Agent skill

Octopus Security Audit

by nyldn in nyldn/claude-octopus

OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

MITAuto-check passedSecurity

Install Octopus Security Audit

skills CLI
$ npx skills add nyldn/claude-octopus --skill octopus-security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nyldn/claude-octopus octopus-security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nyldn/claude-octopus.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/octopus-security-audit .claude/skills/octopus-security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
octopus-security-audit
GitHub stars
4.2k
Used in
1 other repo
Token cost
~2.3k tokens
SKILL.md length
764 words
Files
2
Skills in repo
62
Repo updated
First seen
Licence
MIT

At a glance

OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

  • Works in 4 steps: Blue Team (Defense): Codex reviews code,… → Red Team (Attack): Antigravity attempts… → Remediation (Fix): Codex patches all… → …
  • Security reviews
  • SKILL.md covers Execution Contract (MANDATORY…, Usage, Modes (Auto-Detected) and Model Selection Caveat: Fable…, plus 5 more sections
  • Calls git and bash

What it does

Octopus Security Audit is an agent skill from nyldn/claude-octopus. OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Security, covering Security review, Web application vulnerabilities and Vulnerability scanning. The repository describes itself as: Run multiple AI models against the same research, design, or coding task. Surface disagreements before you ship. The licence is MIT.

When your agent uses it

  • Security reviews
  • Tasks that involve Security review
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/octopus-security-audit”

Requirements

  • Docker

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Blue Team (Defense): Codex reviews code, identifies attack surface, proposes defenses
  2. Red Team (Attack): Antigravity attempts to break defenses, generates exploit PoCs
  3. Remediation (Fix): Codex patches all vulnerabilities found
  4. Validation (Verify): Antigravity re-tests, confirms fixes or fails

What it can do on your machine

Read from SKILL.md and the folder at commit c812f5e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Octopus Security Audit loads about 2.3k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 764 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nyldn/claude-octopus at commit c812f5e, republished under its MIT licence (© nyldn). 764 words, ~2,254 tokens.

Download SKILL.mdSave it as .claude/skills/octopus-security-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
octopus-security-audit
description
OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews
disable-model-invocation
true

Host: Codex CLI — This skill was designed for Claude Code and adapted for Codex. Cross-reference commands use installed skill names in Codex rather than /octo:* slash commands. Use the active Codex shell and subagent tools. Do not claim a provider, model, or host subagent is available until the current session exposes it. For host tool equivalents, see skills/blocks/codex-host-adapter.md.

Execution Contract (MANDATORY - CANNOT SKIP)

This generated Codex skill preserves an enforced workflow contract from the source skill.

PROHIBITED:

  • Do not summarize, simulate, or skip the referenced workflow command when this skill requires execution.
  • Do not claim provider output or validation artifacts exist without checking the actual files or command output.
  • Do not continue silently when a required provider, command, or host capability is unavailable; report the unavailable dependency and use a supported fallback.

Security Audit Skill

Your first output line MUST be: 🐙 **CLAUDE OCTOPUS ACTIVATED** - Security Audit

Invokes the security-auditor persona for thorough security analysis during the ink (deliver) phase. Supports both quick OWASP scanning and full adversarial red/blue team testing.

Usage

bash
# Quick scan via security-auditor persona
${HOME}/.claude-octopus/plugin/scripts/orchestrate.sh spawn security-auditor "Scan for SQL injection vulnerabilities"

# Adversarial red team via squeeze workflow
${HOME}/.claude-octopus/plugin/scripts/orchestrate.sh squeeze "Security audit the authentication module"

# Via auto-routing (detects security intent)
${HOME}/.claude-octopus/plugin/scripts/orchestrate.sh auto "security audit the payment processing module"

Modes (Auto-Detected)

ModeAuto-TriggerConfidence GateScope
Quick (default)Standard security scan, no sensitive files in diff8/10 — only high-confidence findingsChanged files only
Deep (auto-escalated)Diff touches auth/security/CI files, OR explicit request2/10 — flag anything suspiciousEntire codebase

Auto-escalation to Deep mode: The skill automatically switches to Deep mode when ANY of these are true:

  • Diff includes files matching: *auth*, *login*, *password*, *session*, *token*, *secret*, *crypt*, *oauth*, *saml*, *jwt*, *permission*, *rbac*, *acl*
  • Diff includes CI/CD files: .github/workflows/*, Dockerfile*, docker-compose*, .gitlab-ci*
  • Diff includes dependency files: package-lock.json, yarn.lock, Gemfile.lock, requirements.txt, go.sum
  • The user explicitly says "deep", "full", "comprehensive", or "CSO"

No user action needed — mode detection happens automatically from the git diff context.

