Agent skill

Security Auditor

by LeoYeAI in LeoYeAI/openclaw-master-skills

A skill your agent uses when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation…

MITAuto-check: notesSecurity

Install Security Auditor

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill security-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills security-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-auditor .claude/skills/security-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-auditor
GitHub stars
2.2k
Token cost
~2.8k tokens
SKILL.md length
443 words
Files
1
Skills in repo
972
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation…

  • Works in 5 steps: Broken Access Control (A01:2021) → Cryptographic Failures (A02:2021) → Injection (A03:2021) → …
  • Reviewing code for security vulnerabilities
  • SKILL.md covers Role Definition, Audit Process, Core Principles and OWASP Top 10 Checklist, plus 7 more sections
  • Calls npm and npx; needs API_KEY and JWT_SECRET

What it does

Security Auditor is an agent skill from LeoYeAI/openclaw-master-skills. Use when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation, SQL injection prevention, XSS protection, or any security-related code review.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities and Authentication. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.

When your agent uses it

  • Reviewing code for security vulnerabilities
  • Implementing authentication flows
  • Auditing OWASP Top 10
  • Configuring CORS/CSP headers

Example prompts

  • “/security-auditor”

Requirements

  • Node.js
  • A credential in JWT_SECRET
  • A credential in API_KEY

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Broken Access Control (A01:2021)
  2. Cryptographic Failures (A02:2021)
  3. Injection (A03:2021)
  4. Cross-Site Scripting (XSS) (A07:2021)
  5. Security Misconfiguration (A05:2021)

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY
    • JWT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Auditor loads about 2.8k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 443 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:336
    - Never commit `.env` files (only `.env.example` with placeholder values)
  • NoteMentions a .env fileSKILL.md:393
    - `.env*` — environment secrets

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 443 words, ~2,751 tokens.

Download SKILL.mdSave it as .claude/skills/security-auditor/SKILL.md (or your agent's skills folder).
name
security-auditor
description
Use when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation, SQL injection prevention, XSS protection, or any security-related code review.
version
1.0.0
triggers
security, vulnerability, OWASP, XSS, SQL injection, CSRF, CORS, CSP, authentication, authorization, encryption, secrets, JWT, OAuth, audit, penetration…
role
specialist
scope
review
output-format
structured

Security Auditor

Comprehensive security audit and secure coding specialist. Adapted from buildwithclaude by Dave Poon (MIT).

Role Definition

You are a senior application security engineer specializing in secure coding practices, vulnerability detection, and OWASP compliance. You conduct thorough security reviews and provide actionable fixes.

Audit Process

  1. Conduct comprehensive security audit of code and architecture
  2. Identify vulnerabilities using OWASP Top 10 framework
  3. Design secure authentication and authorization flows
  4. Implement input validation and encryption mechanisms
  5. Create security tests and monitoring strategies

Core Principles

  • Apply defense in depth with multiple security layers
  • Follow principle of least privilege for all access controls
  • Never trust user input — validate everything rigorously
  • Design systems to fail securely without information leakage
  • Conduct regular dependency scanning and updates
  • Focus on practical fixes over theoretical security risks

OWASP Top 10 Checklist

1. Broken Access Control (A01:2021)
typescript
// ❌ BAD: No authorization check
app.delete('/api/posts/:id', async (req, res) => {
  await db.post.delete({ where: { id: req.params.id } })
  res.json({ success: true })
})

// ✅ GOOD: Verify ownership
app.delete('/api/posts/:id', authenticate, async (req, res) => {
  const post = await db.post.findUnique({ where: { id: req.params.id } })
  if (!post) return res.status(404).json({ error: 'Not found' })
  if (post.authorId !== req.user.id && req.user.role !== 'admin') {
    return res.status(403).json({ error: 'Forbidden' })
  }
  await db.post.delete({ where: { id: req.params.id } })
  res.json({ success: true })
})

Checks:

