Agent skill

Security Audit

by marketcalls in marketcalls/openalgo

Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report.

AGPL-3.0Auto-check passedSecurity

Install Security Audit

skills CLI
$ npx skills add marketcalls/openalgo --skill security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install marketcalls/openalgo security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/security-audit .claude/skills/security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-audit
GitHub stars
2.8k
Token cost
~1.9k tokens
SKILL.md length
967 words
Files
2
Skills in repo
8
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report.

  • Works in 3 steps: Never print a secret — use fingerprint(). → Never write outside tmp/security-audits/… → Give every finding a remediation, not…
  • Twice-monthly review
  • SKILL.md covers What it covers, Reading the report, Triage guidance for the… and Manual checks the script…, plus 2 more sections
  • Runs Python scripts from its folder; calls npm and uv; needs APP_KEY

What it does

Security Audit is an agent skill from marketcalls/openalgo. Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report. Use for the monthly or twice-monthly review, before a release, after a dependency bump, or when the user asks for a security check, vulnerability scan, or audit report.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `audit.py`).

It sits in Security, covering Security review and Excel spreadsheets. It works with Microsoft Excel. The repository describes itself as: Open Source Algo Trading Platform for Everyone. The licence is AGPL-3.0.

When your agent uses it

  • Twice-monthly review
  • Before a release
  • After a dependency bump
  • The user asks for a security check

Example prompts

  • “/security-audit”

Requirements

  • Python 3
  • A credential in APP_KEY

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Never print a secret — use fingerprint().
  2. Never write outside tmp/security-audits/ — scratch goes to tempfile.
  3. Give every finding a remediation, not just a description. A finding

What it can do on your machine

Read from SKILL.md and the folder at commit 1dcfff5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • APP_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Audit loads about 1.9k tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 967 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from marketcalls/openalgo at commit 1dcfff5, republished under its AGPL-3.0 licence (© marketcalls). 967 words, ~1,880 tokens.

Download SKILL.mdSave it as .claude/skills/security-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
security-audit
description
Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report. Use for the monthly or twice-monthly review, before a release, after a dependency bump, or when the user asks for a security check, vulnerability scan, or audit report.

OpenAlgo security audit

Run monthly (or twice monthly), and additionally before any release and after any dependency bump.

bash
uv run --with openpyxl python .claude/skills/security-audit/audit.py

Writes tmp/security-audits/<YYYY-MM>/security_audit_<date>_<time>.xlsx. tmp/ is gitignored and holds reports only — the script keeps its own scratch files in the OS temp dir. Exit code is 0 when no CRITICAL/HIGH check is failing, 1 otherwise, so it drops into CI unchanged.

The script is read-only. It never rotates a key, edits config, or touches the database, and the report never contains a secret value — only pass/fail, a sha256: fingerprint, and a remediation pointer. That means the xlsx is safe to share with someone helping you triage.

What it covers

AreaChecks
SecretsAPP_KEY/API_KEY_PEPPER present, full-entropy, and not one of the publicly-known leaked values shipped before v2.0.0.6; no credentials tracked in git; detect-secrets sweep
Runtime postureFLASK_DEBUG off; remote MCP never with debug; CSRF on; CSP enforcing (not report-only); CORS not wildcard-with-credentials; HTTPS; ngrok off; rate limits set
RoutesAll 461 blueprint routes checked for @check_session_validity / rate limiting against an allowlist of intentionally-public paths; state-changing routes reported separately; test/debug surfaces flagged
DatabaseFile permissions; Fernet encryption of broker tokens; peppered API keys; NullPool (never StaticPool); engines created via engine_factory; backup presence
CacheCredential caches must have an explicit bounded TTL; auth-change invalidation available; the ZMQ invalidation publisher must connect(), never bind()
Backend codeeval/exec, shell=True, pickle/yaml deserialization, raw-SQL f-strings, path traversal, SSRF, open redirect, weak hashes, verify=False, missing HTTP timeouts
FrontenddangerouslySetInnerHTML, innerHTML, eval/new Function, credentials in browser storage, hardcoded key literals, plain-http endpoints, source maps in dist/, npm audit
Dependenciespip-audit (Python) and npm audit (JS) — two separate ecosystems, both required
Static analysisbandit, triaged rather than dumped

Reading the report

Six sheets: Summary, Findings (colour-coded by status), Code patterns, Frontend patterns, Routes (unprotected), Bandit (triaged), Manual review.

Statuses mean different things and should be worked in this order:

  • FAIL — a control is objectively wrong. Fix it.
  • ERROR — a check could not run (usually a missing tool). Fix the tooling; an unrun check is not a pass.
  • REVIEW — a pattern that is often fine and sometimes catastrophic. A human must look. This is where the real findings live.
  • WARN — weaker posture, defensible depending on deployment.
  • PASS / SKIP — no action.

