Agent skill

Security Audit Example

by Microck in Microck/ordinary-claude-skills

Example security audit skill demonstrating how to audit code for security vulnerabilities.

Custom licenceAuto-check passedSecurity

Install Security Audit Example

skills CLI
$ npx skills add Microck/ordinary-claude-skills --skill security-audit-example -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Microck/ordinary-claude-skills security-audit-example --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Microck/ordinary-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills_all/security-audit-example .claude/skills/security-audit-example && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-audit-example
GitHub stars
401
Token cost
~758 tokens
SKILL.md length
294 words
Files
2
Skills in repo
97
Repo updated
First seen
Licence
Custom licence

At a glance

Example security audit skill demonstrating how to audit code for security vulnerabilities.

  • Works in 4 steps: Code Review → Dependency Check → Configuration Review → …
  • The user asks to perform security reviews
  • SKILL.md covers Instructions, Audit Focus Areas, Audit Process and Common Vulnerabilities to Check, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Audit Example is an agent skill from Microck/ordinary-claude-skills. Example security audit skill demonstrating how to audit code for security vulnerabilities. Use when the user asks to perform security reviews, check for vulnerabilities, or audit code security.

Its SKILL.md is about 760 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `metadata.json`).

It sits in Security, covering Security review. The repository describes itself as: An unappealing collection of Claude Skills and resources.

When your agent uses it

  • The user asks to perform security reviews
  • Check for vulnerabilities
  • Audit code security

Example prompts

  • “/security-audit-example”

Requirements

  • Pre-approved tools (allowed-tools): read_file, grep_search, list_directory

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Code Review
  2. Dependency Check
  3. Configuration Review
  4. Vulnerability Assessment

What it can do on your machine

Read from SKILL.md and the folder at commit 1056d29. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • read_file
    • grep_search
    • list_directory

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Audit Example loads about 758 tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 294 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~758

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 294 words (~758 tokens).

“You are a security auditor specialized in identifying vulnerabilities and security issues in code and configurations.”

— opening of SKILL.md by Microck, Custom licence
name
security-audit-example
allowed-tools
read_file, grep_search, list_directory

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file in skills_all/security-audit-example of Microck/ordinary-claude-skills.

  • SKILL.md
  • metadata.json

Open the folder on GitHubat commit 1056d29

Compare with similar skills

Security Audit Example next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Audit Example compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Audit Example this skillMicrock/ordinary-claude-skills401—~758Automated safety check: PassCustom licence
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Skillward AuditFangcun-AI/SkillWard143—~2.9kAutomated safety check: PassCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated 7 days ago
    SecurityAuto-check: notes
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes

More from Microck/ordinary-claude-skills

All 97 skills in this repo
  • Every Style Editor

    Microck/ordinary-claude-skills

    This skill should be used when reviewing or editing copy to ensure adherence to Every's style guide.

    401 GitHub starsUsed in 3 repos~1.2k tokens
    Auto-check passed
  • Gemini Imagegen

    Microck/ordinary-claude-skills

    Generate and edit images using the Gemini API (Nano Banana Pro).

    401 GitHub starsUsed in 3 repos~1.6k tokens
    Auto-check passed
  • Andrew Kane Gem Writer

    Microck/ordinary-claude-skills

    Write Ruby gems following Andrew Kane's proven patterns and philosophy.

    401 GitHub starsUsed in 2 repos~1.2k tokens
    Auto-check passed
  • Codex

    Microck/ordinary-claude-skills

    Execute Codex CLI for code analysis, refactoring, and automated code changes.

    401 GitHub starsUsed in 2 repos~2.8k tokens
    Auto-check passed
  • Docs Review

    Microck/ordinary-claude-skills

    Review documentation changes for compliance with the Metabase writing style guide.

    401 GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check: notes
  • File Todos

    Microck/ordinary-claude-skills

    This skill should be used when managing the file-based todo tracking system in the todos/ directory.

    401 GitHub starsUsed in 2 repos~1.9k tokens
    Auto-check passed

Categories

Questions about Security Audit Example

What does Security Audit Example do?

Example security audit skill demonstrating how to audit code for security vulnerabilities. Security Audit Example is an agent skill from Microck/ordinary-claude-skills. Example security audit skill demonstrating how to audit code for security vulnerabilities.

When should I use Security Audit Example?

Security Audit Example fits situations like: the user asks to perform security reviews; check for vulnerabilities; audit code security.

How do I install Security Audit Example in Claude Code?

Run `npx skills add Microck/ordinary-claude-skills --skill security-audit-example -a claude-code`. Or copy the skill folder (skills_all/security-audit-example in Microck/ordinary-claude-skills) into .claude/skills/security-audit-example in your project. Claude Code loads it when a task matches its description.

How do I install Security Audit Example in Codex?

Run `npx skills add Microck/ordinary-claude-skills --skill security-audit-example -a codex`. Or copy the skill folder (skills_all/security-audit-example in Microck/ordinary-claude-skills) into .agents/skills/security-audit-example in your project. Codex loads it when a task matches its description.

Can I use Security Audit Example in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Microck/ordinary-claude-skills --skill security-audit-example -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit-example, .gemini/skills/security-audit-example, .github/skills/security-audit-example and .opencode/skills/security-audit-example in your project.

What does Security Audit Example need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Audit Example is instructions for the agent only. Its frontmatter pre-approves these tools: read_file, grep_search, list_directory.

Does Security Audit Example access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Audit Example safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Audit Example use?

Security Audit Example has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Security Audit Example use?

About 758 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Audit Example?

Skills that share tags, products or a category with Security Audit Example: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Semgrep Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Audit Example?

Microck (a GitHub user) maintains it in Microck/ordinary-claude-skills, which has 401 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on September 6, 2026.

Source: Microck/ordinary-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.