A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…

MITAuto-check passedSecurity

Install Code Security Audit

skills CLI
$ npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ProgrammerAnthony/Expert-Coding-Harness code-security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-security-audit .claude/skills/code-security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-security-audit
GitHub stars
235
Token cost
~1.6k tokens
SKILL.md length
354 words
Files
38 (incl. references)
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…

  • Works in 5 steps: :侦察与架构建模(约 10% 工时) → :并行模式匹配(约 30% 工时) → :深度污点追踪(约 40% 工时) → …
  • Tasks that involve Security review
  • SKILL.md covers Inputs / Outputs / Gates /…, 审计方法:三层分析法, 扫描模式 and 10 个安全维度 + 三轨模型, plus 4 more sections
  • Calls rg

What it does

Code Security Audit is an agent skill from ProgrammerAnthony/Expert-Coding-Harness. Use when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code audit、pentest、渗透测试准备、帮我看看有没有安全漏洞、上线前安全review、有没有漏洞、找安全问题。

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 42 other files, including reference files (for example `README.md`, `references/audit-report-template.md` and `references/checklists/architecture-level-checklist.md`).

It sits in Security, covering Security review, Web application vulnerabilities and Penetration testing. It works with SQL. The repository describes itself as: 生产级 AI Agent 技能集,辅助AI Harness应用于企业开发,覆盖代码审查、代码安全审计、TDD、需求工程、实施计划与子代理编排、架构设计、调试、前端开发与技能创建全流程。 The licence is MIT.

When your agent uses it

  • Tasks that involve Security review
  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Penetration testing

Example prompts

  • “/code-security-audit”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. :侦察与架构建模(约 10% 工时)
  2. :并行模式匹配(约 30% 工时)
  3. :深度污点追踪(约 40% 工时)
  4. :攻击链构建与漏洞验证(约 15% 工时)
  5. :生成结构化报告(约 5% 工时)

What it can do on your machine

Read from SKILL.md and the folder at commit ab0b827. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Security Audit loads about 1.6k tokens when it runs, and up to ~116k if it reads all its reference files. Until then it costs about 57 tokens; SKILL.md has 354 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~116k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ProgrammerAnthony/Expert-Coding-Harness at commit ab0b827, republished under its MIT licence (© ProgrammerAnthony). 354 words, ~1,630 tokens.

Download SKILL.mdSave it as .claude/skills/code-security-audit/SKILL.md (or your agent's skills folder). This skill also uses 37 other files; get the full folder from GitHub.
name
code-security-audit
description
Use when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code audit、pentest、渗透测试准备、帮我看看有没有安全漏洞、上线前安全review、有没有漏洞、找安全问题。

代码安全审计专家

铁律:所有漏洞发现必须有代码路径证据。 禁止基于"典型框架通常有此漏洞"等假设报告漏洞,未找到完整调用链的必须标记为"疑似,需人工验证"。

<HARD-GATE>
在用户确认审计范围和扫描模式之前,禁止开始任何扫描分析。
必须先输出审计计划(技术栈、范围、预计时间、模式),等待用户确认后方可执行。
</HARD-GATE>

Inputs / Outputs / Gates / Handoffs(统一契约)

  • Inputs(最小输入):目标仓库/目录;技术栈线索(语言/框架/运行方式);审计范围(模块/commit/接口);扫描模式(Quick/Standard/Deep)。
  • Outputs(产物形态):审计计划(先)+ 结构化审计报告(后,结构参考 references/audit-report-template.md)。
  • Gates(继续前必须满足):
    • 未经用户确认范围与模式,禁止开始扫描分析(保持与本文件 HARD-GATE 一致)。
    • 结论必须有代码路径证据链(Source→Sink);不完整链路必须标为“疑似,需人工验证”。
    • 通用门控清单可复制使用:references/quality-gates-checklist.md。
  • Handoffs(推荐下游):
    • writing-plans(实施计划编写):输出修复计划
    • subagent-driven-development(子代理驱动开发):按计划执行修复
    • code-security-audit(代码安全审计专家):修复后复审

