Agent skill

Owasp Security Audit

by LIDR-academy in LIDR-academy/AI4Devs-LTI-extended

A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a…

MITAuto-check: notesSecurity

Install Owasp Security Audit

skills CLI
$ npx skills add LIDR-academy/AI4Devs-LTI-extended --skill owasp-security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LIDR-academy/AI4Devs-LTI-extended owasp-security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LIDR-academy/AI4Devs-LTI-extended.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ai-specs/skills/owasp-security-audit .claude/skills/owasp-security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
owasp-security-audit
GitHub stars
278
Token cost
~4.3k tokens
SKILL.md length
1,704 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a…

  • Works in 5 steps: Environment Setup and Automated Scans → Systematic Category Audit → Findings Classification → …
  • Performing a cybersecurity audit
  • SKILL.md covers Overview, When to Use, Audit Methodology and Quick Reference: OWASP Top 10…, plus 6 more sections
  • Calls rg, npm and curl

What it does

Owasp Security Audit is an agent skill from LIDR-academy/AI4Devs-LTI-extended. Use when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a Node.js/Express/React application.

Its SKILL.md is about 4.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities, Security review and Vulnerability scanning. It works with React and Node.js. The repository describes itself as: Repository with several experiments from live sessions. The licence is MIT.

When your agent uses it

  • Performing a cybersecurity audit
  • Security review
  • OWASP Top 10 compliance check
  • Vulnerability assessment

Example prompts

  • “/owasp-security-audit”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Environment Setup and Automated Scans
  2. Systematic Category Audit
  3. Findings Classification
  4. Prioritized Remediation Plan
  5. Verification and CI/CD Integration

What it can do on your machine

Read from SKILL.md and the folder at commit 9ff9a80. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg
    • npm
    • curl
    • git
    • python3
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, curl, git and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Owasp Security Audit loads about 4.3k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 1,704 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~4.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:41
    | .gitignore check | Verify `.env`, `*.pem`, `*.key` are in `.gitignore` | A02: Committed secrets |
  • NoteMentions a .env fileSKILL.md:120
    | `.env` in `.gitignore` | `rg '\.env' .gitignore` — verify NOT commented out | Critical |
  • NoteMentions a .env fileSKILL.md:362
    trust `env()` in `schema.prisma` if the `.env` is committed

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LIDR-academy/AI4Devs-LTI-extended at commit 9ff9a80, republished under its MIT licence (© LIDR-academy). 1,704 words, ~4,344 tokens.

Download SKILL.mdSave it as .claude/skills/owasp-security-audit/SKILL.md (or your agent's skills folder).
name
owasp-security-audit
description
Use when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a Node.js/Express/React application.

OWASP Top 10 Security Audit

Overview

Systematic methodology for auditing web applications against the OWASP Top 10:2021. Combines automated tooling with manual code review, produces a prioritized remediation plan with verification steps and CI/CD integration guidance.

Core principle: Every finding must be verified with tooling or code evidence, prioritized by exploitability, and paired with a concrete fix the agent can implement.

When to Use

  • Cybersecurity audit or security review request
  • OWASP Top 10 compliance assessment
  • Pre-release security gate or penetration test preparation
  • Post-incident security hardening
  • Dependency vulnerability triage

When NOT to use:

  • Quick fix for a single known vulnerability (just fix it)
  • General code quality review (use code-auditing skill instead)
  • Infrastructure/cloud security review (out of scope - this covers application layer)

Audit Methodology

Phase 0: Environment Setup and Automated Scans

Run automated tools FIRST - they catch low-hanging fruit before manual review.

Required scans (execute all):

ToolCommandCovers
npm auditnpm audit --jsonA06: Known CVEs in dependencies
ESLint securitynpx eslint --plugin security .A03, A05: Code-level vulnerabilities
Outdated checknpm outdatedA06: Outdated packages
Secret scanrg -i '(password|secret|api_key|token)\s*[:=]' --glob '!node_modules' --glob '!*.lock'A02: Hardcoded secrets
.gitignore checkVerify .env, *.pem, *.key are in .gitignoreA02: Committed secrets
Git history secretsgit log --all --diff-filter=A -- '*.env' '*.pem' '*.key'A02: Secrets in git history
Debug/telemetry coderg 'fetch\(.*127\.0\.0\.1|localhost:[0-9]{4}' --glob '*.{ts,js,jsx,tsx}'A04: Dev-only outbound requests

Record baseline metrics: Total vulnerabilities by severity, outdated dependency count, secret scan hits.