Model Selection Caveat: Fable 5.1

By default, do not dispatch security-audit passes to Claude Fable 5.1 or the preserved Fable 5 ID. Their safety classifiers can refuse adversarial red-team phrasing in authorized audits. Route these passes to OCTOPUS_FABLE5_FALLBACK_MODEL (default claude-opus-5) and keep prompts defensively framed (find and report vulnerabilities; do not request working exploits). Reject an exact model-qualified override that targets claude-fable-5-1 or claude-fable-5. On refusal, retry exactly once on the fallback unless OCTOPUS_FABLE5_NO_RETRY=1; when retries are disabled or the retry refuses, surface the refusal without further dispatches. OCTOPUS_FABLE5_MODE=off is the explicit exception: it disables automatic rerouting for ordinary environment pins, while exact Fable security seats still fail closed. Details: skills/blocks/fable5-prompting.md.

Capabilities

Core (both modes)
  • OWASP Top 10 vulnerability detection
  • SQL injection and XSS scanning
  • Authentication/authorization review
  • Secrets and credential detection
  • Dependency vulnerability assessment
  • Security configuration review
Secrets Archaeology (Deep mode)

Scan git history for leaked credentials that may have been "deleted" but remain in commits:

bash
# Search git history for common secret patterns
git log --all -p --diff-filter=D -- '*.env' '*.key' '*.pem' 2>/dev/null | head -200
git log --all -p -S 'AKIA' --pickaxe-regex 2>/dev/null | head -100  # AWS keys
git log --all -p -S 'sk-[a-zA-Z0-9]{20,}' --pickaxe-regex 2>/dev/null | head -100  # API keys
git log --all -p -S 'ghp_|gho_|github_pat_' --pickaxe-regex 2>/dev/null | head -100  # GitHub tokens
git log --all -p -S 'password\s*[:=]' --pickaxe-regex 2>/dev/null | head -100  # Passwords

Report any findings with the commit SHA, file, and recommendation to rotate the credential.

Show full SKILL.md (311 more words)Show less
CI/CD Pipeline Security (Deep mode)

Audit GitHub Actions and CI configuration for injection and privilege escalation:

bash
# Find all workflow files
find .github/workflows -name '*.yml' -o -name '*.yaml' 2>/dev/null

# Check for dangerous patterns:
# 1. Untrusted input in run: blocks (command injection via PR titles/branch names)
# 2. pull_request_target with checkout of PR code (code execution from forks)
# 3. Overly broad permissions (write-all, contents: write)
# 4. Missing pinned action versions (uses: actions/checkout vs actions/checkout@v4)
# 5. Secrets exposed to pull_request events (accessible to forks)

Flag each finding with severity (CRITICAL/HIGH/MEDIUM/LOW).

Skill & Plugin Supply Chain (Deep mode)

Verify integrity of installed Claude Code skills and plugins:

bash
# List installed plugins
ls -la ~/.claude/plugins/ 2>/dev/null

# Check for skills that execute arbitrary bash
grep -r 'exec\|eval\|bash -c' ~/.claude/skills/*/SKILL.md 2>/dev/null | head -20

# Verify plugin sources (are they from known registries?)
cat ~/.claude/plugins/*/plugin.json 2>/dev/null | grep -E '"source"|"registry"'
STRIDE Threat Modeling (Deep mode)

For the target component, enumerate threats across all 6 STRIDE categories:

CategoryQuestion
SpoofingCan an attacker impersonate a user or component?
TamperingCan data be modified in transit or at rest?
RepudiationCan actions be denied without audit trail?
Information DisclosureCan sensitive data leak through logs, errors, or side channels?
Denial of ServiceCan the service be overwhelmed or starved?
Elevation of PrivilegeCan a low-privilege user gain admin access?

Persona Reference

This skill wraps the security-auditor persona defined in:

  • agents/personas/security-auditor.md
  • CLI: codex-review
  • Model: gpt-5.2-codex
  • Phases: ink
  • Expertise: owasp, vulnerability-scanning, security-review

Example Prompts

"Scan for hardcoded credentials in the codebase"
"Check for CSRF vulnerabilities in form handlers"
"Review the API authentication implementation"
"Red team review the payment API"

Adversarial Mode (squeeze workflow)

For comprehensive security testing, use the squeeze workflow which runs a 4-phase adversarial cycle:

  1. Blue Team (Defense): Codex reviews code, identifies attack surface, proposes defenses
  2. Red Team (Attack): Antigravity attempts to break defenses, generates exploit PoCs
  3. Remediation (Fix): Codex patches all vulnerabilities found
  4. Validation (Verify): Antigravity re-tests, confirms fixes or fails
bash
${HOME}/.claude-octopus/plugin/scripts/orchestrate.sh squeeze "[user's security request]"
OWASP Top 10 Coverage
  • Broken Access Control
  • Cryptographic Failures
  • Injection
  • Insecure Design
  • Security Misconfiguration
  • Vulnerable Components
  • Authentication Failures
  • Software Integrity Failures
  • Logging & Monitoring Failures
  • Server-Side Request Forgery
Additional Attack Patterns
  • Race conditions, business logic flaws
  • Denial of service, information disclosure
  • Client-side attacks (XSS, CSRF)
Advanced Options
bash
# Focus on specific vulnerabilities
${HOME}/.claude-octopus/plugin/scripts/orchestrate.sh squeeze --principles security "Audit for auth bypass only"