Do not treat counts as scores. Bandit produces ~930 raw findings on this repo and roughly 5 matter; the rest are asserts and try/except/pass. The script does that triage for you and reports all three numbers so you can see the ratio. Same for the route check: 461 routes, ~119 without decorators, and almost all of those are legitimately public — which is why the allowlist exists.

Triage guidance for the recurring REVIEW items

Raw SQL f-strings. All current hits interpolate table and column names (SQLite cannot parameterize those) from module-level literals in migration code, e.g. _migrate_mode_unique(ScalpingSLState, "scalping_sl_state"). That is safe. The check exists to catch the day someone interpolates a request value. Trace each new hit to its source; if it is not a developer-controlled constant, it is a real injection.

Direct create_engine calls. Mostly in broker database/master_contract_db.py modules. These bypass engine_factory and therefore the NullPool guarantee — an FD-hygiene and availability issue rather than a breach. Worth converging over time; see the fd-audit skill.

Credential caches. database/telegram_db.py holds _user_credentials_cache with a 30-minute TTL. Broker tokens roll over at ~3 AM IST, so confirm no auth cache outlives that boundary and that logout or revoke invalidates it.

Unprotected routes. Genuinely public ones (React SPA shells, /login, .well-known, broker callbacks, token-authenticated webhooks and postbacks) are on PUBLIC_ROUTE_ALLOWLIST in the script. When you add a legitimately public route, add it there with a reason — that keeps the check meaningful instead of noisy.

detect-secrets candidates. High false-positive rate on this repo. Triage once, then commit a .secrets.baseline so subsequent audits only surface new candidates.

Credentials in browser storage. The current hit is localStorage.setItem('pocketful_oauth_state', ...), which is an OAuth CSRF state token — the correct use of localStorage. An auth token or API key there would not be.

Show full SKILL.md (311 more words)Show less

Manual checks the script cannot do

The Manual review sheet lists twelve items that need a human and an authenticated session — they are part of the audit, not optional extras. The ones most specific to this platform:

  • Static IP whitelisting. Confirm the broker portal still lists only this server's IP. Under the SEBI mandate stolen keys are unusable off-IP, but anything routed through this server still works — so server compromise, not key theft, is the threat that matters.
  • API keys. Revoke keys for integrations no longer in use. TradingView/Chartink send keys in the body or query string and cannot set headers, so a stale key is a standing grant.
  • Network exposure. Ports 5000/8765/5555 must not be internet-reachable. ZMQ 5555 carries the raw tick feed with no authentication.
  • Webhook tokens. Flow and strategy webhook URLs are bearer credentials — anyone holding the URL can trigger the strategy.
  • Pepper discipline. Never hand-edit API_KEY_PEPPER on a populated database; it invalidates every password hash and encrypted token. Use upgrade/rotate_pepper.py.

Threat model this is calibrated to

OpenAlgo is single-user and self-hosted: one user, one broker session per instance, no privilege escalation and no SaaS component. Server access equals full control, which is why filesystem permissions, secret hygiene and network exposure carry more weight here than classic multi-tenant concerns like IDOR or role bypass. Weight your triage accordingly.

Maintaining the script

Add a check by writing one function that calls add(check, severity, status, detail, remediation, evidence) and wiring it into main(). Keep three properties:

  1. Never print a secret — use fingerprint().
  2. Never write outside tmp/security-audits/ — scratch goes to tempfile.
  3. Give every finding a remediation, not just a description. A finding nobody knows how to fix gets skipped next month.

When a REVIEW item is confirmed benign and will stay benign, encode that as an allowlist entry or a narrowed pattern rather than re-triaging it every month.

© marketcalls, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .claude/skills/security-audit of marketcalls/openalgo.

  • SKILL.md
  • audit.py

Open the folder on GitHubat commit 1dcfff5

Compare with similar skills

Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Audit this skillmarketcalls/openalgo2.8k—~1.9kAutomated safety check: PassAGPL-3.0
Host Cve Validatorinfometa/workbuddyskills346—~1.8kAutomated safety check: NotesProprietary
Soeinfometa/workbuddyskills346—~2.3kAutomated safety check: NotesNone
Vul Analyseinfometa/workbuddyskills346—~3.9kAutomated safety check: PassNone
Container Cve Fix Validatorinfometa/workbuddyskills346—~779Automated safety check: NotesApache-2.0
Web Xxes0ld13rr/pentestcode828—~585Automated safety check: PassMIT

