Agent skill

Pyspector Security Audit

by ParzivalHack in ParzivalHack/PySpector

Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

Apache-2.0Auto-check: notesSecurity

Install Pyspector Security Audit

skills CLI
$ npx skills add ParzivalHack/PySpector --skill pyspector-security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ParzivalHack/PySpector pyspector-security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pyspector-security-audit
GitHub stars
151
Token cost
~3.5k tokens
SKILL.md length
1,855 words
Files
83 (incl. scripts)
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

  • Works in 7 steps: Check for / install PySpector → Verify the install → Learn the current CLI → …
  • The user asks for a security audit
  • SKILL.md covers Workflow overview, Step 1: Check for / install…, Step 2: Verify the install and Step 3: Learn the current CLI, plus 5 more sections
  • Runs Shell scripts from its folder; calls pip, cargo and python3; reaches sh.rustup.rs

What it does

Pyspector Security Audit is an agent skill from ParzivalHack/PySpector. Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. Use this skill whenever the user asks for a security audit, vulnerability scan, SAST scan, code security review, or dependency/CVE check of a Python codebase or repository, including phrasing like "check this repo for vulnerabilities," "is my code secure," "audit my project," "scan for CVEs," or "find security issues." Also trigger if the user mentions PySpector by name for any reason…

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 85 other files, including scripts (for example `.github/SECURITY.md`, `.pre-commit-config.yaml` and `.pre-commit-hooks.yaml`).

It sits in Security, covering Security review, Static analysis and SAST and Vulnerability scanning. It works with Python, Rust and GitHub. The repository describes itself as: PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. It leverages a powerful Rust core to deliver high-speed… The licence is Apache-2.0.

When your agent uses it

  • The user asks for a security audit
  • Vulnerability scan
  • Code security review
  • Dependency/CVE check of a Python codebase

Example prompts

  • “check this repo for vulnerabilities,”
  • “is my code secure,”
  • “audit my project,”
  • “/pyspector-security-audit”

Requirements

  • Python 3
  • A Bash shell

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Check for / install PySpector
  2. Verify the install
  3. Learn the current CLI
  4. Recon the codebase before choosing flags
  5. Run the scan
  6. Verify findings before reporting (static re-verification)
  7. Report

What it can do on your machine

Read from SKILL.md and the folder at commit a971f1f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • pip
    • cargo
    • python3
    • curl
    • sh
    • rustc
    • git
    • ollama

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • sh.rustup.rs

    Also links to:

    • rustup.rs

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pyspector Security Audit loads about 3.5k tokens when it runs. Until then it costs about 261 tokens; SKILL.md has 1,855 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~261
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePipes a well-known installer script into a shellSKILL.md:39
    cargo --version || (curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y && source "$HOME/.cargo/env"

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ParzivalHack/PySpector at commit a971f1f, republished under its Apache-2.0 licence (© ParzivalHack). 1,855 words, ~3,477 tokens.

Download SKILL.mdSave it as .claude/skills/pyspector-security-audit/SKILL.md (or your agent's skills folder). This skill also uses 82 other files; get the full folder from GitHub.
name
pyspector-security-audit
description
Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. Use this skill whenever the user asks for a security audit, vulnerability scan, SAST scan, code security review, or dependency/CVE check of a Python codebase or repository, including phrasing like "check this repo for vulnerabilities," "is my code secure," "audit my project," "scan for CVEs," or "find security issues." Also trigger if the user mentions PySpector by name for any reason (install, upgrade, run, configure). This skill installs PySpector (including its required Rust toolchain) if missing, selects scan flags based on what the codebase actually looks like, runs the scan, verifies findings against the real source before reporting them, and produces a report the user can read. Do not use this skill for non-Python codebases, for generic code review unrelated to security, or for fixing/patching vulnerabilities after the report already exists (that's a normal coding task).

PySpector Security Audit

Drive an end-to-end Python codebase security audit with PySpector: install, verify, learn the CLI, recon the codebase, scan with the right flags, verify, report.

PySpector is a Rust-core, Python-CLI SAST tool with a flow-sensitive, inter-procedural taint engine. Its ruleset spans regex (secrets/config), AST (anti-patterns), and graph/taint (data-flow vulnerability chains), plus optional AI/LLM-specific rules and dependency CVE checks. Full project context: https://github.com/ParzivalHack/PySpector

Workflow overview

  1. Check for an existing install; install if missing (including Rust)
  2. Confirm the install actually works
  3. Read pyspector --help and pyspector scan --help to get the real, current flag set. Never assume flags from this document alone
  4. Recon the target codebase to decide which optional rulesets apply
  5. Run the scan(s) with the right flags
  6. Statically re-verify the findings that matter before reporting anything
  7. Produce the report (HTML for a human, JSON if something downstream will parse it) and only show the user verified true positives

Treat steps 3 and 4 as mandatory even if you already "know" PySpector's flags from a previous run. The tool evolves, and --help output is ground truth. Never fabricate a flag that didn't show up in --help.