审计方法:三层分析法

层次方法目标
面Grep / 模式匹配快速定位高风险区域,识别危险函数调用
线Read / 逐行追踪完整数据流追踪,Source → Sink 路径分析
点推理 / 逻辑验证确认漏洞有效性、防护可绕过性、利用条件

扫描模式

启动时询问用户选择模式(默认 Standard):

请选择扫描模式:
1. Quick(快速扫描,约 5-10 分钟)— 高危漏洞 + 敏感信息 + 已知 CVE
2. Standard(标准扫描,约 30-60 分钟)— OWASP Top 10 + 认证授权 + 加密
3. Deep(深度扫描,约 1-3 小时)— 全维度覆盖 + 攻击链 + 业务逻辑 + 合规

10 个安全维度 + 三轨模型

#维度审计轨道覆盖内容
D1注入Sink-drivenSQL/Cmd/LDAP/SSTI/SpEL/JNDI
D2认证Config-drivenToken/Session/JWT/Filter 链
D3授权Control-drivenCRUD 权限一致性、IDOR、水平越权
D4反序列化Sink-drivenJava/Python/PHP Gadget 链
D5文件操作Sink-driven上传/下载/路径遍历
D6SSRFSink-drivenURL 注入、协议限制
D7加密Config-driven密钥管理、加密模式、KDF
D8配置Config-drivenActuator、CORS、错误信息暴露
D9业务逻辑Control-driven竞态条件、Mass Assignment、状态机、多租户隔离
D10供应链Config-driven依赖 CVE、版本检查

五阶段审计流程

Phase 1:侦察与架构建模(约 10% 工时)

目标:建立项目全貌,产出架构图和攻击面清单。

bash
# 技术栈识别
ls -la
find . -name "package.json" -o -name "pom.xml" -o -name "requirements.txt" -o -name "go.mod" | head -20
# 入口点识别
rg "router|app.route|@RequestMapping|@Controller|@RestController" -l
# 配置文件识别
find . -name "*.yml" -o -name "*.yaml" -o -name "*.properties" -o -name "*.env" | head -20
# 敏感信息预扫
rg -i "password|secret|api_key|token|private_key" -l

输出:

  • 技术栈与框架版本
  • Mermaid 架构图(分层/数据流/攻击路径)
  • 攻击面清单(对外 API 端点列表)
  • 数据流边界(外部输入来源)

加载 references/knowledge/architecture-analysis.md 获取架构分析方法论。


Phase 2:并行模式匹配(约 30% 工时)

目标:按 10 个维度并行扫描,快速定位高风险区域。

加载 references/knowledge/pattern-scanning.md 获取各语言的危险函数模式。
加载 references/knowledge/secret-detection.md 扫描敏感信息泄露。

Sink-driven 扫描(D1、D4、D5、D6):

  • 搜索危险函数 → 向上追踪参数来源 → 验证是否有防护

Control-driven 扫描(D3、D9):

  • 枚举所有 API 端点 → 逐一验证权限校验是否完整

Config-driven 扫描(D2、D7、D8、D10):

  • 检查认证配置、加密算法、调试开关、依赖版本

完成后对照 references/checklists/coverage-matrix.md 自检维度覆盖率。
D1–D3 任一未覆盖,不可进入 Phase 3。


Phase 3:深度污点追踪(约 40% 工时)

目标:对 Phase 2 发现的高危点进行完整数据流追踪,确认漏洞真实性。

加载 references/knowledge/data-flow-analysis.md 获取数据流模型。
加载 references/knowledge/taint-analysis-enhanced.md 获取污点追踪报告模板。
加载 references/knowledge/phase2-deep-methodology.md 获取 D3/D9 深度方法论。

追踪路径:Source(用户输入)→ Filter(安全控制)→ Service(业务处理)→ Sink(危险操作)

对每个疑似漏洞:

