Security Reviewer
AratKruglik/claude-laravel
A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.
A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…
$ npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-security-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ProgrammerAnthony/Expert-Coding-Harness code-security-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-security-audit .claude/skills/code-security-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "code-security-audit" agent skill from https://github.com/ProgrammerAnthony/Expert-Coding-Harness/tree/master/skills/code-security-audit into .claude/skills/code-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-security-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ProgrammerAnthony/Expert-Coding-Harness/tree/master/skills/code-security-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-security-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ProgrammerAnthony/Expert-Coding-Harness code-security-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/code-security-audit .agents/skills/code-security-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "code-security-audit" agent skill from https://github.com/ProgrammerAnthony/Expert-Coding-Harness/tree/master/skills/code-security-audit into .agents/skills/code-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-security-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-security-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ProgrammerAnthony/Expert-Coding-Harness code-security-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/code-security-audit .cursor/skills/code-security-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "code-security-audit" agent skill from https://github.com/ProgrammerAnthony/Expert-Coding-Harness/tree/master/skills/code-security-audit into .cursor/skills/code-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-security-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git --path skills/code-security-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-security-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ProgrammerAnthony/Expert-Coding-Harness code-security-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/code-security-audit .gemini/skills/code-security-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "code-security-audit" agent skill from https://github.com/ProgrammerAnthony/Expert-Coding-Harness/tree/master/skills/code-security-audit into .gemini/skills/code-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-security-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ProgrammerAnthony/Expert-Coding-Harness code-security-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-security-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/code-security-audit .github/skills/code-security-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "code-security-audit" agent skill from https://github.com/ProgrammerAnthony/Expert-Coding-Harness/tree/master/skills/code-security-audit into .github/skills/code-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-security-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-security-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ProgrammerAnthony/Expert-Coding-Harness code-security-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ProgrammerAnthony/Expert-Coding-Harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/code-security-audit .opencode/skills/code-security-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "code-security-audit" agent skill from https://github.com/ProgrammerAnthony/Expert-Coding-Harness/tree/master/skills/code-security-audit into .opencode/skills/code-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-security-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
code-security-auditA skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…
Code Security Audit is an agent skill from ProgrammerAnthony/Expert-Coding-Harness. Use when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code audit、pentest、渗透测试准备、帮我看看有没有安全漏洞、上线前安全review、有没有漏洞、找安全问题。
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 42 other files, including reference files (for example `README.md`, `references/audit-report-template.md` and `references/checklists/architecture-level-checklist.md`).