Phase 1: Systematic Category Audit

Audit EVERY category using the checklist in the Quick Reference section. Do not skip categories even if they seem irrelevant - document "N/A" with justification.

For each category:

  1. Run the specific checks listed in the checklist
  2. Record findings with file path, line number, and severity
  3. Note what you checked even if clean (proves thoroughness)
Phase 2: Findings Classification

Rate each finding using this severity matrix:

SeverityCriteriaExample
CriticalExploitable remotely, no auth required, data breach likelyHardcoded DB credentials in git, zero authentication
HighExploitable with some effort, significant impactMissing security headers, no rate limiting, IDOR
MediumRequires specific conditions, moderate impactOutdated dependencies without known exploits, weak validation
LowMinimal impact or unlikely exploitationMissing CSP fine-tuning, verbose error messages in dev
Phase 3: Prioritized Remediation Plan

Group fixes into implementation phases:

Phase A - Immediate (< 1 day, critical/high):

  • Rotate exposed credentials
  • Add authentication middleware
  • Install and configure Helmet
  • Add rate limiting
  • Fix .gitignore and purge secrets from git history

Phase B - Short-term (1-3 days, high/medium):

  • Implement RBAC authorization
  • Add input sanitization (xss/DOMPurify)
  • Configure structured logging
  • Set body size limits
  • Add CSRF protection

Phase C - Medium-term (1-2 weeks, medium/low):

  • Upgrade outdated dependencies
  • Add CI/CD security pipeline
  • Implement audit logging
  • Add security monitoring/alerting

Each fix must include: what to change, where, a code example, and how to verify it works.

Phase 4: Verification and CI/CD Integration

For each remediation, define a verification step:

  • Unit test that validates the security control
  • curl command that proves the vulnerability is fixed
  • CI pipeline check that prevents regression

Quick Reference: OWASP Top 10 Audit Checklist

A01: Broken Access Control

Step 1: Enumerate all routes first. Run rg 'router\.(get|post|put|patch|delete)' --glob '*.ts' and list every endpoint. Then verify EACH has auth middleware.