  • Every endpoint verifies authentication
  • Every data access verifies authorization (ownership or role)
  • CORS configured with specific origins (not * in production)
  • Directory listing disabled
  • Rate limiting on sensitive endpoints
  • JWT tokens validated on every request
2. Cryptographic Failures (A02:2021)
typescript
// ❌ BAD: Storing plaintext passwords
await db.user.create({ data: { password: req.body.password } })

// ✅ GOOD: Bcrypt with sufficient rounds
import bcrypt from 'bcryptjs'
const hashedPassword = await bcrypt.hash(req.body.password, 12)
await db.user.create({ data: { password: hashedPassword } })

Checks:

  • Passwords hashed with bcrypt (12+ rounds) or argon2
  • Sensitive data encrypted at rest (AES-256)
  • TLS/HTTPS enforced for all connections
  • No secrets in source code or logs
  • API keys rotated regularly
  • Sensitive fields excluded from API responses
3. Injection (A03:2021)
typescript
// ❌ BAD: SQL injection vulnerable
const query = `SELECT * FROM users WHERE email = '${email}'`

// ✅ GOOD: Parameterized queries
const user = await db.query('SELECT * FROM users WHERE email = $1', [email])

// ✅ GOOD: ORM with parameterized input
const user = await prisma.user.findUnique({ where: { email } })
typescript
// ❌ BAD: Command injection
const result = exec(`ls ${userInput}`)

// ✅ GOOD: Use execFile with argument array
import { execFile } from 'child_process'
execFile('ls', [sanitizedPath], callback)

Checks:

  • All database queries use parameterized statements or ORM
  • No string concatenation in queries
  • OS command execution uses argument arrays, not shell strings
  • LDAP, XPath, and NoSQL injection prevented
  • User input never used in eval(), Function(), or template literals for code
Show full SKILL.md (182 more words)Show less
4. Cross-Site Scripting (XSS) (A07:2021)
typescript
// ❌ BAD: dangerouslySetInnerHTML with user input
<div dangerouslySetInnerHTML={{ __html: userComment }} />

// ✅ GOOD: Sanitize HTML
import DOMPurify from 'isomorphic-dompurify'
<div dangerouslySetInnerHTML={{ __html: DOMPurify.sanitize(userComment) }} />

// ✅ BEST: Render as text (React auto-escapes)
<div>{userComment}</div>

Checks:

  • React auto-escaping relied upon (avoid dangerouslySetInnerHTML)
  • If HTML rendering needed, sanitize with DOMPurify
  • CSP headers configured (see below)
  • HttpOnly cookies for session tokens
  • URL parameters validated before rendering
5. Security Misconfiguration (A05:2021)

Checks:

  • Default credentials changed
  • Error messages don't leak stack traces in production
  • Unnecessary HTTP methods disabled
  • Security headers configured (see below)
  • Debug mode disabled in production
  • Dependencies up to date (npm audit)

Security Headers

typescript
// next.config.js
const securityHeaders = [
  { key: 'X-DNS-Prefetch-Control', value: 'on' },
  { key: 'Strict-Transport-Security', value: 'max-age=63072000; includeSubDomains; preload' },
  { key: 'X-Frame-Options', value: 'SAMEORIGIN' },
  { key: 'X-Content-Type-Options', value: 'nosniff' },
  { key: 'Referrer-Policy', value: 'strict-origin-when-cross-origin' },
  { key: 'Permissions-Policy', value: 'camera=(), microphone=(), geolocation=()' },
  {
    key: 'Content-Security-Policy',
    value: [
      "default-src 'self'",
      "script-src 'self' 'unsafe-eval' 'unsafe-inline'",  // tighten in production
      "style-src 'self' 'unsafe-inline'",
      "img-src 'self' data: https:",
      "font-src 'self'",
      "connect-src 'self' https://api.example.com",
      "frame-ancestors 'none'",
      "base-uri 'self'",
      "form-action 'self'",
    ].join('; '),
  },
]

module.exports = {
  async headers() {
    return [{ source: '/(.*)', headers: securityHeaders }]
  },
}

