Agent skill

Security Audit

by aAAaqwq in aAAaqwq/AGI-Super-Team

Comprehensive security auditing for Clawdbot deployments. An agent skill from aAAaqwq/AGI-Super-Team.

MITAuto-check: notesSecurity

Install Security Audit

skills CLI
$ npx skills add aAAaqwq/AGI-Super-Team --skill security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aAAaqwq/AGI-Super-Team security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-audit .claude/skills/security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-audit
GitHub stars
105
Used in
2 other repos
Token cost
~619 tokens
SKILL.md length
180 words
Files
4 (incl. scripts)
Skills in repo
152
Repo updated
First seen
Licence
MIT

At a glance

Comprehensive security auditing for Clawdbot deployments. An agent skill from aAAaqwq/AGI-Super-Team.

  • Tasks that involve Security review
  • SKILL.md covers When to use, Setup, How to and Output, plus 3 more sections
  • Runs JavaScript scripts from its folder; calls node
  • Tasks that involve Secrets management

What it does

Security Audit is an agent skill from aAAaqwq/AGI-Super-Team. Comprehensive security auditing for Clawdbot deployments. Scans for exposed credentials, open ports, weak configs, and vulnerabilities. Auto-fix mode included.

Its SKILL.md is about 620 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts (for example `.clawhub/origin.json` and `_meta.json`).

It sits in Security, covering Security review, Secrets management and Deployment. The repository describes itself as: An installable, cross-framework AI organization: C-suite agents, expert subagents, curated skills, independent review, and one-command setup across 18 AI client/runtime adapters. The licence is MIT.

When your agent uses it

  • Tasks that involve Security review
  • Tasks that involve Secrets management
  • Tasks that involve Deployment

Example prompts

  • “/security-audit”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 331ecd3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Audit loads about 619 tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 180 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~619

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:95
    ets restrictive file permissions (600 on .env)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from aAAaqwq/AGI-Super-Team at commit 331ecd3, republished under its MIT licence (© aAAaqwq). 180 words, ~619 tokens.

Download SKILL.mdSave it as .claude/skills/security-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
security-audit
description
Comprehensive security auditing for Clawdbot deployments. Scans for exposed credentials, open ports, weak configs, and vulnerabilities. Auto-fix mode included.

Security Audit Skill

When to use

Run a security audit to identify vulnerabilities in your Clawdbot setup before deployment or on a schedule. Use auto-fix to remediate common issues automatically.

Setup

No external dependencies required. Uses native system tools where available.

How to

Quick audit (common issues)
bash
node skills/security-audit/scripts/audit.cjs
Full audit (comprehensive scan)
bash
node skills/security-audit/scripts/audit.cjs --full
Auto-fix common issues
bash
node skills/security-audit/scripts/audit.cjs --fix
Audit specific areas
bash
node skills/security-audit/scripts/audit.cjs --credentials      # Check for exposed API keys
node skills/security-audit/scripts/audit.cjs --ports            # Scan for open ports
node skills/security-audit/scripts/audit.cjs --configs          # Validate configuration
node skills/security-audit/scripts/audit.cjs --permissions      # Check file permissions
node skills/security-audit/scripts/audit.cjs --docker           # Docker security checks
Generate report
bash
node skills/security-audit/scripts/audit.cjs --full --json > audit-report.json

Output

The audit produces a report with:

LevelDescription
🔴 CRITICALImmediate action required (exposed credentials)
🟠 HIGHSignificant risk, fix soon
🟡 MEDIUMModerate concern
🟢 INFOFYI, no action needed

Checks Performed

Credentials
  • API keys in environment files
  • Tokens in command history
  • Hardcoded secrets in code
  • Weak password patterns
Ports
  • Unexpected open ports
  • Services exposed to internet
  • Missing firewall rules
Configs
  • Missing rate limiting
  • Disabled authentication
  • Default credentials
  • Open CORS policies
Files
  • World-readable files
  • Executable by anyone
  • Sensitive files in public dirs
Docker
  • Privileged containers
  • Missing resource limits
  • Root user in container

Auto-Fix

The --fix option automatically:

  • Sets restrictive file permissions (600 on .env)
  • Secures sensitive configuration files
  • Creates .gitignore if missing
  • Enables basic security headers
  • security-monitor - Real-time monitoring (available separately)

© aAAaqwq, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts) in skills/security-audit of aAAaqwq/AGI-Super-Team.

  • SKILL.md
  • .clawhub/origin.json
  • _meta.json
  • scripts/audit.cjs

Open the folder on GitHubat commit 331ecd3

Used in 2 other repositories

We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in aAAaqwq/AGI-Super-Team, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Audit this skillaAAaqwq/AGI-Super-Team1052 repos~619Automated safety check: NotesMIT
Robotics Securityarpitg1304/robotics-agent-skills368—~7.8kAutomated safety check: WarnApache-2.0
Vpn Security CheckSergei-thinker/vpn-setup189—~1.5kAutomated safety check: NotesMIT
Healthcheckunderstudy-ai/understudy461—~1.2kAutomated safety check: PassMIT
Healthchecktrpc-group/trpc-agent-go1.8k9 repos~2.6kAutomated safety check: PassApache-2.0
Security Review PRwarpdotdev/oz-for-oss3131 repos~2kAutomated safety check: NotesMIT

Similar skills

  • Robotics Security

    arpitg1304/robotics-agent-skills

    Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety intersection.