CheckHowSeverity if missing
Authentication middleware on ALL routesEnumerate all routes, verify each has auth middleware in chainCritical
RBAC / role-based authorizationCheck for role checks before data accessCritical
IDOR protectionVerify resource ownership checks (e.g., where: { id, userId })High
CORS configurationCheck cors() options - no wildcard in productionHigh
Serverless CORS vs Express CORSCompare serverless.yml CORS with Express CORS configMedium
CSRF protectionCheck for csurf or double-submit cookie patternMedium
A02: Cryptographic Failures
CheckHowSeverity if missing
No hardcoded secretsrg '(password|secret|key)\s*[:=]\s*["\x27]' --glob '!*.lock'Critical
.env in .gitignorerg '\.env' .gitignore — verify NOT commented outCritical
Secrets in git historygit log --all --diff-filter=A -- '*.env' '*.pem' — if found, recommend bfg-repo-cleaner purgeCritical
Prisma uses env("DATABASE_URL")Check schema.prisma datasource block — no inline connection stringCritical
HTTPS enforcementCheck for https redirects or HSTS headersHigh
PII field filteringCheck API responses for unnecessary sensitive fieldsMedium
Password hashing (if auth exists)Verify bcrypt/argon2, not SHA/MD5Critical
A03: Injection
CheckHowSeverity if missing
No raw SQLrg '\$(queryRaw|executeRaw)|rawQuery' --glob '*.ts'Critical
Parameterized queries (Prisma/ORM)Verify all DB access through ORM, no string concatenationCritical
Input validation on all endpointsCheck every route handler has validation before DB opsHigh
File upload filename sanitizationCheck multer/upload config for originalname usageHigh
Sort/filter field allowlistsVerify user-supplied field names checked against allowlistMedium
No eval() or Function()rg 'eval\(|new Function\(' --glob '*.{ts,js}'Critical
No template literal injection in logsCheck log statements for unsanitized user inputLow
Mass assignment preventionVerify req.body is NOT spread directly into Prisma create/update — use explicit field allowlistsHigh
A04: Insecure Design
CheckHowSeverity if missing
Request body size limitsCheck express.json({ limit: ... })Medium
File upload size/type restrictionsCheck multer config for limits and fileFilterHigh
File upload path traversalVerify upload destination is absolute, filename is sanitizedHigh
Validation not bypassableCheck validators cannot be skipped (e.g., with extra fields)High
No debug/telemetry endpoints in productionrg 'fetch\(.*127\.0\.0\.1|localhost:[0-9]' --glob '*.{ts,js,jsx}'High
Error responses don't leak internalsVerify 500 errors return generic messagesMedium
A05: Security Misconfiguration
CheckHowSeverity if missing
Helmet.js installed and configuredCheck package.json for helmet, index.ts for app.use(helmet())High
x-powered-by disabledapp.disable('x-powered-by') or Helmet handles itLow
Rate limitingCheck for express-rate-limit or equivalentHigh
Strict CORS (no wildcard)Verify origin is not * or trueHigh
Environment variable validationCheck for startup validation of required env varsMedium
No default credentialsCheck seed files, test configs for hardcoded passwordsMedium
HTTP parameter pollution (HPP)Check for hpp middleware or manual preventionLow
trust proxy configured (if behind LB)Check app.set('trust proxy', ...) for Lambda/ALBMedium
CSP for React SPAVerify Content-Security-Policy header restricts script-src, style-src, connect-srcHigh
No inline <script> in public HTMLCheck public/index.html for inline scripts or event handlersMedium
Show full SKILL.md (708 more words)Show less
A06: Vulnerable and Outdated Components
CheckHowSeverity if missing
npm audit cleanRun npm audit --json, count critical/highVaries
Node.js runtime not EOLCheck engines field, Lambda runtime versionMedium
No deprecated packagesRun npm outdated, check for major version gapsLow
Lock file exists and committedVerify package-lock.json is in gitMedium
TypeScript version currentCheck package.json TypeScript versionLow
No suspicious postinstall scriptsCheck dependencies for preinstall/postinstall scripts: rg '"preinstall|postinstall"' node_modules/*/package.json | head -20Medium
No typosquatting riskSpot-check unusual or less-known package names against npm registryLow
A07: Identification and Authentication Failures
CheckHowSeverity if missing
Auth mechanism existsrg 'jwt|jsonwebtoken|passport|auth|session' --glob '*.ts' -iCritical
Password policy enforcedCheck password validation (length, complexity)High
Account lockout after failed attemptsCheck for brute-force protectionHigh
Session/token expirationVerify JWT expiry or session timeoutHigh
Secure cookie flagsCheck httpOnly, secure, sameSite flagsMedium
A08: Software and Data Integrity Failures
CheckHowSeverity if missing
HTML sanitization on text inputsCheck for xss, sanitize-html, or DOMPurify usageMedium
No dangerouslySetInnerHTML without sanitizationrg 'dangerouslySetInnerHTML' --glob '*.{tsx,jsx}'High
URL sanitization in href/src attributesCheck for javascript: protocol filteringHigh
Prototype pollution preventionCheck for Object.freeze, --disable-proto flag, or hppMedium
Lock file integrityVerify package-lock.json integrity hashesLow
A09: Security Logging and Monitoring Failures
CheckHowSeverity if missing
Structured logging (not console.log)Check for winston, pino, or structured loggerHigh
Audit trail for CRUD operationsVerify create/update/delete actions are logged with actorHigh
Request logging middleware orderVerify logger is BEFORE route handlersMedium
No PII in error logsCheck error handlers for data leakageMedium
Log injection preventionVerify user input is not interpolated into log templatesLow
Failed auth attempt loggingVerify 401/403 responses are loggedMedium
A10: Server-Side Request Forgery (SSRF)
CheckHowSeverity if missing
No outbound requests from user inputrg 'fetch\(|axios\.|http\.request' --glob 'backend/**/*.ts'High
URL allowlist for external callsVerify outbound URLs are validated against allowlistHigh
No user-controlled redirect URLsCheck redirect endpoints for open redirectMedium
File operations use absolute pathsVerify no path.join(userInput) without validationMedium

Serverless/Lambda Specific Checks

If the project deploys to AWS Lambda (or similar FaaS), also check:

CheckHowSeverity if missing
Lambda runtime not EOLCheck serverless.yml or template.yaml runtime versionMedium
IAM permissions least-privilegeVerify Lambda role has minimal permissions, not *High
API Gateway CORS matches Express CORSCompare gateway-level CORS with application-levelHigh
Environment variables encrypted at restVerify sensitive values use KMS encryptionMedium
Function timeout configuredCheck for reasonable timeout to prevent resource exhaustionLow
VPC configuration (if accessing private resources)Verify Lambda is in VPC with proper security groupsMedium

Runtime Verification Commands

After implementing fixes, verify with actual HTTP requests:

bash
# Verify Helmet headers
curl -sI http://localhost:3010/ | grep -iE '(x-powered-by|x-content-type|strict-transport|x-frame)'

