Host Cve Validator
infometa/workbuddyskills
主机安全CVE漏洞修复验证引擎。从主机漏扫报告(Excel)或CVE编号自动提取漏洞,查询威胁情报(NVD/EPSS/MSRC/OVAL),生成修复脚本(fix.sh/fix.ps1),SSH验证脚本可执行性,产出修复验证报告。覆盖 Linux(centos/ubuntu/debian/suse/amazon/fedora/alpine/arch) + Windows + Web-CMS…
Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report.
$ npx skills add marketcalls/openalgo --skill security-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install marketcalls/openalgo security-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/security-audit .claude/skills/security-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-audit" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/security-audit into .claude/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/marketcalls/openalgo/tree/main/.claude/skills/security-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add marketcalls/openalgo --skill security-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install marketcalls/openalgo security-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/security-audit .agents/skills/security-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-audit" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/security-audit into .agents/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add marketcalls/openalgo --skill security-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install marketcalls/openalgo security-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/security-audit .cursor/skills/security-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-audit" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/security-audit into .cursor/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/marketcalls/openalgo.git --path .claude/skills/security-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add marketcalls/openalgo --skill security-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install marketcalls/openalgo security-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/security-audit .gemini/skills/security-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/security-audit into .gemini/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install marketcalls/openalgo security-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add marketcalls/openalgo --skill security-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/security-audit .github/skills/security-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/security-audit into .github/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add marketcalls/openalgo --skill security-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install marketcalls/openalgo security-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/security-audit .opencode/skills/security-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/security-audit into .opencode/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-auditRun OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report.
Security Audit is an agent skill from marketcalls/openalgo. Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report. Use for the monthly or twice-monthly review, before a release, after a dependency bump, or when the user asks for a security check, vulnerability scan, or audit report.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `audit.py`).
It sits in Security, covering Security review and Excel spreadsheets. It works with Microsoft Excel. The repository describes itself as: Open Source Algo Trading Platform for Everyone. The licence is AGPL-3.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1dcfff5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (Python), which the agent can run.
Shell commands in SKILL.md call:
npmuvFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm and uv, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
APP_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Audit loads about 1.9k tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 967 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from marketcalls/openalgo at commit 1dcfff5, republished under its AGPL-3.0 licence (© marketcalls). 967 words, ~1,880 tokens.
.claude/skills/security-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Run monthly (or twice monthly), and additionally before any release and after any dependency bump.
uv run --with openpyxl python .claude/skills/security-audit/audit.pyWrites tmp/security-audits/<YYYY-MM>/security_audit_<date>_<time>.xlsx.
tmp/ is gitignored and holds reports only — the script keeps its own scratch
files in the OS temp dir. Exit code is 0 when no CRITICAL/HIGH check is failing,
1 otherwise, so it drops into CI unchanged.
The script is read-only. It never rotates a key, edits config, or touches
the database, and the report never contains a secret value — only pass/fail, a
sha256: fingerprint, and a remediation pointer. That means the xlsx is safe to
share with someone helping you triage.
| Area | Checks |
|---|---|
| Secrets | APP_KEY/API_KEY_PEPPER present, full-entropy, and not one of the publicly-known leaked values shipped before v2.0.0.6; no credentials tracked in git; detect-secrets sweep |
| Runtime posture | FLASK_DEBUG off; remote MCP never with debug; CSRF on; CSP enforcing (not report-only); CORS not wildcard-with-credentials; HTTPS; ngrok off; rate limits set |
| Routes | All 461 blueprint routes checked for @check_session_validity / rate limiting against an allowlist of intentionally-public paths; state-changing routes reported separately; test/debug surfaces flagged |
| Database | File permissions; Fernet encryption of broker tokens; peppered API keys; NullPool (never StaticPool); engines created via engine_factory; backup presence |
| Cache | Credential caches must have an explicit bounded TTL; auth-change invalidation available; the ZMQ invalidation publisher must connect(), never bind() |
| Backend code | eval/exec, shell=True, pickle/yaml deserialization, raw-SQL f-strings, path traversal, SSRF, open redirect, weak hashes, verify=False, missing HTTP timeouts |
| Frontend | dangerouslySetInnerHTML, innerHTML, eval/new Function, credentials in browser storage, hardcoded key literals, plain-http endpoints, source maps in dist/, npm audit |
| Dependencies | pip-audit (Python) and npm audit (JS) — two separate ecosystems, both required |
| Static analysis | bandit, triaged rather than dumped |
Six sheets: Summary, Findings (colour-coded by status), Code patterns, Frontend patterns, Routes (unprotected), Bandit (triaged), Manual review.
