, AskUserQuestion

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 367 words, ~910 tokens.

Download SKILL.mdSave it as .claude/skills/warden-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
warden-audit
description
Full security audit — secrets, dependencies, IAM, auth, injection, XSS, HTTPS, rate limiting, public storage. Use when asked for "security audit", "check for vulnerabilities", "security review", or "are we secure".
allowed-tools
Read, Bash, Glob, Grep, WebFetch, WebSearch, AskUserQuestion
version
0.6.4
author
tonone-ai <hello@tonone.ai>
license
MIT

Full Security Audit

You are Warden — the security engineer on the Engineering Team.

Steps

Step 0: Detect Environment

Identify the project's stack and security posture:

  • Check for frameworks: package.json, requirements.txt, go.mod, Cargo.toml, Gemfile
  • Check for cloud platform: GCP, AWS, Azure configs (gcloud, aws, Terraform, Pulumi files)
  • Check for auth: middleware, JWT configs, session management, OAuth setup
  • Check for CI/CD: .github/workflows/, Dockerfile, cloudbuild.yaml
  • Check for dependency lock files: package-lock.json, yarn.lock, poetry.lock, Pipfile.lock, go.sum

If the stack is ambiguous, ask the user.

Step 1: Scan for Hardcoded Secrets

Search the codebase for exposed secrets:

  • API keys, tokens, passwords in source files (not just .env)
  • Patterns: sk-, AKIA, ghp_, Bearer , base64-encoded credentials
  • Check .env files committed to git (should be in .gitignore)
  • Check CI/CD configs for inline secrets
  • Check for private keys (.pem, .key files)
Step 2: Scan Dependencies

Check for vulnerable dependencies:

  • Read lock files and check for known CVEs
  • Look for outdated major versions with known security issues
  • Check for typosquatting risks (similar package names)
  • Verify dependency sources (no private registries without auth)
Step 3: Check IAM and Access Control

Review access control configuration:

  • IAM roles and policies — any wildcards or overly permissive?
  • Service accounts — shared across services? Over-privileged?
  • API keys — rotated? Scoped? Rate-limited?
  • Admin access — who has it? Is it justified?
Show full SKILL.md (156 more words)Show less
Step 4: Check Application Security

Review application code for common vulnerabilities:

  • Auth on endpoints — are all sensitive endpoints protected?
  • SQL injection — raw SQL with string interpolation?
  • XSS — unescaped user input rendered in HTML?
  • CSRF — forms without CSRF tokens?
  • HTTPS — is TLS enforced? Any HTTP fallbacks?
  • Rate limiting — present on auth endpoints and public APIs?
  • Security headers — HSTS, CSP, X-Frame-Options, X-Content-Type-Options?
  • CORS — overly permissive? Allows all origins?
  • Public storage — S3 buckets, GCS buckets, or blobs publicly accessible?
Step 5: Report by Severity

Follow the output format defined in docs/output-kit.md — 40-line CLI max, box-drawing skeleton, unified severity indicators, compressed prose.

## Security Audit Report

### Critical
- [issue] — [location] — [fix]

### Warning
- [issue] — [location] — [fix]

### Info
- [observation] — [recommendation]

### Summary
| Category | Status |
|---|---|
| Secrets | [status] |
| Dependencies | [status] |
| IAM | [status] |
| Auth | [status] |
| Injection | [status] |
| Headers | [status] |
| Rate Limiting | [status] |
| Storage | [status] |

Use severity indicators: Critical for actively exploitable issues, Warning for weaknesses that increase risk, Info for best-practice improvements.

Delivery

If output exceeds the 40-line CLI budget, invoke /atlas-report with the full findings. The HTML report is the output. CLI is the receipt — box header, one-line verdict, top 3 findings, and the report path. Never dump analysis to CLI.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in plugins/ai-agency/tonone/skills/warden-audit of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • .claude-plugin/plugin.json

Open the folder on GitHubat commit cfae287

Compare with similar skills

Warden Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Warden Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Warden Audit this skilljeremylongshore/tons-of-skills-marketplace2.8k—~910Automated safety check: NotesMIT
API Security ReviewOWASP/secure-agent-playbook188—~744Automated safety check: PassCC-BY-4.0
Security Reviewaffaan-m/ECC277k1 repos~3.2kAutomated safety check: NotesMIT
MCP Implementation Security Reviewgithub/awesome-copilot40k—~5.2kAutomated safety check: PassMIT
Better Auth Security Best PracticesEpicenterHQ/epicenter4.8k—~896Automated safety check: PassCustom licence
API Security Best Practicesdavila7/claude-code-templates33k8 repos~5.8kAutomated safety check: PassMIT

Similar skills

  • API Security Review

    OWASP/secure-agent-playbook

    Comprehensive API security review against OWASP API Security Top 10 (2023).

    188 GitHub stars~744 tokensUpdated 16 days ago
    SecurityAuto-check passed
  • Security Review

    affaan-m/ECC

    Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın.

    277k GitHub starsUsed in 1 repo~3.2k tokens
    SecurityAuto-check: notes
  • Official

    Review the implementation source code of MCP (Model Context Protocol) servers, clients, and tool handlers against a security baseline — authentication, sessions, rate limiting, input-schema…

    40k GitHub stars~5.2k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • API Security Best Practices

    davila7/claude-code-templates

    Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities

    33k GitHub starsUsed in 8 repos~5.8k tokens
    Backend & APIsAuto-check passed
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated 2 days ago
    SecurityAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Warden Audit

What does Warden Audit do?

Full security audit — secrets, dependencies, IAM, auth, injection, XSS, HTTPS, rate limiting, public storage. Warden Audit is an agent skill from jeremylongshore/tons-of-skills-marketplace. Full security audit — secrets, dependencies, IAM, auth, injection, XSS, HTTPS, rate limiting, public storage.

When should I use Warden Audit?

Warden Audit fits situations like: asked for security audit; check for vulnerabilities; security review.

How do I install Warden Audit in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-audit -a claude-code`. Or copy the skill folder (plugins/ai-agency/tonone/skills/warden-audit in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/warden-audit in your project. Claude Code loads it when a task matches its description.

How do I install Warden Audit in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-audit -a codex`. Or copy the skill folder (plugins/ai-agency/tonone/skills/warden-audit in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/warden-audit in your project. Codex loads it when a task matches its description.

Can I use Warden Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/warden-audit, .gemini/skills/warden-audit, .github/skills/warden-audit and .opencode/skills/warden-audit in your project.

What does Warden Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Warden Audit is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Bash, Glob, Grep, WebFetch, WebSearch, AskUserQuestion.

Does Warden Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Warden Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Warden Audit use?

Warden Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Warden Audit use?

About 910 tokens (SKILL.md is roughly 3.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Warden Audit?

Skills that share tags, products or a category with Warden Audit: API Security Review (OWASP/secure-agent-playbook, 188 stars), Security Review (affaan-m/ECC, 277k stars), MCP Implementation Security Review (github/awesome-copilot, 40k stars) and Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Warden Audit?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.