Agent skill

Banned API Audit

by jmagly in jmagly/aiwg

Scan source code for banned APIs/forbidden functions per project banlist; report violations with paths, line numbers, and recommended replacements

MITAuto-check passed

Install Banned API Audit

skills CLI
$ npx skills add jmagly/aiwg --skill banned-api-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jmagly/aiwg banned-api-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jmagly/aiwg.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agentic/code/plugins/security-engineering/skills/banned-api-audit .claude/skills/banned-api-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
banned-api-audit
GitHub stars
220
Token cost
~2.2k tokens
SKILL.md length
546 words
Files
10 (incl. scripts)
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Scan source code for banned APIs/forbidden functions per project banlist; report violations with paths, line numbers, and recommended replacements

  • Works in 6 steps: Resolve banlist → Resolve paths and exclusions → Scan with ripgrep → …
  • SKILL.md covers Core Philosophy, Natural Language Triggers, Parameters and Execution Flow, plus 5 more sections
  • Runs JavaScript and Shell scripts from its folder; calls rg

What it does

Banned API Audit is an agent skill from jmagly/aiwg. Scan source code for banned APIs/forbidden functions per project banlist; report violations with paths, line numbers, and recommended replacements

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts (for example `banlists/c.yaml`, `banlists/cpp.yaml` and `banlists/go.yaml`).

It works with C++ and Rust. The repository describes itself as: Cognitive architecture for AI-augmented software development. Specialized agents, structured workflows, and multi-platform deployment. Claude Code · Codex · Copilot · Cursor ·… The licence is MIT.

Example prompts

  • “/banned-api-audit”

Requirements

  • Node.js
  • A Bash shell

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Resolve banlist
  2. Resolve paths and exclusions
  3. Scan with ripgrep
  4. Honor inline allow annotations
  5. Emit report
  6. Exit code

What it can do on your machine

Read from SKILL.md and the folder at commit dda238f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (JavaScript and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • curl.se
    • github.com
    • docs.oasis-open.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Banned API Audit loads about 2.2k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 546 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jmagly/aiwg at commit dda238f, republished under its MIT licence (© jmagly). 546 words, ~2,156 tokens.

Download SKILL.mdSave it as .claude/skills/banned-api-audit/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
banned-api-audit
description
Scan source code for banned APIs/forbidden functions per project banlist; report violations with paths, line numbers, and recommended replacements
namespace
aiwg
platforms
all
invariants
inline AIWG-allow annotations are honored and recorded in the report (never silently dropped), test/**, tests/**, vendor/**, node_modules/**, .aiwg/**…
script.entrypoint
scripts/audit.mjs
script.runtime
node
script.cwd
project-root
script.argsHint
[--starter c|cpp|python|node|go|rust] [--fail-on-violation] [--paths <path>...] [--format text|json|both|sarif]
commandHint.argumentHint
[--starter c|cpp|python|node|go|rust] [--fail-on-violation] [--paths <glob>...] [--format text|json|both|sarif] [--sarif]
commandHint.allowedTools
Read, Write, Bash, Glob, Grep
commandHint.model
haiku

Banned API Audit

You are the Banned API Auditor — scan source code for prohibited functions and APIs declared in the project banlist, report violations with full context, and exit with a CI-suitable status code.

Core Philosophy

"Eliminate CVE classes by construction." Banning a dangerous API is cheaper than vigilance. The audit makes the ban enforceable: every CI run rejects any new occurrence; existing violations are tracked until remediated or explicitly excepted.

Natural Language Triggers

  • "audit banned APIs"
  • "scan for forbidden functions"
  • "check banned-functions policy"
  • "run banlist audit"
  • "check for unsafe C functions"

Parameters

--starter <language> (optional)

Use a bundled starter banlist instead of (or in addition to) the project banlist. Useful for a first-time audit before the project has its own banned-apis.yaml. Valid: c, cpp, python, node, go, rust.

--fail-on-violation (optional)

Exit non-zero when ANY violation is found. Default: exit 0 always (report-only mode for first runs and migration audits).

--paths <glob>... (optional)

Limit the scan to these paths. Overrides paths: declarations in the banlist. Useful for scoped PR audits.

--format text|json|both|sarif (default both)

text to stdout, json to .aiwg/security/banned-api-audit/, or both.

--sarif (optional)

Also emit SARIF 2.1.0 to .aiwg/security/banned-api-audit/ for code-scanning ingest.

Execution Flow

Phase 1: Resolve banlist
  1. Look for .aiwg/security/banned-apis.yaml.

  2. If --starter <lang> is set, merge the bundled starter into the active banlist (project banlist wins on pattern conflict).

  3. If neither exists, emit a guided message:

    No banlist found. Bootstrap with:
      aiwg run skill banned-api-audit -- --starter c
    Or seed your own at .aiwg/security/banned-apis.yaml
Phase 2: Resolve paths and exclusions

Default exclusions (always applied unless --paths overrides):

  • test/**, tests/**, **/*_test.*, **/*.test.*
  • vendor/**, node_modules/**, target/**, dist/**, build/**
  • .git/**, .aiwg/**, .claude/**, .codex/**, .factory/**

Project banlist paths: declarations narrow further (e.g., src/** only).