# Verify rate limiting
for i in $(seq 1 110); do curl -s -o /dev/null -w "%{http_code}\n" http://localhost:3010/; done | sort | uniq -c

# Verify CORS rejects unknown origins
curl -sI -H "Origin: http://evil.com" http://localhost:3010/ | grep -i access-control

# Verify body size limit
python3 -c "print('x'*2000000)" | curl -s -X POST -H "Content-Type: application/json" -d @- http://localhost:3010/candidates -w "\n%{http_code}"

# Verify auth required
curl -s http://localhost:3010/candidates -w "\n%{http_code}"

Report Template

markdown
# OWASP Top 10 Security Audit Report

- **Project**: [name]
- **Stack**: [technologies]
- **Date**: [YYYY-MM-DD]
- **Scope**: Static code analysis + automated tooling

## Automated Scan Results

### npm audit
- Critical: X | High: X | Medium: X | Low: X
- Key vulnerabilities: [list]

### Secret Scan
- Hits: X
- Locations: [list]

## Findings by Category

### A01: Broken Access Control — [CRITICAL/HIGH/MEDIUM/LOW/CLEAN]
**Checked:** [list what was examined]
**Findings:** [list with file:line references]
**Remediation:** [code examples]

[...repeat for A02-A10...]

## Remediation Priority Matrix

| Phase | Finding | Severity | Effort | Fix |
|-------|---------|----------|--------|-----|
| A | [finding] | Critical | [hours] | [brief description] |

## Verification Checklist
- [ ] [Finding 1]: [how to verify fix]
- [ ] [Finding 2]: [how to verify fix]

## CI/CD Security Integration
- [ ] `npm audit` in CI pipeline (fail on critical/high)
- [ ] ESLint security plugin in pre-commit hook
- [ ] Dependency update bot (Dependabot/Renovate)
- [ ] Secret scanning in CI (truffleHog/gitleaks)

Common Mistakes

MistakeWhy it's wrongFix
Skipping categories marked "N/A" without evidenceAuditor assumed rather than verifiedAlways document what you checked
Not running automated toolsMissing known CVEs that are trivially exploitableRun npm audit and secret scan FIRST
Reporting findings without remediation codeFindings without fixes create toil, not progressEvery finding needs a code-level fix
Not prioritizing fixesTreating all findings equally paralyzes teamsUse the severity matrix and phase grouping
Forgetting CI/CD integrationManual audits rot; only automated gates persistAlways include pipeline integration steps
Auditing only backend OR frontendXSS vectors cross the boundaryAudit both, trace data flow end-to-end
Trusting ORM = no injection riskORMs prevent SQL injection but not all injection typesCheck for command injection, log injection, path traversal
Skipping .gitignore and git history checkSecrets removed from code may still be in git historyCheck .gitignore AND git log history AND recommend purge if needed
Not checking for mass assignmentORM prevents SQL injection but allows unfiltered field updatesVerify req.body is filtered through an allowlist before Prisma calls
Static analysis onlySome vulnerabilities only appear at runtime (CORS headers, rate limits)Include runtime verification commands in the report

Node.js/Express Specific Hardening Checklist

Essential middleware stack (order matters):

typescript
import helmet from 'helmet';
import rateLimit from 'express-rate-limit';
import cors from 'cors';
import hpp from 'hpp';

// 1. Security headers
app.use(helmet());
app.disable('x-powered-by');

// 2. Rate limiting
app.use(rateLimit({
  windowMs: 15 * 60 * 1000,
  max: 100,
  standardHeaders: true,
  legacyHeaders: false,
}));

// 3. CORS - explicit origins only
app.use(cors({
  origin: process.env.ALLOWED_ORIGINS?.split(',') || [],
  credentials: true,
  methods: ['GET', 'POST', 'PUT', 'PATCH', 'DELETE'],
}));

// 4. Body parsing with size limits
app.use(express.json({ limit: '1mb' }));
app.use(express.urlencoded({ extended: true, limit: '1mb' }));

// 5. HTTP Parameter Pollution protection
app.use(hpp());

// 6. Request logging (BEFORE routes)
app.use(requestLogger);

// 7. Routes
app.use('/api', routes);

// 8. Error handler (AFTER routes, generic messages only)
app.use(errorHandler);

Prisma/ORM Security Notes

  • Always use select to limit returned fields (avoid PII leakage)
  • Never trust env() in schema.prisma if the .env is committed
  • Watch for validation bypass when id is present in request body
  • Prisma prevents SQL injection but NOT mass assignment - validate allowed fields explicitly

© LIDR-academy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in ai-specs/skills/owasp-security-audit of LIDR-academy/AI4Devs-LTI-extended.

