Security Audit
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection.
$ npx skills add openJiuwen-ai/agent-core --skill security-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install openJiuwen-ai/agent-core security-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/openJiuwen-ai/agent-core.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/security-review .claude/skills/security-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-review" agent skill from https://github.com/openJiuwen-ai/agent-core/tree/develop/.claude/skills/security-review into .claude/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/openJiuwen-ai/agent-core/tree/develop/.claude/skills/security-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add openJiuwen-ai/agent-core --skill security-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install openJiuwen-ai/agent-core security-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openJiuwen-ai/agent-core.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/security-review .agents/skills/security-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-review" agent skill from https://github.com/openJiuwen-ai/agent-core/tree/develop/.claude/skills/security-review into .agents/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openJiuwen-ai/agent-core --skill security-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install openJiuwen-ai/agent-core security-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openJiuwen-ai/agent-core.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/security-review .cursor/skills/security-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-review" agent skill from https://github.com/openJiuwen-ai/agent-core/tree/develop/.claude/skills/security-review into .cursor/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/openJiuwen-ai/agent-core.git --path .claude/skills/security-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add openJiuwen-ai/agent-core --skill security-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install openJiuwen-ai/agent-core security-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openJiuwen-ai/agent-core.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/security-review .gemini/skills/security-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-review" agent skill from https://github.com/openJiuwen-ai/agent-core/tree/develop/.claude/skills/security-review into .gemini/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install openJiuwen-ai/agent-core security-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add openJiuwen-ai/agent-core --skill security-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/openJiuwen-ai/agent-core.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/security-review .github/skills/security-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-review" agent skill from https://github.com/openJiuwen-ai/agent-core/tree/develop/.claude/skills/security-review into .github/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openJiuwen-ai/agent-core --skill security-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install openJiuwen-ai/agent-core security-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openJiuwen-ai/agent-core.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/security-review .opencode/skills/security-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-review" agent skill from https://github.com/openJiuwen-ai/agent-core/tree/develop/.claude/skills/security-review into .opencode/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-reviewA ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection.
This skill gives the agent a checklist of ten categories to run before a security-sensitive change or PR in the agent-core Python project. Each category states a rule and a set of checkboxes. Secrets management says credentials never enter source code, come from environment variables, keep .env files out of version control, and use mock defaults in tests. Input validation requires file paths to pass the project's safe_path helpers, rejects paths containing parent-directory segments, and builds shell commands through parameterized APIs.
SQL injection rules call for parameterized queries and allowlists for any dynamic table or column names. Authentication and RBAC rules require server-side enforcement, permission checks on every code path and resource limits. The prompt injection section keeps user strings out of system prompts without sanitization and separates user content from instructions in templates. The excerpt is cut off partway through that section, and a checklist.md file ships alongside.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9824919. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python and bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
API_KEYOPENAI_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Agent-Core Security Checklist loads about 1.7k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 538 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- [ ] `.env` files not committed (already in `.gitignore` — do not remove)`settings.json` deny rules block `Read(./.env)` and `Read(./**/secrets/**)`Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from openJiuwen-ai/agent-core at commit 9824919, republished under its Apache-2.0 licence (© openJiuwen-ai). 538 words, ~1,744 tokens.
.claude/skills/security-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Comprehensive security checklist for agent-core. Run through all 10 categories before any security-sensitive change or PR.
See .claude/rules/python/security.md for tool-specific guidance (bandit, pip-audit).
See .claude/rules/security.md for credential, sandbox, and shell execution rules.
Rule: Credentials never enter source code.
.py filesos.getenv().env files not committed (already in .gitignore — do not remove)settings.json deny rules block Read(./.env) and Read(./**/secrets/**)os.getenv("KEY", "mock-key-for-tests")# Bad
API_KEY = "sk-1234567890abcdef"
# Good
import os
API_KEY = os.getenv("OPENAI_API_KEY") # Must be set in environmentRule: Validate all external input before use.
safe_path utilities.. or resolve outside allowed scopeFor sys_operation:
from openjiuwen.core.common.security import safe_path
def execute_command(user_path: str, working_dir: Path) -> None:
validated = safe_path(user_path, allowed_base=working_dir)
if validated is None:
raise SecurityError(f"Path outside allowed scope: {user_path}")
# Proceed with validated pathRule: Use parameterized queries for all database operations.
f"SELECT * FROM {table}" is forbidden"WHERE id = ?", (id,)# Bad
cursor.execute(f"SELECT * FROM {table_name} WHERE id = {user_id}")
# Good
cursor.execute(
"SELECT * FROM sessions WHERE id = ?",
(session_id,)
)Rule: Access control must be enforced server-side, not just client-side.
core/security/openjiuwen/core/security/ verify permissions before executionRule: openjiuwen/harness/prompts/ must guard against injected user content.
openjiuwen/harness/rails/) correctly blocks dangerous patternsPrompt injection is agent-core's most unique security concern. Attackers may try to inject instructions into conversation history to manipulate agent behavior:
# Bad — user content injected into system prompt
system_prompt = f"You are a helpful assistant. User said: {user_message}"
# Good — user content kept in separate context slot
system_prompt = SYSTEM_INSTRUCTIONS
context = {
"user_message": sanitize_for_display(user_message),
"conversation_history": conversation,
}Rule: All mutating requests include validation.
core/session/ validates that requests originate from legitimate sessionssecrets.token_urlsafe())Rule: Protect core/runner/ and core/runner/ resources from exhaustion.