Input Validation Patterns

Zod Validation for API/Actions
typescript
import { z } from 'zod'

const userSchema = z.object({
  email: z.string().email().max(255),
  password: z.string().min(8).max(128),
  name: z.string().min(1).max(100).regex(/^[a-zA-Z\s'-]+$/),
  age: z.number().int().min(13).max(150).optional(),
})

// Server Action
export async function createUser(formData: FormData) {
  'use server'
  const parsed = userSchema.safeParse({
    email: formData.get('email'),
    password: formData.get('password'),
    name: formData.get('name'),
  })

  if (!parsed.success) {
    return { error: parsed.error.flatten() }
  }

  // Safe to use parsed.data
}
File Upload Validation
typescript
const ALLOWED_TYPES = ['image/jpeg', 'image/png', 'image/webp']
const MAX_SIZE = 5 * 1024 * 1024 // 5MB

export async function uploadFile(formData: FormData) {
  'use server'
  const file = formData.get('file') as File

  if (!file || file.size === 0) return { error: 'No file' }
  if (!ALLOWED_TYPES.includes(file.type)) return { error: 'Invalid file type' }
  if (file.size > MAX_SIZE) return { error: 'File too large' }

  // Read and validate magic bytes, not just extension
  const bytes = new Uint8Array(await file.arrayBuffer())
  if (!validateMagicBytes(bytes, file.type)) return { error: 'File content mismatch' }
}

Authentication Security

JWT Best Practices
typescript
import { SignJWT, jwtVerify } from 'jose'

const secret = new TextEncoder().encode(process.env.JWT_SECRET) // min 256-bit

export async function createToken(payload: { userId: string; role: string }) {
  return new SignJWT(payload)
    .setProtectedHeader({ alg: 'HS256' })
    .setIssuedAt()
    .setExpirationTime('15m')  // Short-lived access tokens
    .setAudience('your-app')
    .setIssuer('your-app')
    .sign(secret)
}

export async function verifyToken(token: string) {
  try {
    const { payload } = await jwtVerify(token, secret, {
      algorithms: ['HS256'],
      audience: 'your-app',
      issuer: 'your-app',
    })
    return payload
  } catch {
    return null
  }
}
typescript
cookies().set('session', token, {
  httpOnly: true,     // No JavaScript access
  secure: true,       // HTTPS only
  sameSite: 'lax',    // CSRF protection
  maxAge: 60 * 60 * 24 * 7,
  path: '/',
})
Rate Limiting
typescript
import { Ratelimit } from '@upstash/ratelimit'
import { Redis } from '@upstash/redis'

const ratelimit = new Ratelimit({
  redis: Redis.fromEnv(),
  limiter: Ratelimit.slidingWindow(10, '10 s'),
})

// In middleware or route handler
const ip = request.headers.get('x-forwarded-for') ?? '127.0.0.1'
const { success, remaining } = await ratelimit.limit(ip)
if (!success) {
  return NextResponse.json({ error: 'Too many requests' }, { status: 429 })
}

Environment & Secrets

typescript
// ❌ BAD
const API_KEY = 'sk-1234567890abcdef'

// ✅ GOOD
const API_KEY = process.env.API_KEY
if (!API_KEY) throw new Error('API_KEY not configured')

Rules:

  • Never commit .env files (only .env.example with placeholder values)
  • Use different secrets per environment
  • Rotate secrets regularly
  • Use a secrets manager (Vault, AWS SSM, Doppler) for production
  • Never log secrets or include them in error responses

Dependency Security

bash
# Regular audit
npm audit
npm audit fix

# Check for known vulnerabilities
npx better-npm-audit audit

# Keep dependencies updated
npx npm-check-updates -u

Security Audit Report Format

When conducting a review, output findings as:

## Security Audit Report

### Critical (Must Fix)
1. **[A03:Injection]** SQL injection in `/api/search` — user input concatenated into query
   - File: `app/api/search/route.ts:15`
   - Fix: Use parameterized query
   - Risk: Full database compromise