  1. 确认数据可达性:外部输入能否到达危险操作(找代码证据,不做假设)
  2. 确认防护缺失:净化函数是否真的有效,是否有绕过可能
  3. 评估可利用性:利用是否需要特定权限或条件

Phase 4:攻击链构建与漏洞验证(约 15% 工时)

目标:评估漏洞组合攻击可能性,构建完整攻击路径,评估综合风险。

加载 references/knowledge/vulnerability-validation.md 获取漏洞验证四步法。
加载 references/knowledge/attack-chain-analysis.md 获取攻击链构建方法。

攻击链分析步骤:

  1. 识别所有已确认漏洞的关联关系
  2. 构建漏洞依赖关系图(哪些漏洞可以组合利用)
  3. 评估攻击链的综合风险等级(通常高于单个漏洞)
  4. 提供攻击链的优先修复建议

Phase 5:生成结构化报告(约 5% 工时)

加载 references/knowledge/reporting.md 获取报告生成标准。
加载 references/templates/report-template.md 获取完整报告模板。

报告必须包含:

  • 执行摘要(总体风险评级、关键发现数量)
  • 项目概述(技术栈、架构图)
  • 漏洞详情(含完整数据流路径 Source→Sink)
  • 攻击链分析(漏洞组合场景)
  • 修复建议(P0 立即/P1 短期/P2 中期/P3 长期)
  • 覆盖矩阵自检结果
  • 未覆盖范围说明

Show full SKILL.md (131 more words)Show less

严重度分级

级别CVSS 分数响应时间典型示例
Critical9.0-10.024小时内RCE、SQL注入获取所有数据
High7.0-8.91周内越权访问、文件路径穿越
Medium4.0-6.91月内信息泄露、弱加密
Low0.1-3.93月内非敏感信息暴露、最佳实践偏差
Info0.0可选修复代码质量问题、建议性改进

防幻觉规则

核心原则:宁可漏报,不可误报。误报会消耗开发团队信任。

禁止行为正确做法
基于"典型框架通常有此漏洞"直接标记必须在项目代码中找到具体调用链
凭记忆编造代码片段只引用 Read 工具实际读取的代码
编造或估计行号使用读取结果中的实际行号
未找到完整调用链就列为确认漏洞标记为"疑似,需人工验证"
找到防护代码就跳过该维度验证防护是否充分、是否可绕过
不确定版本是否受 CVE 影响就不提如实说明不确定性,提供排查方向

完整规则加载 references/knowledge/anti-hallucination.md。


参考资源(按需加载)

核心知识库
  • references/knowledge/architecture-analysis.md — Phase 1 架构分析方法论
  • references/knowledge/pattern-scanning.md — Phase 2 多语言危险函数模式
  • references/knowledge/data-flow-analysis.md — Phase 3 数据流模型与追踪方法
  • references/knowledge/taint-analysis-enhanced.md — 污点追踪报告模板
  • references/knowledge/phase2-deep-methodology.md — D3/D9 控制流深度方法论
  • references/knowledge/vulnerability-validation.md — Phase 4 漏洞验证四步法
  • references/knowledge/attack-chain-analysis.md — 攻击链构建与综合风险评估
  • references/knowledge/reporting.md — Phase 5 报告生成标准
  • references/knowledge/secret-detection.md — 敏感信息检测方法
  • references/knowledge/dependency-analysis.md — 依赖安全分析(D10)
  • references/knowledge/anti-hallucination.md — 防幻觉完整规则
  • references/knowledge/security-controls-matrix.yaml — 安全控制矩阵(CWE 映射)
检查清单
  • references/checklists/coverage-matrix.md — D1-D10 覆盖自检与终止条件
  • references/checklists/code-level-checklist.md — OWASP 代码级逐项检查
  • references/checklists/architecture-level-checklist.md — 架构级安全检查
漏洞规则
  • references/rules/sql-injection-rules.md — SQL 注入检测规则与模式
  • references/rules/command-injection-rules.md — 命令注入检测规则与模式
报告与模板
  • references/templates/report-template.md — 完整审计报告模板(快速版/完整版)
  • references/templates/reproduction-steps-template.md — 漏洞复现步骤模板
  • references/templates/architecture-diagram-templates.md — Mermaid 架构图模板
扩展资料
  • references/wooyun/wooyun-cases.md — WooYun 真实漏洞案例库(2010-2016)
  • references/examples/audit-examples.md — 完整审计流程示例
  • references/examples/vulnerability-cases.md — 多语言漏洞案例库
  • references/examples/detailed-vulnerability-chains.md — 攻击链 POC 详细步骤
  • references/compliance/compliance-frameworks.md — GDPR/PCI-DSS/ISO 27001 合规要点
  • references/tools/security-tools.md — SAST 工具配置与命令参考
  • references/devsecops-best-practices.md — DevSecOps 左移实践指南