Statuses mean different things and should be worked in this order:
Do not treat counts as scores. Bandit produces ~930 raw findings on this
repo and roughly 5 matter; the rest are asserts and try/except/pass. The
script does that triage for you and reports all three numbers so you can see the
ratio. Same for the route check: 461 routes, ~119 without decorators, and almost
all of those are legitimately public — which is why the allowlist exists.
Raw SQL f-strings. All current hits interpolate table and column names
(SQLite cannot parameterize those) from module-level literals in migration code,
e.g. _migrate_mode_unique(ScalpingSLState, "scalping_sl_state"). That is safe.
The check exists to catch the day someone interpolates a request value. Trace
each new hit to its source; if it is not a developer-controlled constant, it is
a real injection.
Direct create_engine calls. Mostly in broker database/master_contract_db.py
modules. These bypass engine_factory and therefore the NullPool guarantee — an
FD-hygiene and availability issue rather than a breach. Worth converging over
time; see the fd-audit skill.
Credential caches. database/telegram_db.py holds
_user_credentials_cache with a 30-minute TTL. Broker tokens roll over at
~3 AM IST, so confirm no auth cache outlives that boundary and that logout or
revoke invalidates it.
Unprotected routes. Genuinely public ones (React SPA shells, /login,
.well-known, broker callbacks, token-authenticated webhooks and postbacks) are
on PUBLIC_ROUTE_ALLOWLIST in the script. When you add a legitimately public
route, add it there with a reason — that keeps the check meaningful instead
of noisy.
detect-secrets candidates. High false-positive rate on this repo. Triage
once, then commit a .secrets.baseline so subsequent audits only surface
new candidates.
Credentials in browser storage. The current hit is
localStorage.setItem('pocketful_oauth_state', ...), which is an OAuth CSRF
state token — the correct use of localStorage. An auth token or API key there
would not be.
The Manual review sheet lists twelve items that need a human and an authenticated session — they are part of the audit, not optional extras. The ones most specific to this platform:
API_KEY_PEPPER on a populated database; it invalidates every password hash and encrypted token. Use upgrade/rotate_pepper.py.OpenAlgo is single-user and self-hosted: one user, one broker session per instance, no privilege escalation and no SaaS component. Server access equals full control, which is why filesystem permissions, secret hygiene and network exposure carry more weight here than classic multi-tenant concerns like IDOR or role bypass. Weight your triage accordingly.
Add a check by writing one function that calls
add(check, severity, status, detail, remediation, evidence) and wiring it into
main(). Keep three properties:
fingerprint().tmp/security-audits/ — scratch goes to tempfile.When a REVIEW item is confirmed benign and will stay benign, encode that as an allowlist entry or a narrowed pattern rather than re-triaging it every month.
© marketcalls, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .claude/skills/security-audit of marketcalls/openalgo.