Step 1: Check for / install PySpector

Check first:

bash
pyspector --version || pip show pyspector

If it's missing, PySpector's own docs say the supported path is PyPI, not manual OS-specific binary downloads. There's no separate per-OS release artifact to fetch; pip install pyspector builds/pulls the right thing for the current platform. So "install it based on the OS the agent is running on" in practice means: pick the right shell/venv invocation for the OS, not a different download URL.

Rust toolchain (hard requirement). PySpector's Rust core means rustc and cargo must be present, the project's own FAQ states this explicitly. Check first, install only if missing.

On Linux/macOS:

bash
cargo --version || (curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y && source "$HOME/.cargo/env")

On Windows: first check whether rustc/cargo are already available. If not, check whether a rustup-init.exe installer is already present on the system (e.g. in the user's Downloads folder or a known path); if it is, run it. If no installer is present and you don't have shell access to the user's machine to download and run one yourself, don't try to fetch and execute an installer silently: direct the user to https://rustup.rs/ and ask them to download and run it themselves, then confirm back with you once it's done so you can proceed to verification.

Python. PySpector supports Python 3.9 to 3.14. The project recommends a dedicated venv (3.14 if available, but any supported version works):

bash
python3 -m venv venv
source venv/bin/activate   # Windows: .\venv\Scripts\Activate.ps1
pip install --upgrade pip
pip install pyspector

If a venv isn't appropriate for the environment you're in (e.g. an ephemeral agent sandbox), a plain pip install pyspector --break-system-packages (Linux) or pip install pyspector is fine. The venv is a recommendation for the human workflow, not a functional requirement for the scan itself.

Step 2: Verify the install

Don't proceed on faith. Confirm all of:

bash
rustc --version
cargo --version
python3 --version
pyspector --version

If any of these fail, stop and fix it before scanning. A broken Rust toolchain in particular will surface as a cryptic scan failure later rather than a clean error at install time.

Step 3: Learn the current CLI

Always run these before scanning, even if you recall the flags from a previous session, and treat their output as the only source of truth for what flags exist and what they do:

bash
pyspector --help
pyspector scan --help

Do not hardcode or assume a flag list. Parse whatever the live output actually shows: available options, their exact spelling, defaults, and descriptions. If something in this skill (like the decision rules below referencing --ai or --supply-chain) doesn't match what --help shows, trust --help.

Two commands surfaced by pyspector --help are interactive-only and out of scope for this skill's autonomous workflow:

  • pyspector triage <report.json>: an interactive TUI for a human to mark findings as false positives and save a .pyspector_baseline.json. Don't invoke this yourself; if the user wants to triage findings interactively, tell them to run it themselves in their own terminal. If a baseline file already exists in the repo root from a prior human triage session, subsequent scans will pick it up automatically and suppress previously dismissed findings.
  • pyspector watch <path>: continuous re-scan on file change, meant for a human to run in their own terminal during active development. Don't invoke this yourself; if relevant, tell the user they can run it themselves.

Step 4: Recon the codebase before choosing flags

Before scanning, spend a short pass understanding what you're actually looking at, then pick flags accordingly using whatever flags Step 3 actually confirmed exist. Don't just run a bare default scan.

Checks to run:

bash
# Age / maturity signals
git log -1 --format=%cd 2>/dev/null   # last commit date, if it's a git repo
find . -name "requirements*.txt" -o -name "pyproject.toml" -o -name "Pipfile*" -o -name "poetry.lock" | head

# Dependency pinning style (unpinned or very old pins : higher supply-chain risk)
cat requirements.txt 2>/dev/null || cat pyproject.toml 2>/dev/null

# AI/LLM usage signals
grep -RIl -E "openai|anthropic|langchain|llama[_-]index|transformers|litellm|ollama|cohere|google\.generativeai|vertexai" --include="*.py" . 2>/dev/null | head

Decision rules (apply these, and combine flags freely, they're not mutually exclusive):