© ProgrammerAnthony, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 37 other files (references) in skills/code-security-audit of ProgrammerAnthony/Expert-Coding-Harness.

  • SKILL.md
  • README.md
  • references/audit-report-template.md
  • references/checklists/architecture-level-checklist.md
  • references/checklists/code-level-checklist.md
  • references/checklists/coverage-matrix.md
  • references/compliance/compliance-frameworks.md
  • references/devsecops-best-practices.md
  • references/examples/audit-examples.md
  • references/examples/config-file-vulnerabilities.md
  • references/examples/detailed-vulnerability-chains.md
  • references/examples/environment-simulation.md
  • references/examples/vulnerability-analysis.md
  • references/examples/vulnerability-cases.md
  • references/knowledge/anti-hallucination.md
  • references/knowledge/architecture-analysis.md
  • … and 22 more

Open the folder on GitHubat commit ab0b827

Compare with similar skills

Code Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Security Audit this skillProgrammerAnthony/Expert-Coding-Harness235—~1.6kAutomated safety check: PassMIT
Security ReviewerAratKruglik/claude-laravel1551 repos~1.1kAutomated safety check: NotesNone
Web Sqlis0ld13rr/pentestcode817—~710Automated safety check: PassMIT
Security Reviewliuyanghejerry/Clausura204—~106Automated safety check: PassMIT
Exploitability AnalyzerArabelaTso/Skills-4-SE253—~3.5kAutomated safety check: PassApache-2.0
Static Vulnerability DetectorArabelaTso/Skills-4-SE253—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Security Reviewer

    AratKruglik/claude-laravel

    A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.

    155 GitHub starsUsed in 1 repo~1.1k tokens
    SecurityAuto-check: notes
  • Web Sqli

    s0ld13rr/pentestcode

    SQL injection detection→exploitation→proof for web apps and APIs.

    817 GitHub stars~710 tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Security Review

    liuyanghejerry/Clausura

    检查 SQL 注入、XSS、硬编码密钥

    204 GitHub stars~106 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Exploitability Analyzer

    ArabelaTso/Skills-4-SE

    Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context.

    253 GitHub stars~3.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Static Vulnerability Detector

    ArabelaTso/Skills-4-SE

    Statically analyze code to detect security vulnerabilities including buffer overflows, injection risks (SQL, command, XSS), insecure deserialization, improper authentication, hard-coded credentials…

    253 GitHub stars~2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Go Review

    SpecterOps/skills

    Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications.

