Agent skill

Security Auditor

by pavel-molyanov in pavel-molyanov/molyanov-ai-dev

Analyzes changed security boundaries against applicable OWASP risks and project contracts.

MITAuto-check passedSecurity

Install Security Auditor

skills CLI
$ npx skills add pavel-molyanov/molyanov-ai-dev --skill security-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pavel-molyanov/molyanov-ai-dev security-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pavel-molyanov/molyanov-ai-dev.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-auditor .claude/skills/security-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-auditor
GitHub stars
297
Token cost
~566 tokens
SKILL.md length
234 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

Analyzes changed security boundaries against applicable OWASP risks and project contracts.

  • : проверь безопасность
  • SKILL.md covers Applicable Risks and Dependency Scan
  • Calls npm and pnpm
  • Найди уязвимости

What it does

Security Auditor is an agent skill from pavel-molyanov/molyanov-ai-dev. Analyzes changed security boundaries against applicable OWASP risks and project contracts. Use after code-reviewer when authentication, authorization, untrusted input, secrets, sensitive data, database queries, file paths, rendering, or external APIs changed. Use when: "проверь безопасность", "security audit", "найди уязвимости", "check security" Do NOT use for: general code review (use code-reviewer), test quality review (use test-reviewer)

Its SKILL.md is about 570 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Code review, Web application vulnerabilities and Security review. The repository describes itself as: Intent-driven AI-First development methodology for Claude Code and Codex — Project Knowledge, user-spec planning, focused execution, and evidence-gated reviews. The licence is MIT.

When your agent uses it

  • : проверь безопасность
  • Найди уязвимости
  • Check security Do NOT use for: general code review (use code-reviewer)
  • Test quality review (use test-reviewer)

Example prompts

  • “security audit”
  • “check security”
  • “Use the security-auditor skill to analyz changed security boundaries against applicable OWASP risks and project contracts”
  • “/security-auditor”

What it can do on your machine

Read from SKILL.md and the folder at commit b5db526. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Auditor loads about 566 tokens when it runs. Until then it costs about 116 tokens; SKILL.md has 234 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~566

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pavel-molyanov/molyanov-ai-dev at commit b5db526, republished under its MIT licence (© pavel-molyanov). 234 words, ~566 tokens.

Download SKILL.mdSave it as .claude/skills/security-auditor/SKILL.md (or your agent's skills folder).
name
security-auditor
description
Analyzes changed security boundaries against applicable OWASP risks and project contracts. Use after code-reviewer when authentication, authorization, untrusted input, secrets, sensitive data, database queries, file paths, rendering, or external APIs changed. Use when: "проверь безопасность", "security audit", "найди уязвимости", "check security" Do NOT use for: general code review (use code-reviewer), test quality review (use test-reviewer)

Security Auditor

Applicable Risks

Select risks from the actual trust boundaries and capabilities in the project:

  • injection in queries, commands, templates, logs, and interpreters;
  • XSS and context-appropriate output encoding;
  • CSRF, CORS, and browser security headers;
  • authentication, session handling, authorization, and privilege escalation;
  • SSRF, path traversal, unsafe file handling, and external requests;
  • secrets, sensitive data exposure, cryptography, and secure randomness;
  • unsafe deserialization, software/data integrity, and CI/CD trust;
  • denial of service, missing bounds, abuse controls, and rate limiting;
  • security logging and audit trails where the project has a concrete monitoring contract;
  • business-logic abuse and project-specific compliance requirements.

Trace untrusted data from entry to each sensitive sink. Verify protection at the operation that needs it rather than inferring safety from a UI or a distant boundary. Account for framework protections only when configuration and execution paths show that they apply.

Dependency Scan

Run a read-only dependency vulnerability scanner when a manifest, lockfile, dependency, or dependency version changed, or when the user requested a full security audit. Choose the scanner for the current ecosystem, such as npm audit, pnpm audit, pip-audit, or an available equivalent, and avoid commands that mutate manifests or lockfiles.

If no applicable scanner is installed or its data source is unavailable, record that specific coverage gap as limitation evidence. Do not invent scan results. Dependency findings still need a matching changed dependency or full-audit scope, affected version evidence, realistic reachability conditions, and concrete impact.

© pavel-molyanov, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security-auditor of pavel-molyanov/molyanov-ai-dev.