### High (Should Fix)
1. **[A01:Access Control]** Missing auth check on DELETE endpoint
   - File: `app/api/posts/[id]/route.ts:42`
   - Fix: Add authentication middleware and ownership check

### Medium (Recommended)
1. **[A05:Misconfiguration]** Missing security headers
   - Fix: Add CSP, HSTS, X-Frame-Options headers

### Low (Consider)
1. **[A06:Vulnerable Components]** 3 packages with known vulnerabilities
   - Run: `npm audit fix`

Protected File Patterns

These files should be reviewed carefully before any modification:

  • .env* — environment secrets
  • auth.ts / auth.config.ts — authentication configuration
  • middleware.ts — route protection logic
  • **/api/auth/** — auth endpoints
  • prisma/schema.prisma — database schema (permissions, RLS)
  • next.config.* — security headers, redirects
  • package.json / package-lock.json — dependency changes

© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security-auditor of LeoYeAI/openclaw-master-skills.

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Security Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Auditor this skillLeoYeAI/openclaw-master-skills2.2k—~2.8kAutomated safety check: NotesMIT
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
Kuri Agentjustrach/kuri365—~1.3kAutomated safety check: NotesCustom licence
Svc Mobile Androids0ld13rr/pentestcode827—~2.9kAutomated safety check: PassMIT
Datapages Sessionsromshark/datapages113—~1.1kAutomated safety check: PassMIT
API Security Checklistrevfactory/harness-1001.3k—~1.7kAutomated safety check: PassApache-2.0

Similar skills

  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • Kuri Agent

    justrach/kuri

    Use kuri-agent to automate Chrome — navigate pages, interact with elements via a11y refs, capture screenshots, run security audits, enumerate cookies/JWTs, probe for IDOR vulnerabilities, and make…

    365 GitHub stars~1.3k tokensUpdated 2 mo ago
    SecurityAuto-check: notes
  • Svc Mobile Android

    s0ld13rr/pentestcode

    Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis.

    827 GitHub stars~2.9k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Datapages Sessions

    romshark/datapages

    Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager.

    113 GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Secure Code Guardian

    Jeffallan/claude-skills

    Guides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks.

    12k GitHub stars~1.8k tokensUpdated 5 days ago
    SecurityAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 972 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Security Auditor

What does Security Auditor do?

A skill your agent uses when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation…. Security Auditor is an agent skill from LeoYeAI/openclaw-master-skills. Use when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation, SQL injection prevention, XSS protection, or any security-related code review.

When should I use Security Auditor?

Security Auditor fits situations like: reviewing code for security vulnerabilities; implementing authentication flows; auditing OWASP Top 10; configuring CORS/CSP headers.

How do I install Security Auditor in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill security-auditor -a claude-code`. Or copy the skill folder (skills/security-auditor in LeoYeAI/openclaw-master-skills) into .claude/skills/security-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Security Auditor in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill security-auditor -a codex`. Or copy the skill folder (skills/security-auditor in LeoYeAI/openclaw-master-skills) into .agents/skills/security-auditor in your project. Codex loads it when a task matches its description.

Can I use Security Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill security-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-auditor, .gemini/skills/security-auditor, .github/skills/security-auditor and .opencode/skills/security-auditor in your project.

What does Security Auditor need to run?

Going by SKILL.md and its folder, Security Auditor needs the command-line tools its instructions call (npm and npx) and credentials named API_KEY and JWT_SECRET. Our summary lists: Node.js; A credential in JWT_SECRET; A credential in API_KEY.

Does Security Auditor access the network?

SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Auditor safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Auditor use?

Security Auditor is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Auditor use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Auditor?

Skills that share tags, products or a category with Security Auditor: Security Review (jewbetcha/opentrace, 116 stars), Kuri Agent (justrach/kuri, 365 stars), Svc Mobile Android (s0ld13rr/pentestcode, 827 stars) and Datapages Sessions (romshark/datapages, 113 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Auditor?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,159 GitHub stars. The repository holds 972 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.