Phase 3: Scan with ripgrep

For each (language, pattern) pair:

bash
# Word-boundary literal pattern
rg -n --type <lang> -w '<pattern>' <paths>

# Regex pattern (when prefixed re:)
rg -n --type <lang> '<regex>' <paths>

Language → ripgrep --type mapping:

  • c → c
  • cpp → cpp
  • python → py
  • node → js,ts,tsx,jsx
  • go → go
  • rust → rust
Phase 4: Honor inline allow annotations

For each candidate violation, check the source line and the preceding 2 lines for:

AIWG-allow:banned-apis reason="..."

When present, classify as excepted (not a violation). Record the reason in the report so security reviewers can grep all exceptions periodically.

Show full SKILL.md (211 more words)Show less
Phase 5: Emit report

Text report format:

Banned API Audit — 2026-05-21T17:30:00Z

Banlist:    .aiwg/security/banned-apis.yaml (24 patterns across 3 languages)
Paths:      src/, lib/
Excluded:   test/, tests/, vendor/, node_modules/

VIOLATIONS (3)

src/auth/token.c:42:    strcpy(buf, user_input);
  pattern:      strcpy  (language: c)
  reason:       Unbounded copy — buffer overflow vector
  replacement:  strncpy_s, strlcpy, or snprintf with bounds

src/parser/json.c:118:  sprintf(out, "%s/%s", base, path);
  pattern:      sprintf  (language: c)
  reason:       Unbounded format expansion — overflow + format-string risk
  replacement:  snprintf with explicit buffer size

src/util/legacy.py:7:   user = pickle.loads(payload)
  pattern:      re:pickle\.loads?\b  (language: python)
  reason:       Arbitrary code execution on untrusted input
  replacement:  json, msgpack, or signed pickle with integrity check

EXCEPTIONS (1)

src/compat/curses_wrapper.c:33:  char *tok = strtok(buf, " ");
  pattern:  strtok
  reason:   curses interop requires strtok per legacy API contract

SUMMARY
  Violations:  3
  Exceptions:  1
  Patterns:    24
  Files scanned: 184

JSON report (machine-readable, suitable for SARIF conversion or CI dashboard ingest):

json
{
  "schemaVersion": "1",
  "auditedAt": "2026-05-21T17:30:00Z",
  "banlistPath": ".aiwg/security/banned-apis.yaml",
  "patterns": 24,
  "filesScanned": 184,
  "violations": [
    {
      "file": "src/auth/token.c",
      "line": 42,
      "column": 5,
      "match": "strcpy(buf, user_input);",
      "pattern": "strcpy",
      "language": "c",
      "reason": "Unbounded copy — buffer overflow vector",
      "replacement": "strncpy_s, strlcpy, or snprintf with bounds",
      "severity": "HIGH"
    }
  ],
  "exceptions": [ /* same shape, plus exceptionReason */ ]
}
Phase 6: Exit code
  • 0 — no violations, OR violations present but --fail-on-violation not set
  • 1 — banlist missing AND no --starter flag
  • 2 — violations present AND --fail-on-violation set
  • 3 — ripgrep not installed or other tooling failure

CI Integration

Gitea Actions:

yaml
- name: Banned-API audit
  run: aiwg run skill banned-api-audit -- --fail-on-violation

GitHub Actions:

yaml
- name: Banned-API audit
  run: aiwg run skill banned-api-audit -- --fail-on-violation

Starter Banlists

Bundled at banlists/:

  • c.yaml — C dangerous functions (strcpy, sprintf, gets, strtok, atoi)
  • cpp.yaml — C++ overlay (auto_ptr, gets, strcpy)
  • python.yaml — eval, exec, pickle.loads, subprocess shell=True
  • node.yaml — eval, new Function, child_process.exec
  • go.yaml — shell-string commands, weak hashes, HTML templating footguns
  • rust.yaml — unsafe/transmute/unwrap review gates, shell-string commands

Users seed their project banlist via --starter <lang> and customize.

Composing with Crypto Rules

The CRITICAL applied-cryptography rules (no-unauthenticated-encryption, no-adhoc-kdf, no-key-reuse-across-purposes) are enforced separately by their own audit paths. This skill does not replace them; it complements them with HIGH-severity language-level policy.

Implementation

Cycle 2 adds:

  • scripts/audit.sh / scripts/audit.mjs reference implementation.
  • schema.json documenting the banlist YAML shape.
  • Starter banlists for C, C++, Python, Node, Go, and Rust.
  • Text, JSON, and SARIF report output.
  • Exit codes: 0 clean/report-only, 1 banlist/schema problem, 2 violations with --fail-on-violation, 3 tooling failure.

References

© jmagly, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (scripts) in agentic/code/plugins/security-engineering/skills/banned-api-audit of jmagly/aiwg.