  • Any signal of LLM/AI usage (imports above, or the codebase is a model-serving/agent project) : add the AI ruleset flag. Running it even when unsure is fine; the cost of an unnecessary ruleset is low.
  • Old codebase, unpinned/loosely-pinned dependencies, no lockfile, or clear supply-chain risk signals : the supply-chain CVE check flag is a good fit. This flag contacts the OSV.dev database directly to check dependencies against known CVEs, so it's not purely local and can very slightly increase scan time, on the order of a few seconds at most even on large codebases with many dependencies.
  • When it's genuinely unclear whether supply-chain checking is warranted : don't default to including it. Ask the user first, and mention that it queries OSV.dev and may add a small amount of time (up to a few seconds on large projects with many dependencies) to the scan.
  • Large codebases : not a concern by default. PySpector's Rust core comfortably handles very large codebases (hundreds of thousands of lines) at high throughput, so don't hesitate to run a full scan regardless of size.
  • First scan of a given codebase vs. later scans : PySpector caches the AST it builds during a scan, so the first scan of a given codebase will always take somewhat longer than later ones. Subsequent scans are substantially faster, even after the source has changed somewhat in the meantime. If you're re-scanning something you already scanned earlier in the session, mention that it should be quicker this time; if it's a first scan, mention that this initial pass is expected to take a bit longer than future ones.

Set severity threshold based on intent: for a genuine security audit, use the lowest severity threshold (see what --help shows as the default/lowest option) to see everything, then let the verification step (Step 6) do the filtering. Don't pre-filter by raising the severity threshold, since that would hide true positives from your own verification pass, not just noise.

Show full SKILL.md (775 more words)Show less

Step 5: Run the scan

Always emit JSON as the primary artifact, you need structured output to parse and verify findings programmatically. Generate HTML at the end for the human, from the same run or a parallel run with identical flags.

For a remote repository instead of a local path, PySpector's --url option works only with public GitHub and GitLab repositories. It cannot pull from private repos or other git hosts, so confirm the repo is public before relying on this path; if it's private, ask the user for local access to the code instead (a local clone or an uploaded copy).

Don't default to SARIF output for this workflow. SARIF exists for CI/CD ingestion into platforms like GitHub Code Scanning, which isn't the context here (per PySpector's own docs on SARIF). If the user says the output specifically needs to feed a downstream tool that expects SARIF, honor that instead, but default to JSON and HTML.

Step 6: Verify findings before reporting (static re-verification)

This is the step that turns "a scanner ran" into "a security audit." Do not hand the user PySpector's raw output as-is. SAST tools, PySpector included, will produce some false positives, especially on complex taint chains or when a sanitizer isn't recognized.

For every finding at MEDIUM severity or above (adjust the threshold down if the codebase is small enough to review everything):

  1. Open the actual flagged file at the actual flagged line(s) in the real codebase. Don't reason from the finding's description alone
  2. Trace the taint path the finding claims: confirm the source is genuinely attacker/externally-influenced input, and that it genuinely reaches the sink PySpector flagged
  3. Check for a sanitizer, validation, or escaping step between source and sink that the finding's summary doesn't account for
  4. Check surrounding context: is this dead code, a test fixture, or behind an auth/permission check that changes the real-world exploitability?
  5. For supply-chain (CVE) findings: confirm the installed/pinned version in the dependency file actually matches the vulnerable range the CVE applies to, not just that the package name matched
  6. Classify each reviewed finding as Confirmed true positive, False positive (explain why, in one line), or Needs human judgement (e.g. exploitability depends on deployment context you can't see from the code alone)

Only "Confirmed true positive" and "Needs human judgement" findings go in the final report to the user. Silently dropping false positives without explanation is fine for the summary, but keep your reasoning available if the user asks why a raw PySpector finding didn't make the cut.

Do not attempt to actually exploit anything (no live PoC execution, no reaching out to external services, no running injected payloads). This is a static re-read and reasoning pass only, not a penetration test.

Step 7: Report

Default to HTML when the deliverable is for the user to read, PySpector's own HTML report is fine to hand over directly, or you can write your own summary. Use JSON instead only if the user says the output needs to be consumed by another tool or script.

Your own summary to the user (in addition to, or instead of, PySpector's raw report) should include:

  • What was scanned, and which flags were used and why (tie back to what recon found, e.g. "used the AI ruleset because the project imports openai and langchain")
  • Total raw findings vs. verified true positives, so the user sees the verification happened
  • Each confirmed true positive: file, line, vulnerability class, why it's exploitable (the taint path), and severity
  • Anything flagged "needs human judgement" and why
  • Supply-chain CVEs, if that check was used: package, installed version, CVE ID, and whether a fixed version is available

If findings exist, offer to help fix them as a natural next step, but that's a separate task from the audit itself; don't start patching without the user asking.