Open the folder on GitHubat commit b5db526

Compare with similar skills

Security Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Auditor this skillpavel-molyanov/molyanov-ai-dev297—~566Automated safety check: PassMIT
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Security Reviewgetsentry/skills1k4 repos~2.9kAutomated safety check: NotesCC-BY-SA-4.0
Performing Security Code Reviewjeremylongshore/tons-of-skills-marketplace2.8k2 repos~1.3kAutomated safety check: NotesMIT
Security Reviewdeadlock-mod-manager/deadlock-mod-manager478—~1.8kAutomated safety check: PassCC-BY-SA-4.0
Security Reviewerforyourhealth111-pixel/Vibe-Skills3.6k—~523Automated safety check: PassApache-2.0

Similar skills

  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    SecurityAuto-check: notes
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    SecurityAuto-check: notes
  • Security Review

    deadlock-mod-manager/deadlock-mod-manager

    Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.

    478 GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Reviewer

    foryourhealth111-pixel/Vibe-Skills

    Dedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure.

    3.6k GitHub stars~523 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy

    239 GitHub stars~5.8k tokensUpdated yesterday
    SecurityAuto-check passed

More from pavel-molyanov/molyanov-ai-dev

All 13 skills in this repo
  • Documentation Writing

    pavel-molyanov/molyanov-ai-dev

    Creates and maintains project documentation in .claude/skills/project-knowledge/: interview, initial Project Knowledge, audit, edit, consistency, and feature finalization.

    297 GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • User Spec Planning

    pavel-molyanov/molyanov-ai-dev

    Creates user-spec.md through adaptive interview, codebase research, and three-lane validation.

    297 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Infrastructure Setup

    pavel-molyanov/molyanov-ai-dev

    Provides project infrastructure conventions and review criteria for local setup, Docker, Git hooks, CI/CD, service delivery, release artifacts, monitoring, backups, and operations.

    297 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • Layout Writing

    pavel-molyanov/molyanov-ai-dev

    Reproduces and adjusts web layouts from Figma, Claude Design exports, screenshots, or an existing project style with high visual fidelity and proportional verification.

    297 GitHub stars~1.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Skill Master

    pavel-molyanov/molyanov-ai-dev

    Guides skill creation and updates with specialized knowledge and workflows.

    297 GitHub stars~3.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Project Initialization

    pavel-molyanov/molyanov-ai-dev

    Initializes a project from the standard dual-runtime template, preserves existing files, configures Git hooks, and creates or connects a private GitHub repository with main and dev branches.

    297 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check: notes

Categories

Questions about Security Auditor

What does Security Auditor do?

Analyzes changed security boundaries against applicable OWASP risks and project contracts. Security Auditor is an agent skill from pavel-molyanov/molyanov-ai-dev. Analyzes changed security boundaries against applicable OWASP risks and project contracts.

When should I use Security Auditor?

Security Auditor fits situations like: : проверь безопасность; Найди уязвимости; check security Do NOT use for: general code review (use code-reviewer); test quality review (use test-reviewer).

How do I install Security Auditor in Claude Code?

Run `npx skills add pavel-molyanov/molyanov-ai-dev --skill security-auditor -a claude-code`. Or copy the skill folder (skills/security-auditor in pavel-molyanov/molyanov-ai-dev) into .claude/skills/security-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Security Auditor in Codex?

Run `npx skills add pavel-molyanov/molyanov-ai-dev --skill security-auditor -a codex`. Or copy the skill folder (skills/security-auditor in pavel-molyanov/molyanov-ai-dev) into .agents/skills/security-auditor in your project. Codex loads it when a task matches its description.

Can I use Security Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pavel-molyanov/molyanov-ai-dev --skill security-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-auditor, .gemini/skills/security-auditor, .github/skills/security-auditor and .opencode/skills/security-auditor in your project.

What does Security Auditor need to run?

Going by SKILL.md and its folder, Security Auditor needs the command-line tools its instructions call (npm and pnpm).

Does Security Auditor access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Auditor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Auditor use?

Security Auditor is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Auditor use?

About 566 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Auditor?

Skills that share tags, products or a category with Security Auditor: Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Security Review (getsentry/skills, 1k stars), Performing Security Code Review (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Security Review (deadlock-mod-manager/deadlock-mod-manager, 478 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Auditor?

pavel-molyanov (a GitHub user) maintains it in pavel-molyanov/molyanov-ai-dev, which has 297 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on August 23, 2026.

Source: pavel-molyanov/molyanov-ai-dev on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.