    368 GitHub stars~7.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: warnings
  • Vpn Security Check

    Sergei-thinker/vpn-setup

    Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup.

    189 GitHub stars~1.5k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Healthcheck

    understudy-ai/understudy

    Host security hardening and risk-tolerance guidance for Understudy deployments.

    461 GitHub stars~1.2k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Healthcheck

    trpc-group/trpc-agent-go

    Host security hardening and risk-tolerance configuration for OpenClaw deployments.

    1.8k GitHub starsUsed in 9 repos~2.6k tokens
    SecurityAuto-check passed
  • Security Review PR

    warpdotdev/oz-for-oss

    Audit a pull request diff for common security concerns (input validation, sanitization, authentication and authorization, secrets management, unsafe dependencies, and related risks) and fold…

    313 GitHub starsUsed in 1 repo~2k tokens
    SecurityAuto-check: notes
  • Azure Compliance

    microsoft/GitHub-Copilot-for-Azure

    Official

    Run Azure compliance and security audits with azqr plus Key Vault expiration checks.

    255 GitHub starsUsed in 2 repos~997 tokens
    SecurityAuto-check passed

More from aAAaqwq/AGI-Super-Team

All 152 skills in this repo
  • Content Creator

    aAAaqwq/AGI-Super-Team

    Create SEO-optimized marketing content with consistent brand voice.

    105 GitHub starsUsed in 3 repos~1.9k tokens
    Auto-check passed
  • Financial Calculator

    aAAaqwq/AGI-Super-Team

    Advanced financial calculator with future value tables, present value, discount calculations, markup pricing, and compound interest.

    105 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Frontend Design Ultimate

    aAAaqwq/AGI-Super-Team

    Create distinctive, production-grade static sites with React, Tailwind CSS, and shadcn/ui — no mockups needed.

    105 GitHub starsUsed in 2 repos~2.7k tokens
    Auto-check passed
  • Sysadmin Toolbox

    aAAaqwq/AGI-Super-Team

    Tool discovery and shell one-liner reference for sysadmin, DevOps, and security tasks.

    105 GitHub starsUsed in 2 repos~775 tokens
    Auto-check passed
  • Zsxq Smart Publish

    aAAaqwq/AGI-Super-Team

    Publish and manage content on 知识星球 (zsxq.com). An agent skill from aAAaqwq/AGI-Super-Team.

    105 GitHub stars~1.5k tokensUpdated 10 days ago
    Auto-check passed
  • Content Extract

    aAAaqwq/AGI-Super-Team

    Robust URL-to-Markdown extraction for OpenClaw workflows. An agent skill from aAAaqwq/AGI-Super-Team.

    105 GitHub starsUsed in 1 repo~650 tokens
    Auto-check passed

Questions about Security Audit

What does Security Audit do?

Comprehensive security auditing for Clawdbot deployments. An agent skill from aAAaqwq/AGI-Super-Team. Security Audit is an agent skill from aAAaqwq/AGI-Super-Team. Comprehensive security auditing for Clawdbot deployments.

When should I use Security Audit?

Security Audit fits situations like: tasks that involve Security review; tasks that involve Secrets management; tasks that involve Deployment.

How do I install Security Audit in Claude Code?

Run `npx skills add aAAaqwq/AGI-Super-Team --skill security-audit -a claude-code`. Or copy the skill folder (skills/security-audit in aAAaqwq/AGI-Super-Team) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Security Audit in Codex?

Run `npx skills add aAAaqwq/AGI-Super-Team --skill security-audit -a codex`. Or copy the skill folder (skills/security-audit in aAAaqwq/AGI-Super-Team) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.

Can I use Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aAAaqwq/AGI-Super-Team --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.

What does Security Audit need to run?

Going by SKILL.md and its folder, Security Audit needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Docker.

Does Security Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Audit use?

Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Audit use?

About 619 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Audit?

Skills that share tags, products or a category with Security Audit: Robotics Security (arpitg1304/robotics-agent-skills, 368 stars), Vpn Security Check (Sergei-thinker/vpn-setup, 189 stars), Healthcheck (understudy-ai/understudy, 461 stars) and Healthcheck (trpc-group/trpc-agent-go, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Audit?

aAAaqwq (a GitHub user) maintains it in aAAaqwq/AGI-Super-Team, which has 105 GitHub stars. The repository holds 152 skills in this directory. The repository was last updated on September 27, 2026.

Source: aAAaqwq/AGI-Super-Team on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.