# Loop until all vulnerabilities fixed
${HOME}/.claude-octopus/plugin/scripts/orchestrate.sh squeeze --loop --quality 100 "Zero tolerance audit"
When to Use Adversarial Mode
AspectQuick Scan (spawn)Adversarial (squeeze)
Speed1-2 min5-10 min
DepthSingle perspectiveBlue + Red team
OutputIssue listExploit PoCs + fixes
Best forPre-commit checksPre-deployment review

When NOT to Use This

  • Production systems (use real pentest tools)
  • Compliance audits (use certified auditors)
  • Legal verification (consult security lawyers)

Do use for: pre-commit security checks, development-phase testing, architecture security review, CI/CD security gates.

© nyldn, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/octopus-security-audit of nyldn/claude-octopus.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit c812f5e

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in nyldn/claude-octopus, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Octopus Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Octopus Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Octopus Security Audit this skillnyldn/claude-octopus4.2k1 repos~2.3kAutomated safety check: PassMIT
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone
Security Audit Scannerruvnet/ruflo74k1 repos~823Automated safety check: PassMIT
Security Checkgocronx-team/gocron801—~690Automated safety check: PassMIT
Cyber NeoHainrixz/cyber-neo283—~5.9kAutomated safety check: WarnMIT

Similar skills

  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 1 repo~823 tokens
    SecurityAuto-check passed
  • Security Check

    gocronx-team/gocron

    Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities.

    801 GitHub stars~690 tokensUpdated yesterday
    SecurityAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    283 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Code Vuln Audit

    zebbern/claude-code-guide

    Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

    4.7k GitHub stars~1.3k tokensUpdated yesterday
    SecurityAuto-check passed

More from nyldn/claude-octopus

All 62 skills in this repo
  • Octopus Quick

    nyldn/claude-octopus

    Quick execution for ad-hoc tasks without full workflow overhead — use for small, self-contained requests

    4.2k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Octopus Research

    nyldn/claude-octopus

    Thorough research across multiple sources — use for complex topics needing broad synthesis

    4.2k GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Skill Audit

    nyldn/claude-octopus

    Audit codebases for quality, consistency, and broken patterns — use for pre-release or tech debt review

    4.2k GitHub starsUsed in 1 repo~3.2k tokens
    Auto-check passed
  • Skill Content Pipeline

    nyldn/claude-octopus

    Extract patterns and anatomy from URLs — use to reverse-engineer content strategies from live pages

    4.2k GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Skill Context Detection

    nyldn/claude-octopus

    Auto-detect work context (Dev vs Knowledge) — use to tailor workflows based on current task type

    4.2k GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check passed
  • Skill Decision Support

    nyldn/claude-octopus

    Present options with trade-offs for informed decision-making — use when choosing between approaches

    4.2k GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check passed

Categories

Questions about Octopus Security Audit

What does Octopus Security Audit do?

OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews. Octopus Security Audit is an agent skill from nyldn/claude-octopus.

When should I use Octopus Security Audit?

Octopus Security Audit fits situations like: security reviews; tasks that involve Security review; tasks that involve Web application vulnerabilities.

How do I install Octopus Security Audit in Claude Code?

Run `npx skills add nyldn/claude-octopus --skill octopus-security-audit -a claude-code`. Or copy the skill folder (skills/octopus-security-audit in nyldn/claude-octopus) into .claude/skills/octopus-security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Octopus Security Audit in Codex?

Run `npx skills add nyldn/claude-octopus --skill octopus-security-audit -a codex`. Or copy the skill folder (skills/octopus-security-audit in nyldn/claude-octopus) into .agents/skills/octopus-security-audit in your project. Codex loads it when a task matches its description.

Can I use Octopus Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nyldn/claude-octopus --skill octopus-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/octopus-security-audit, .gemini/skills/octopus-security-audit, .github/skills/octopus-security-audit and .opencode/skills/octopus-security-audit in your project.

What does Octopus Security Audit need to run?

Going by SKILL.md and its folder, Octopus Security Audit needs the command-line tools its instructions call (git and bash). Our summary lists: Docker.

Does Octopus Security Audit access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Octopus Security Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Octopus Security Audit use?

Octopus Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Octopus Security Audit use?

About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Octopus Security Audit?

Skills that share tags, products or a category with Octopus Security Audit: Security Auditor (eigent-ai/eigent, 15k stars), Code Audit (3stoneBrother/code-audit, 892 stars), Security Audit Scanner (ruvnet/ruflo, 74k stars) and Security Check (gocronx-team/gocron, 801 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Octopus Security Audit?

nyldn (a GitHub user) maintains it in nyldn/claude-octopus, which has 4,200 GitHub stars. The repository holds 62 skills in this directory. The repository was last updated on October 11, 2026.

Source: nyldn/claude-octopus on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.