Agent skill

Code Audit

by 3stoneBrother in 3stoneBrother/code-audit

Professional code security audit skill covering 55+ vulnerability types.

No licenceAuto-check passedSecurity

Install Code Audit

skills CLI
$ npx skills add 3stoneBrother/code-audit --skill code-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install 3stoneBrother/code-audit code-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-audit
GitHub stars
893
Used in
1 other repo
Token cost
~2.7k tokens
SKILL.md length
511 words
Files
120 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
None found

At a glance

Professional code security audit skill covering 55+ vulnerability types.

  • Works in 6 steps: 模式判定 → 文档加载 → 侦察(Reconnaissance) → …
  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers When to Use This Skill, Quick Reference, Execution Controller(执行控制器 —… and Anti-Hallucination Rules (MUST…, plus 6 more sections
  • Calls docker-compose and docker

What it does

Code Audit is an agent skill from 3stoneBrother/code-audit. Professional code security audit skill covering 55+ vulnerability types. Enhanced with WooYun 88,636 real-world vulnerability cases (2010-2016). This skill should be used when performing security audits, vulnerability scanning, penetration testing preparation, or code review for security issues. Supports 9 languages: Java, Python, Go, PHP, JavaScript/Node.js, C/C++, .NET/C, Ruby, Rust. Includes 143 mandatory detection items across all languages with language-specific checklists. Covers SQL injection, XSS, RCE…

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 124 other files, including reference files (for example `README.md`, `README_CN.md` and `agent.md`).

It sits in Security, covering Web application vulnerabilities, Security review and Vulnerability scanning. It works with Docker, C#, C++ and Java.

When your agent uses it

  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Security review
  • Tasks that involve Vulnerability scanning

Example prompts

  • “/code-audit”

Requirements

  • Python 3
  • Node.js
  • Docker

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. 模式判定
  2. 文档加载
  3. 侦察(Reconnaissance)
  4. 执行计划 → STOP
  5. 执行
  6. 报告门控

What it can do on your machine

Read from SKILL.md and the folder at commit 6f88ae3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker-compose
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Audit loads about 2.7k tokens when it runs, and up to ~466k if it reads all its reference files. Until then it costs about 233 tokens; SKILL.md has 511 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~233
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~466k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 511 words (~2,653 tokens).

“This skill should be used when:”

— opening of SKILL.md by 3stoneBrother
name
code-audit
tools
Read, Grep, Glob, Bash, Task, LSP
model
sonnet
priority
high
file_patterns
**/*.java, **/*.py, **/*.go, **/*.php, **/*.js, **/*.ts, **/*.jsx, **/*.tsx, **/*.c, **/*.cpp, **/*.h, **/*.cs, **/*.rb, **/*.rs, **/*.xml, **/*.yml…
exclude_patterns
**/node_references/**, **/vendor/**, **/dist/**, **/build/**, **/.git/**, **/test/**, **/tests/**, **/__pycache__/**

Read the full SKILL.md on GitHub

Files

SKILL.md and 119 other files (references) in the repository root of 3stoneBrother/code-audit.

  • SKILL.md
  • README.md
  • README_CN.md
  • agent.md
  • image/wechat.png
  • references/adapters/go.yaml
  • references/adapters/java.yaml
  • references/adapters/javascript.yaml
  • references/adapters/php.yaml
  • references/adapters/python.yaml
  • references/cases/real_world_vulns.md
  • references/checklists/c_cpp.md
  • references/checklists/coverage_matrix.md
  • references/checklists/dotnet.md
  • references/checklists/go.md
  • references/checklists/java.md
  • … and 104 more

Open the folder on GitHubat commit 6f88ae3

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in 3stoneBrother/code-audit, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Code Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Audit this skill3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Security Analyzeraiskillstore/marketplace430—~1.2kAutomated safety check: NotesNone
Constant Time Analysissickn33/agentic-awesome-skills47k2 repos~2.4kAutomated safety check: PassMIT
Cyberowlaikarimhabush/cyberowl263—~2.5kAutomated safety check: PassMIT

Similar skills

  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    430 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check: notes
  • Constant Time Analysis

    sickn33/agentic-awesome-skills

    Analyze cryptographic code to detect operations that leak secret data through execution timing variations.

    47k GitHub starsUsed in 2 repos~2.4k tokens
    MobileAuto-check passed
  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    281 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings

Categories

Questions about Code Audit

What does Code Audit do?

Professional code security audit skill covering 55+ vulnerability types. Code Audit is an agent skill from 3stoneBrother/code-audit. Professional code security audit skill covering 55+ vulnerability types.

When should I use Code Audit?

Code Audit fits situations like: tasks that involve Web application vulnerabilities; tasks that involve Security review; tasks that involve Vulnerability scanning.

How do I install Code Audit in Claude Code?

Run `npx skills add 3stoneBrother/code-audit --skill code-audit -a claude-code`. Or copy the skill folder (the 3stoneBrother/code-audit repository) into .claude/skills/code-audit in your project. Claude Code loads it when a task matches its description.

How do I install Code Audit in Codex?

Run `npx skills add 3stoneBrother/code-audit --skill code-audit -a codex`. Or copy the skill folder (the 3stoneBrother/code-audit repository) into .agents/skills/code-audit in your project. Codex loads it when a task matches its description.

Can I use Code Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add 3stoneBrother/code-audit --skill code-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-audit, .gemini/skills/code-audit, .github/skills/code-audit and .opencode/skills/code-audit in your project.

What does Code Audit need to run?

Going by SKILL.md and its folder, Code Audit needs the command-line tools its instructions call (docker-compose and docker). Our summary lists: Python 3; Node.js; Docker.

Does Code Audit access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Audit use?

No licence was found for Code Audit or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Code Audit use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 464k tokens, read only when the agent opens those files.

What are the alternatives to Code Audit?

Skills that share tags, products or a category with Code Audit: Security Review (github/awesome-copilot, 40k stars), CodeQL Security Scan (trailofbits/skills, 7.4k stars), Security Analyzer (aiskillstore/marketplace, 430 stars) and Constant Time Analysis (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Audit?

3stoneBrother (a GitHub user) maintains it in 3stoneBrother/code-audit, which has 893 GitHub stars. The repository was last updated on February 13, 2026.

Source: 3stoneBrother/code-audit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.