  • SKILL.md
  • banlists/c.yaml
  • banlists/cpp.yaml
  • banlists/go.yaml
  • banlists/node.yaml
  • banlists/python.yaml
  • banlists/rust.yaml
  • schema.json
  • scripts/audit.mjs
  • scripts/audit.sh

Open the folder on GitHubat commit dda238f

Compare with similar skills

Banned API Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Banned API Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Banned API Audit this skilljmagly/aiwg220—~2.2kAutomated safety check: PassMIT
Fory Releaseapache/fory4.6k—~2.9kAutomated safety check: PassApache-2.0
SeekDB Code Reviewoceanbase/seekdb3.1k—~2.1kAutomated safety check: PassApache-2.0
Fory Version Bumpapache/fory4.6k—~1.1kAutomated safety check: PassApache-2.0
Add Grammarafnanenayet/diffsitter2.4k—~1.9kAutomated safety check: NotesMIT
Fory Performance Optimizationapache/fory4.6k—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • Fory Release

    apache/fory

    Prepare an Apache Fory release candidate from a clean release branch, including the version bump, RC tag, JVM staging, ASF source artifacts, SVN upload, and vote email.

    4.6k GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • SeekDB Code Review

    oceanbase/seekdb

    Reviews seekdb pull requests and diffs for real defects in correctness, resources, concurrency, security and tests, reporting only Blocker or Major findings.

    3.1k GitHub stars~2.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Bump Apache Fory release or post-release development versions across Java, Kotlin, Scala, Python, Rust, Go, C++, C, Dart, JavaScript, Swift, integration tests, examples, and source docs.

    4.6k GitHub stars~1.1k tokensUpdated yesterday
    MobileAuto-check passed
  • Add Grammar

    afnanenayet/diffsitter

    Step-by-step guide for adding a new tree-sitter language grammar to diffsitter.

    2.4k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Run profile-driven bottleneck optimization across Apache Fory implementations (Java, C++, Python/Cython, Go, Rust, Swift, C, JavaScript/TypeScript, Dart, Kotlin, Scala).

    4.6k GitHub stars~2.2k tokensUpdated yesterday
    MobileAuto-check passed
  • Crossbind

    crossbind/crossbind

    A skill your agent uses when a user wants to call C++ or Rust from JavaScript or TypeScript; add a native library such as GDAL, SQLite, OpenSSL, GEOS or PROJ to a browser, Node.js, Cloudflare Worker…

    148 GitHub stars~1.1k tokensUpdated today
    MobileAuto-check passed

More from jmagly/aiwg

All 11 skills in this repo
  • Review editorial phrase patterns and suggest contextual alternatives; legacy name does not imply authorship detection.

    220 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Voice Apply

    jmagly/aiwg

    Apply a voice profile to transform content. An agent skill from jmagly/aiwg.

    220 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Mutation Test

    jmagly/aiwg

    Run mutation testing to validate test quality beyond code coverage.

    220 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • TDD Enforce

    jmagly/aiwg

    Configure TDD enforcement via pre-commit hooks and CI coverage gates.

    220 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Detect project type, AIWG framework state, team configuration, and active work to summarize status and recommend next actions

    220 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Manage artifact metadata, versioning, ownership, and review history across the SDLC lifecycle

    220 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Works with

Questions about Banned API Audit

What does Banned API Audit do?

Scan source code for banned APIs/forbidden functions per project banlist; report violations with paths, line numbers, and recommended replacements. Banned API Audit is an agent skill from jmagly/aiwg.

How do I install Banned API Audit in Claude Code?

Run `npx skills add jmagly/aiwg --skill banned-api-audit -a claude-code`. Or copy the skill folder (agentic/code/plugins/security-engineering/skills/banned-api-audit in jmagly/aiwg) into .claude/skills/banned-api-audit in your project. Claude Code loads it when a task matches its description.

How do I install Banned API Audit in Codex?

Run `npx skills add jmagly/aiwg --skill banned-api-audit -a codex`. Or copy the skill folder (agentic/code/plugins/security-engineering/skills/banned-api-audit in jmagly/aiwg) into .agents/skills/banned-api-audit in your project. Codex loads it when a task matches its description.

Can I use Banned API Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jmagly/aiwg --skill banned-api-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/banned-api-audit, .gemini/skills/banned-api-audit, .github/skills/banned-api-audit and .opencode/skills/banned-api-audit in your project.

What does Banned API Audit need to run?

Going by SKILL.md and its folder, Banned API Audit needs JavaScript and a shell for the scripts in its folder and the command-line tools its instructions call (rg). Our summary lists: Node.js; A Bash shell.

Does Banned API Audit access the network?

SKILL.md names 3 domains. As links in the text: curl.se, github.com and docs.oasis-open.org. This is read from the text; nothing was executed.

Is Banned API Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Banned API Audit use?

Banned API Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Banned API Audit use?

About 2.2k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Banned API Audit?

Skills that share tags, products or a category with Banned API Audit: Fory Release (apache/fory, 4.6k stars), SeekDB Code Review (oceanbase/seekdb, 3.1k stars), Fory Version Bump (apache/fory, 4.6k stars) and Add Grammar (afnanenayet/diffsitter, 2.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Banned API Audit?

jmagly (a GitHub user) maintains it in jmagly/aiwg, which has 220 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 8, 2026.

Source: jmagly/aiwg on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.