Similar skills

  • Host Cve Validator

    infometa/workbuddyskills

    主机安全CVE漏洞修复验证引擎。从主机漏扫报告(Excel)或CVE编号自动提取漏洞,查询威胁情报(NVD/EPSS/MSRC/OVAL),生成修复脚本(fix.sh/fix.ps1),SSH验证脚本可执行性,产出修复验证报告。覆盖 Linux(centos/ubuntu/debian/suse/amazon/fedora/alpine/arch) + Windows + Web-CMS…

    346 GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Soe

    infometa/workbuddyskills

    This skill should be used when the user asks to "analyze security alerts", "parse vulnerability scan report", "analyze vulnerability scan report", "verify CVE fix", "analyze WAF attack log"…

    346 GitHub stars~2.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Vul Analyse

    infometa/workbuddyskills

    漏扫报告分析 Skill。输入主流厂商漏扫报告(绿盟/深信服/悬镜/明鉴/等保/奇安信/启明/华云安/长亭/Nessus/Trivy/Grype/Snyk/OpenVAS 等 Excel/HTML/JSON/XML/.nessus 格式),自动提取漏洞并去重,可选对接知识库 Provider(修复历史)和威胁情报 Provider(CVE 情报),生成 7…

    346 GitHub stars~3.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Container Cve Fix Validator

    infometa/workbuddyskills

    容器安全CVE漏洞修复验证引擎。从容器漏扫报告(Excel)自动提取漏洞,生成修复计划, SSH到测试环境验证OS包(apt/yum/apk)、Python(pip)、Node.js(npm)、Java(JAR)四种包类型的 修复方案,产出修复验证报告。不涉及主机层漏洞修复、不处理容器编排层安全配置。

    346 GitHub stars~779 tokensUpdated yesterday
    SecurityAuto-check: notes
  • Web Xxe

    s0ld13rr/pentestcode

    XML External Entity injection detection→file-read/SSRF→proof for web apps.

    828 GitHub stars~585 tokensUpdated 7 days ago
    Documents & OfficeAuto-check passed
  • Firewall Review

    transilienceai/communitytools

    Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate…

    562 GitHub stars~2.4k tokensUpdated 2 mo ago
    Documents & OfficeAuto-check passed

More from marketcalls/openalgo

All 8 skills in this repo
  • Broker Integration

    marketcalls/openalgo

    Integrate a new Indian broker into OpenAlgo, or modify an existing broker plugin.

    2.8k GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Fd Audit

    marketcalls/openalgo

    Audit a change for resource leaks in OpenAlgo — file descriptors AND unbounded memory growth.

    2.8k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Flow Builder

    marketcalls/openalgo

    Build, edit or debug an OpenAlgo Flow workflow - the no-code node graph at /flow.

    2.8k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Openscript

    marketcalls/openalgo

    Write an OpenScript study or strategy for OpenAlgo, and install it into strategies/openscript/ only after it compiles.

    2.8k GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Verify

    marketcalls/openalgo

    Verify a claim before stating it, and verify a test before trusting it.

    2.8k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Version Bump

    marketcalls/openalgo

    Bump a version in the OpenAlgo repo. An agent skill from marketcalls/openalgo.

    2.8k GitHub stars~1.8k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Security Audit

What does Security Audit do?

Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report. Security Audit is an agent skill from marketcalls/openalgo. Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report.

When should I use Security Audit?

Security Audit fits situations like: twice-monthly review; before a release; after a dependency bump; the user asks for a security check.

How do I install Security Audit in Claude Code?

Run `npx skills add marketcalls/openalgo --skill security-audit -a claude-code`. Or copy the skill folder (.claude/skills/security-audit in marketcalls/openalgo) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Security Audit in Codex?

Run `npx skills add marketcalls/openalgo --skill security-audit -a codex`. Or copy the skill folder (.claude/skills/security-audit in marketcalls/openalgo) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.

Can I use Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add marketcalls/openalgo --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.

What does Security Audit need to run?

Going by SKILL.md and its folder, Security Audit needs Python for the scripts in its folder, the command-line tools its instructions call (npm and uv) and credentials named APP_KEY. Our summary lists: Python 3; A credential in APP_KEY.

Does Security Audit access the network?

SKILL.md contains no URLs. Its commands use npm and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Audit use?

Security Audit is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Audit use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Audit?

Skills that share tags, products or a category with Security Audit: Host Cve Validator (infometa/workbuddyskills, 346 stars), Soe (infometa/workbuddyskills, 346 stars), Vul Analyse (infometa/workbuddyskills, 346 stars) and Container Cve Fix Validator (infometa/workbuddyskills, 346 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Audit?

marketcalls (a GitHub user) maintains it in marketcalls/openalgo, which has 2,808 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 9, 2026.

Source: marketcalls/openalgo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.