Open the folder on GitHubat commit 9ff9a80

Compare with similar skills

Owasp Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Owasp Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Owasp Security Audit this skillLIDR-academy/AI4Devs-LTI-extended278—~4.3kAutomated safety check: NotesMIT
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone
Security Verification Gatefengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT
Security Audit Scannerruvnet/ruflo74k1 repos~823Automated safety check: PassMIT
Cyber NeoHainrixz/cyber-neo283—~5.9kAutomated safety check: WarnMIT

Similar skills

  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 25 days ago
    SecurityAuto-check: notes
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 1 repo~823 tokens
    SecurityAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    283 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Code Vuln Audit

    zebbern/claude-code-guide

    Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

    4.7k GitHub stars~1.3k tokensUpdated yesterday
    SecurityAuto-check passed

More from LIDR-academy/AI4Devs-LTI-extended

All 9 skills in this repo
  • Show Spec Working

    LIDR-academy/AI4Devs-LTI-extended

    A skill your agent uses when the user asks "show me X", "demo X", "walk me through X", "how X works" or requests a live feature demonstration from a spec, feature or ticket.

    278 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed
  • Sync Agent Symlinks

    LIDR-academy/AI4Devs-LTI-extended

    Analyze and synchronize agent skill exposure after ai-specs skill changes (additions, removals, renames).

    278 GitHub stars~1k tokensUpdated 4 mo ago
    Auto-check passed
  • Run Parallel Tasks

    LIDR-academy/AI4Devs-LTI-extended

    Run N feature tasks in parallel, each in its own worktree, following the full specboot pipeline (enrich → new → ff → apply → verify).

    278 GitHub stars~1.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Commit

    LIDR-academy/AI4Devs-LTI-extended

    Create focused commits and pull requests following repository standards.

    278 GitHub stars~1.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Explain

    LIDR-academy/AI4Devs-LTI-extended

    Teach underlying concepts with clear mental models to close skill gaps behind user questions.

    278 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check passed
  • Enrich Us

    LIDR-academy/AI4Devs-LTI-extended

    Analyze and enhance Jira user stories with complete, implementation-ready technical detail.

    278 GitHub stars~521 tokensUpdated 4 mo ago
    Auto-check passed

Works with

Categories

Questions about Owasp Security Audit

What does Owasp Security Audit do?

A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a…. Owasp Security Audit is an agent skill from LIDR-academy/AI4Devs-LTI-extended.js/Express/React application.

When should I use Owasp Security Audit?

Owasp Security Audit fits situations like: performing a cybersecurity audit; security review; OWASP Top 10 compliance check; vulnerability assessment.

How do I install Owasp Security Audit in Claude Code?

Run `npx skills add LIDR-academy/AI4Devs-LTI-extended --skill owasp-security-audit -a claude-code`. Or copy the skill folder (ai-specs/skills/owasp-security-audit in LIDR-academy/AI4Devs-LTI-extended) into .claude/skills/owasp-security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Owasp Security Audit in Codex?

Run `npx skills add LIDR-academy/AI4Devs-LTI-extended --skill owasp-security-audit -a codex`. Or copy the skill folder (ai-specs/skills/owasp-security-audit in LIDR-academy/AI4Devs-LTI-extended) into .agents/skills/owasp-security-audit in your project. Codex loads it when a task matches its description.

Can I use Owasp Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LIDR-academy/AI4Devs-LTI-extended --skill owasp-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/owasp-security-audit, .gemini/skills/owasp-security-audit, .github/skills/owasp-security-audit and .opencode/skills/owasp-security-audit in your project.

What does Owasp Security Audit need to run?

Going by SKILL.md and its folder, Owasp Security Audit needs the command-line tools its instructions call (rg, npm, curl, git, python3 and npx). Our summary lists: Node.js.

Does Owasp Security Audit access the network?

SKILL.md contains no URLs. Its commands use npm, curl, git and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Owasp Security Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Owasp Security Audit use?

Owasp Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Owasp Security Audit use?

About 4.3k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Owasp Security Audit?

Skills that share tags, products or a category with Owasp Security Audit: Security Auditor (eigent-ai/eigent, 15k stars), Code Audit (3stoneBrother/code-audit, 892 stars), Security Verification Gate (fengshao1227/ccg-workflow, 5.9k stars) and Security Audit Scanner (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Owasp Security Audit?

LIDR-academy (a GitHub organization) maintains it in LIDR-academy/AI4Devs-LTI-extended, which has 278 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on June 9, 2026.

Source: LIDR-academy/AI4Devs-LTI-extended on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.