It sits in Security, covering Security review, Web application vulnerabilities and Penetration testing. It works with SQL. The repository describes itself as: 生产级 AI Agent 技能集,辅助AI Harness应用于企业开发,覆盖代码审查、代码安全审计、TDD、需求工程、实施计划与子代理编排、架构设计、调试、前端开发与技能创建全流程。 The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ab0b827. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
rgFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Code Security Audit loads about 1.6k tokens when it runs, and up to ~116k if it reads all its reference files. Until then it costs about 57 tokens; SKILL.md has 354 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ProgrammerAnthony/Expert-Coding-Harness at commit ab0b827, republished under its MIT licence (© ProgrammerAnthony). 354 words, ~1,630 tokens.
.claude/skills/code-security-audit/SKILL.md (or your agent's skills folder). This skill also uses 37 other files; get the full folder from GitHub.铁律:所有漏洞发现必须有代码路径证据。 禁止基于"典型框架通常有此漏洞"等假设报告漏洞,未找到完整调用链的必须标记为"疑似,需人工验证"。
<HARD-GATE>
在用户确认审计范围和扫描模式之前,禁止开始任何扫描分析。
必须先输出审计计划(技术栈、范围、预计时间、模式),等待用户确认后方可执行。
</HARD-GATE>
references/audit-report-template.md)。references/quality-gates-checklist.md。writing-plans(实施计划编写):输出修复计划subagent-driven-development(子代理驱动开发):按计划执行修复code-security-audit(代码安全审计专家):修复后复审| 层次 | 方法 | 目标 |
|---|---|---|
| 面 | Grep / 模式匹配 | 快速定位高风险区域,识别危险函数调用 |
| 线 | Read / 逐行追踪 | 完整数据流追踪,Source → Sink 路径分析 |
| 点 | 推理 / 逻辑验证 | 确认漏洞有效性、防护可绕过性、利用条件 |
启动时询问用户选择模式(默认 Standard):
请选择扫描模式:
1. Quick(快速扫描,约 5-10 分钟)— 高危漏洞 + 敏感信息 + 已知 CVE
2. Standard(标准扫描,约 30-60 分钟)— OWASP Top 10 + 认证授权 + 加密
3. Deep(深度扫描,约 1-3 小时)— 全维度覆盖 + 攻击链 + 业务逻辑 + 合规| # | 维度 | 审计轨道 | 覆盖内容 |
|---|---|---|---|
| D1 | 注入 | Sink-driven | SQL/Cmd/LDAP/SSTI/SpEL/JNDI |
| D2 | 认证 | Config-driven | Token/Session/JWT/Filter 链 |
| D3 | 授权 | Control-driven | CRUD 权限一致性、IDOR、水平越权 |
| D4 | 反序列化 | Sink-driven | Java/Python/PHP Gadget 链 |
| D5 | 文件操作 | Sink-driven | 上传/下载/路径遍历 |
| D6 | SSRF | Sink-driven | URL 注入、协议限制 |
| D7 | 加密 | Config-driven | 密钥管理、加密模式、KDF |
| D8 | 配置 | Config-driven | Actuator、CORS、错误信息暴露 |
| D9 | 业务逻辑 | Control-driven | 竞态条件、Mass Assignment、状态机、多租户隔离 |
| D10 | 供应链 | Config-driven | 依赖 CVE、版本检查 |
目标:建立项目全貌,产出架构图和攻击面清单。
# 技术栈识别
ls -la
find . -name "package.json" -o -name "pom.xml" -o -name "requirements.txt" -o -name "go.mod" | head -20
# 入口点识别
rg "router|app.route|@RequestMapping|@Controller|@RestController" -l
# 配置文件识别
find . -name "*.yml" -o -name "*.yaml" -o -name "*.properties" -o -name "*.env" | head -20
# 敏感信息预扫
rg -i "password|secret|api_key|token|private_key" -l输出:
加载 references/knowledge/architecture-analysis.md 获取架构分析方法论。
目标:按 10 个维度并行扫描,快速定位高风险区域。
加载 references/knowledge/pattern-scanning.md 获取各语言的危险函数模式。
加载 references/knowledge/secret-detection.md 扫描敏感信息泄露。
Sink-driven 扫描(D1、D4、D5、D6):
Control-driven 扫描(D3、D9):
Config-driven 扫描(D2、D7、D8、D10):
完成后对照 references/checklists/coverage-matrix.md 自检维度覆盖率。
D1–D3 任一未覆盖,不可进入 Phase 3。
目标:对 Phase 2 发现的高危点进行完整数据流追踪,确认漏洞真实性。
加载 references/knowledge/data-flow-analysis.md 获取数据流模型。
加载 references/knowledge/taint-analysis-enhanced.md 获取污点追踪报告模板。
加载 references/knowledge/phase2-deep-methodology.md 获取 D3/D9 深度方法论。
追踪路径:Source(用户输入)→ Filter(安全控制)→ Service(业务处理)→ Sink(危险操作)
对每个疑似漏洞:
目标:评估漏洞组合攻击可能性,构建完整攻击路径,评估综合风险。
加载 references/knowledge/vulnerability-validation.md 获取漏洞验证四步法。
加载 references/knowledge/attack-chain-analysis.md 获取攻击链构建方法。
攻击链分析步骤:
加载 references/knowledge/reporting.md 获取报告生成标准。
加载 references/templates/report-template.md 获取完整报告模板。
报告必须包含:
| 级别 | CVSS 分数 | 响应时间 | 典型示例 |
|---|---|---|---|
| Critical | 9.0-10.0 | 24小时内 | RCE、SQL注入获取所有数据 |
| High | 7.0-8.9 | 1周内 | 越权访问、文件路径穿越 |
| Medium | 4.0-6.9 | 1月内 | 信息泄露、弱加密 |
| Low | 0.1-3.9 | 3月内 | 非敏感信息暴露、最佳实践偏差 |
| Info | 0.0 | 可选修复 | 代码质量问题、建议性改进 |
核心原则:宁可漏报,不可误报。误报会消耗开发团队信任。
| 禁止行为 | 正确做法 |
|---|---|
| 基于"典型框架通常有此漏洞"直接标记 | 必须在项目代码中找到具体调用链 |
| 凭记忆编造代码片段 | 只引用 Read 工具实际读取的代码 |
| 编造或估计行号 | 使用读取结果中的实际行号 |
| 未找到完整调用链就列为确认漏洞 | 标记为"疑似,需人工验证" |
| 找到防护代码就跳过该维度 | 验证防护是否充分、是否可绕过 |
| 不确定版本是否受 CVE 影响就不提 | 如实说明不确定性,提供排查方向 |
完整规则加载 references/knowledge/anti-hallucination.md。