    702 GitHub stars~2.1k tokensUpdated 14 days ago
    SecurityAuto-check passed

More from ProgrammerAnthony/Expert-Coding-Harness

All 23 skills in this repo
  • Architecture Advisor

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要设计新系统架构、评审或优化已有系统架构、选择技术方案时。触发场景:架构分析、架构设计、系统设计、architecture、架构优化、系统架构、架构评审、架构咨询、技术方案、技术设计、如何组织代码结构、模块划分、服务拆分、数据库选型、微服务设计。

    235 GitHub stars~673 tokensUpdated 4 mo ago
    Auto-check passed
  • Code Review Expert

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户要求审查代码、评估代码质量、提交 PR 前检查、发现代码有潜在问题时。触发场景:代码审查、code review、审查代码、review、检查代码、代码检查、代码质量、代码评审、这段代码有问题吗、帮我看看代码、合并前检查。

    235 GitHub stars~806 tokensUpdated 4 mo ago
    Auto-check passed
  • Debug Expert

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 程序出现错误、异常、崩溃,或行为与预期不符,或测试失败,或无法定位问题根因时。触发场景:调试、debug、报错、错误、异常、bug、问题排查、故障排查、不工作、崩溃、无法运行、出错了、为什么不生效、运行报错、跑不起来、程序挂了。

    235 GitHub stars~986 tokensUpdated 4 mo ago
    Auto-check passed
  • Frontend Code Review

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要审查前端代码(React/Vue/Next.js/TypeScript/Tailwind等)、检查代码质量、性能问题、可维护性、安全漏洞、最佳实践落地时。触发场景:前端代码评审、前端代码优化、React/Vue代码检查、TypeScript代码审查、前端性能优化、前端安全审计、前端代码规范检查。

    235 GitHub stars~614 tokensUpdated 4 mo ago
    Auto-check passed
  • Frontend Performance Optimization

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要优化前端性能、提升页面加载速度、减少白屏时间、优化交互流畅度、进行性能排查时。触发场景:前端性能优化、页面加载慢、白屏时间长、卡顿、LCP/FID/CLS指标优化、前端性能分析、打包体积优化。

    235 GitHub stars~701 tokensUpdated 4 mo ago
    Auto-check passed
  • Prd Engineer

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要编写产品需求文档、整理功能需求、拆解 GitHub Issues 或制定实施计划时。触发场景:写PRD、产品需求、需求文档、prd、需求分析、功能设计、产品设计、需求评审、需求拆解、issue拆解、帮我写需求、整理功能点、我有个想法要落地、新功能规划。

    235 GitHub stars~624 tokensUpdated 4 mo ago
    Auto-check passed

Works with

Categories

Questions about Code Security Audit

What does Code Security Audit do?

A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…. Code Security Audit is an agent skill from ProgrammerAnthony/Expert-Coding-Harness.

When should I use Code Security Audit?

Code Security Audit fits situations like: tasks that involve Security review; tasks that involve Web application vulnerabilities; tasks that involve Penetration testing.

How do I install Code Security Audit in Claude Code?

Run `npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-security-audit -a claude-code`. Or copy the skill folder (skills/code-security-audit in ProgrammerAnthony/Expert-Coding-Harness) into .claude/skills/code-security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Code Security Audit in Codex?

Run `npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-security-audit -a codex`. Or copy the skill folder (skills/code-security-audit in ProgrammerAnthony/Expert-Coding-Harness) into .agents/skills/code-security-audit in your project. Codex loads it when a task matches its description.

Can I use Code Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-security-audit, .gemini/skills/code-security-audit, .github/skills/code-security-audit and .opencode/skills/code-security-audit in your project.

What does Code Security Audit need to run?

Going by SKILL.md and its folder, Code Security Audit needs the command-line tools its instructions call (rg).

Does Code Security Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Security Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Security Audit use?

Code Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Security Audit use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 114k tokens, read only when the agent opens those files.

What are the alternatives to Code Security Audit?

Skills that share tags, products or a category with Code Security Audit: Security Reviewer (AratKruglik/claude-laravel, 155 stars), Web Sqli (s0ld13rr/pentestcode, 817 stars), Security Review (liuyanghejerry/Clausura, 204 stars) and Exploitability Analyzer (ArabelaTso/Skills-4-SE, 253 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Security Audit?

ProgrammerAnthony (a GitHub user) maintains it in ProgrammerAnthony/Expert-Coding-Harness, which has 235 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on May 11, 2026.

Source: ProgrammerAnthony/Expert-Coding-Harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.