Notes / gotchas

  • Always trust the live pyspector --help / pyspector scan --help output over anything written in this document
  • If the Rust toolchain install requires a shell restart or sourcing ~/.cargo/env, do that before retrying pyspector commands in the same session
  • A .pyspector_baseline.json in the repo root from a prior human triage session will suppress previously-dismissed findings automatically. Mention this to the user if the finding count looks lower than expected
  • pyspector watch and pyspector triage are interactive tools for the user to run themselves, never invoke them on the user's behalf
  • Remote scanning via --url only works for public GitHub/GitLab repos; for private repos, work from a local copy instead
  • The first scan of a given codebase builds an AST cache and will be slower than subsequent scans of the same codebase, even after minor source changes

© ParzivalHack, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 82 other files (scripts) in the repository root of ParzivalHack/PySpector.

  • SKILL.md
  • .dockerignore
  • .github/SECURITY.md
  • .gitignore
  • .pre-commit-config.yaml
  • .pre-commit-hooks.yaml
  • .satori.yml
  • CODE_OF_CONDUCT.md
  • CONTRIBUTING.md
  • Cargo.toml
  • Dockerfile
  • LICENSE
  • MANIFEST.in
  • NOTICE.md
  • README.md
  • benchmarks/speed/bandit.yml
  • benchmarks/speed/benchmark.sh
  • benchmarks/speed/benchmark_results_20260828_132828.csv
  • … and 65 more

Open the folder on GitHubat commit a971f1f

Compare with similar skills

Pyspector Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pyspector Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pyspector Security Audit this skillParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
SkepticRaoFoundation/subtensor389—~660Automated safety check: PassApache-2.0
Cyber NeoHainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT

Similar skills

  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated today
    SecurityAuto-check: notes
  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated today
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Skeptic

    RaoFoundation/subtensor

    Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

    389 GitHub stars~660 tokensUpdated today
    SecurityAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    281 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes

Categories

Questions about Pyspector Security Audit

What does Pyspector Security Audit do?

Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. Pyspector Security Audit is an agent skill from ParzivalHack/PySpector.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

When should I use Pyspector Security Audit?

Pyspector Security Audit fits situations like: the user asks for a security audit; vulnerability scan; code security review; dependency/CVE check of a Python codebase.

How do I install Pyspector Security Audit in Claude Code?

Run `npx skills add ParzivalHack/PySpector --skill pyspector-security-audit -a claude-code`. Or copy the skill folder (the ParzivalHack/PySpector repository) into .claude/skills/pyspector-security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Pyspector Security Audit in Codex?

Run `npx skills add ParzivalHack/PySpector --skill pyspector-security-audit -a codex`. Or copy the skill folder (the ParzivalHack/PySpector repository) into .agents/skills/pyspector-security-audit in your project. Codex loads it when a task matches its description.

Can I use Pyspector Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ParzivalHack/PySpector --skill pyspector-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pyspector-security-audit, .gemini/skills/pyspector-security-audit, .github/skills/pyspector-security-audit and .opencode/skills/pyspector-security-audit in your project.

What does Pyspector Security Audit need to run?

Going by SKILL.md and its folder, Pyspector Security Audit needs a shell for the scripts in its folder and the command-line tools its instructions call (pip, cargo, python3, curl, sh and rustc). Our summary lists: Python 3; A Bash shell.

Does Pyspector Security Audit access the network?

SKILL.md names 2 domains. In commands or code: sh.rustup.rs; the agent is likely to contact it when it follows the instructions. As links in the text: rustup.rs. This is read from the text; nothing was executed.

Is Pyspector Security Audit safe to install?

Our automated static check of SKILL.md found notes only (pipes a well-known installer script into a shell), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Pyspector Security Audit use?

Pyspector Security Audit is published under the Apache-2.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pyspector Security Audit use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pyspector Security Audit?

Skills that share tags, products or a category with Pyspector Security Audit: CodeQL Security Scan (trailofbits/skills, 7.4k stars), Kedro Security Review (kedro-org/kedro, 11k stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars) and Skeptic (RaoFoundation/subtensor, 389 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pyspector Security Audit?

ParzivalHack (a GitHub user) maintains it in ParzivalHack/PySpector, which has 151 GitHub stars. The repository was last updated on October 7, 2026.

Source: ParzivalHack/PySpector on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.