Runner.resource_mgr enforces limits on concurrent agent executionsRule: Logs must not expose credentials, tokens, or sensitive data.
openjiuwen.core.common.logging used instead of print()# Bad
logger.info(f"Authenticated user {user_id} with token {token}")
# Good
logger.info("User authenticated", extra={"user_id": user_id})Rule: All dependencies scanned before merging PRs.
pip-auditbandit -r openjiuwen/ -ll passes (no HIGH/CRITICAL findings)core/sys_operation/ and core/security/ minimized# Run before merging dependency changes
pip-audit
bandit -r openjiuwen/ -llRule: core/sys_operation/sandbox/ must provide genuine isolation.
../)For sandbox implementations, verify:
# Path isolation
def sandbox_read(path: Path, allowed_base: Path) -> str:
resolved = (allowed_base / path).resolve()
if not resolved.is_relative_to(allowed_base):
raise SecurityError(f"Escape attempt: {path}")
return resolved.read_text()Before marking a security-sensitive PR as ready for review, run through all 10 categories above. Document the review in the PR description:
Security Review
===============
Secrets: PASS (no hardcoded credentials)
Input Val: PASS (safe_path used for all user paths)
SQL Injection: PASS (parameterized queries only)
Auth/RBAC: PASS (guardrails enforce permissions)
Prompt Inject: PASS (user content isolated from system prompts)
CSRF: PASS (session IDs are non-guessable)
Rate Limiting: PASS (resource_mgr enforces limits)
Log Safety: PASS (no credentials in structured logs)
Dependencies: PASS (bandit + pip-audit clean)
Sandbox: PASS (path scoping verified)For changes to core/security/, core/sys_operation/, or
openjiuwen/extensions/sys_operation/sandbox/, request a dedicated
security review from a second reviewer.
© openJiuwen-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .claude/skills/security-review of openJiuwen-ai/agent-core.
Open the folder on GitHubat commit 9824919
Agent-Core Security Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Agent-Core Security Checklist this skillopenJiuwen-ai/agent-core | 446 | — | ~1.7k | Automated safety check: Notes | Apache-2.0 | |
| Security AuditTheDecipherist/claude-code-mastery | 551 | — | ~1.3k | Automated safety check: Notes | MIT | |
| CodeQL Security Scantrailofbits/skills | 7.5k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Security Review ChecklistZeroDeng01/sublinkPro | 1.7k | — | ~2.3k | Automated safety check: Pass | MIT | |
| Python kwargs setattr Allowlistmicrosoft/onnxruntime | 22k | — | ~737 | Automated safety check: Pass | MIT | |
| Codewhale Security Reviewcodewhale-hq/Codewhale | 41k | — | ~844 | Automated safety check: Pass | MIT |
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
ZeroDeng01/sublinkPro
Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.
microsoft/onnxruntime
Shows how to replace unsafe hasattr and setattr loops over user-controlled kwargs with an explicit allowlist when configuring ONNX Runtime option objects.
codewhale-hq/Codewhale
Reviews a diff, module or network surface for exploitable defects, mapping trust boundaries and sinks, then reports only findings with a verified reachable path and a fix.
jellydn/my-ai-tools
A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.
openJiuwen-ai/agent-core
Static safety audit of a SKILL.md that scores five dimensions and acts as a gate: skills below the pass line do not ship, whatever else they score.
openJiuwen-ai/agent-core
Runs a read-only assessment in one of two modes, a repository health check or a runtime extension gap review, and reports findings as a markdown table.
openJiuwen-ai/agent-core
Chinese-language rules for how an agent writes commit messages, PR descriptions, session journals, handoff issues and requests for help.
openJiuwen-ai/agent-core
Reference for idiomatic Python in the agent-core codebase: immutability, protocols, exception hierarchies, context managers and async patterns.
openJiuwen-ai/agent-core
Pytest patterns for the agent-core codebase: a red-green-refactor workflow, conftest fixtures, custom marks, monkeypatch and patch mocking, and async tests.
openJiuwen-ai/agent-core
Formalizes agent-core's make check/type-check/test/fix pipeline into a structured 6-phase verification skill.
Works with
Categories
A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection. This skill gives the agent a checklist of ten categories to run before a security-sensitive change or PR in the agent-core Python project. Each category states a rule and a set of checkboxes.
Agent-Core Security Checklist fits situations like: reviewing a pull request that touches credentials, file paths, shell commands or SQL; checking agent capabilities for missing permission checks before merging; auditing prompt templates for user content that could be injected into instructions.
Run `npx skills add openJiuwen-ai/agent-core --skill security-review -a claude-code`. Or copy the skill folder (.claude/skills/security-review in openJiuwen-ai/agent-core) into .claude/skills/security-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add openJiuwen-ai/agent-core --skill security-review -a codex`. Or copy the skill folder (.claude/skills/security-review in openJiuwen-ai/agent-core) into .agents/skills/security-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openJiuwen-ai/agent-core --skill security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review, .gemini/skills/security-review, .github/skills/security-review and .opencode/skills/security-review in your project.
Going by SKILL.md and its folder, Agent-Core Security Checklist needs credentials named API_KEY and OPENAI_API_KEY.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Agent-Core Security Checklist is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Agent-Core Security Checklist: Security Audit (TheDecipherist/claude-code-mastery, 551 stars), CodeQL Security Scan (trailofbits/skills, 7.5k stars), Security Review Checklist (ZeroDeng01/sublinkPro, 1.7k stars) and Python kwargs setattr Allowlist (microsoft/onnxruntime, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
openJiuwen-ai (a GitHub organization) maintains it in openJiuwen-ai/agent-core, which has 446 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 11, 2026.
Source: openJiuwen-ai/agent-core on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.