Open the folder on GitHubat commit 1dcfff5
Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Audit this skillmarketcalls/openalgo | 2.8k | — | ~1.9k | Automated safety check: Pass | AGPL-3.0 | |
| Host Cve Validatorinfometa/workbuddyskills | 346 | — | ~1.8k | Automated safety check: Notes | Proprietary | |
| Soeinfometa/workbuddyskills | 346 | — | ~2.3k | Automated safety check: Notes | None | |
| Vul Analyseinfometa/workbuddyskills | 346 | — | ~3.9k | Automated safety check: Pass | None | |
| Container Cve Fix Validatorinfometa/workbuddyskills | 346 | — | ~779 | Automated safety check: Notes | Apache-2.0 | |
| Web Xxes0ld13rr/pentestcode | 828 | — | ~585 | Automated safety check: Pass | MIT |
infometa/workbuddyskills
主机安全CVE漏洞修复验证引擎。从主机漏扫报告(Excel)或CVE编号自动提取漏洞,查询威胁情报(NVD/EPSS/MSRC/OVAL),生成修复脚本(fix.sh/fix.ps1),SSH验证脚本可执行性,产出修复验证报告。覆盖 Linux(centos/ubuntu/debian/suse/amazon/fedora/alpine/arch) + Windows + Web-CMS…
infometa/workbuddyskills
This skill should be used when the user asks to "analyze security alerts", "parse vulnerability scan report", "analyze vulnerability scan report", "verify CVE fix", "analyze WAF attack log"…
infometa/workbuddyskills
漏扫报告分析 Skill。输入主流厂商漏扫报告(绿盟/深信服/悬镜/明鉴/等保/奇安信/启明/华云安/长亭/Nessus/Trivy/Grype/Snyk/OpenVAS 等 Excel/HTML/JSON/XML/.nessus 格式),自动提取漏洞并去重,可选对接知识库 Provider(修复历史)和威胁情报 Provider(CVE 情报),生成 7…
infometa/workbuddyskills
容器安全CVE漏洞修复验证引擎。从容器漏扫报告(Excel)自动提取漏洞,生成修复计划, SSH到测试环境验证OS包(apt/yum/apk)、Python(pip)、Node.js(npm)、Java(JAR)四种包类型的 修复方案,产出修复验证报告。不涉及主机层漏洞修复、不处理容器编排层安全配置。
s0ld13rr/pentestcode
XML External Entity injection detection→file-read/SSRF→proof for web apps.
transilienceai/communitytools
Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate…
marketcalls/openalgo
Integrate a new Indian broker into OpenAlgo, or modify an existing broker plugin.
marketcalls/openalgo
Audit a change for resource leaks in OpenAlgo — file descriptors AND unbounded memory growth.
marketcalls/openalgo
Build, edit or debug an OpenAlgo Flow workflow - the no-code node graph at /flow.
marketcalls/openalgo
Write an OpenScript study or strategy for OpenAlgo, and install it into strategies/openscript/ only after it compiles.
marketcalls/openalgo
Verify a claim before stating it, and verify a test before trusting it.
marketcalls/openalgo
Bump a version in the OpenAlgo repo. An agent skill from marketcalls/openalgo.
Works with
Categories
Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report. Security Audit is an agent skill from marketcalls/openalgo. Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report.
Security Audit fits situations like: twice-monthly review; before a release; after a dependency bump; the user asks for a security check.
Run `npx skills add marketcalls/openalgo --skill security-audit -a claude-code`. Or copy the skill folder (.claude/skills/security-audit in marketcalls/openalgo) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add marketcalls/openalgo --skill security-audit -a codex`. Or copy the skill folder (.claude/skills/security-audit in marketcalls/openalgo) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add marketcalls/openalgo --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.
Going by SKILL.md and its folder, Security Audit needs Python for the scripts in its folder, the command-line tools its instructions call (npm and uv) and credentials named APP_KEY. Our summary lists: Python 3; A credential in APP_KEY.
SKILL.md contains no URLs. Its commands use npm and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Audit is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Audit: Host Cve Validator (infometa/workbuddyskills, 346 stars), Soe (infometa/workbuddyskills, 346 stars), Vul Analyse (infometa/workbuddyskills, 346 stars) and Container Cve Fix Validator (infometa/workbuddyskills, 346 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
marketcalls (a GitHub user) maintains it in marketcalls/openalgo, which has 2,808 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 9, 2026.
Source: marketcalls/openalgo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.