references/knowledge/architecture-analysis.md — Phase 1 架构分析方法论references/knowledge/pattern-scanning.md — Phase 2 多语言危险函数模式references/knowledge/data-flow-analysis.md — Phase 3 数据流模型与追踪方法references/knowledge/taint-analysis-enhanced.md — 污点追踪报告模板references/knowledge/phase2-deep-methodology.md — D3/D9 控制流深度方法论references/knowledge/vulnerability-validation.md — Phase 4 漏洞验证四步法references/knowledge/attack-chain-analysis.md — 攻击链构建与综合风险评估references/knowledge/reporting.md — Phase 5 报告生成标准references/knowledge/secret-detection.md — 敏感信息检测方法references/knowledge/dependency-analysis.md — 依赖安全分析(D10)references/knowledge/anti-hallucination.md — 防幻觉完整规则references/knowledge/security-controls-matrix.yaml — 安全控制矩阵(CWE 映射)references/checklists/coverage-matrix.md — D1-D10 覆盖自检与终止条件references/checklists/code-level-checklist.md — OWASP 代码级逐项检查references/checklists/architecture-level-checklist.md — 架构级安全检查references/rules/sql-injection-rules.md — SQL 注入检测规则与模式references/rules/command-injection-rules.md — 命令注入检测规则与模式references/templates/report-template.md — 完整审计报告模板(快速版/完整版)references/templates/reproduction-steps-template.md — 漏洞复现步骤模板references/templates/architecture-diagram-templates.md — Mermaid 架构图模板references/wooyun/wooyun-cases.md — WooYun 真实漏洞案例库(2010-2016)references/examples/audit-examples.md — 完整审计流程示例references/examples/vulnerability-cases.md — 多语言漏洞案例库references/examples/detailed-vulnerability-chains.md — 攻击链 POC 详细步骤references/compliance/compliance-frameworks.md — GDPR/PCI-DSS/ISO 27001 合规要点references/tools/security-tools.md — SAST 工具配置与命令参考references/devsecops-best-practices.md — DevSecOps 左移实践指南© ProgrammerAnthony, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 37 other files (references) in skills/code-security-audit of ProgrammerAnthony/Expert-Coding-Harness.
Open the folder on GitHubat commit ab0b827
Code Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Code Security Audit this skillProgrammerAnthony/Expert-Coding-Harness | 235 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Security ReviewerAratKruglik/claude-laravel | 155 | 1 repos | ~1.1k | Automated safety check: Notes | None | |
| Web Sqlis0ld13rr/pentestcode | 817 | — | ~710 | Automated safety check: Pass | MIT | |
| Security Reviewliuyanghejerry/Clausura | 204 | — | ~106 | Automated safety check: Pass | MIT | |
| Exploitability AnalyzerArabelaTso/Skills-4-SE | 253 | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | |
| Static Vulnerability DetectorArabelaTso/Skills-4-SE | 253 | — | ~2k | Automated safety check: Pass | Apache-2.0 |
AratKruglik/claude-laravel
A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.
s0ld13rr/pentestcode
SQL injection detection→exploitation→proof for web apps and APIs.
liuyanghejerry/Clausura
检查 SQL 注入、XSS、硬编码密钥
ArabelaTso/Skills-4-SE
Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context.
ArabelaTso/Skills-4-SE
Statically analyze code to detect security vulnerabilities including buffer overflows, injection risks (SQL, command, XSS), insecure deserialization, improper authentication, hard-coded credentials…
SpecterOps/skills
Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications.
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要设计新系统架构、评审或优化已有系统架构、选择技术方案时。触发场景:架构分析、架构设计、系统设计、architecture、架构优化、系统架构、架构评审、架构咨询、技术方案、技术设计、如何组织代码结构、模块划分、服务拆分、数据库选型、微服务设计。
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户要求审查代码、评估代码质量、提交 PR 前检查、发现代码有潜在问题时。触发场景:代码审查、code review、审查代码、review、检查代码、代码检查、代码质量、代码评审、这段代码有问题吗、帮我看看代码、合并前检查。
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 程序出现错误、异常、崩溃,或行为与预期不符,或测试失败,或无法定位问题根因时。触发场景:调试、debug、报错、错误、异常、bug、问题排查、故障排查、不工作、崩溃、无法运行、出错了、为什么不生效、运行报错、跑不起来、程序挂了。
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要审查前端代码(React/Vue/Next.js/TypeScript/Tailwind等)、检查代码质量、性能问题、可维护性、安全漏洞、最佳实践落地时。触发场景:前端代码评审、前端代码优化、React/Vue代码检查、TypeScript代码审查、前端性能优化、前端安全审计、前端代码规范检查。
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要优化前端性能、提升页面加载速度、减少白屏时间、优化交互流畅度、进行性能排查时。触发场景:前端性能优化、页面加载慢、白屏时间长、卡顿、LCP/FID/CLS指标优化、前端性能分析、打包体积优化。
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要编写产品需求文档、整理功能需求、拆解 GitHub Issues 或制定实施计划时。触发场景:写PRD、产品需求、需求文档、prd、需求分析、功能设计、产品设计、需求评审、需求拆解、issue拆解、帮我写需求、整理功能点、我有个想法要落地、新功能规划。
Works with
Categories
A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…. Code Security Audit is an agent skill from ProgrammerAnthony/Expert-Coding-Harness.
Code Security Audit fits situations like: tasks that involve Security review; tasks that involve Web application vulnerabilities; tasks that involve Penetration testing.
Run `npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-security-audit -a claude-code`. Or copy the skill folder (skills/code-security-audit in ProgrammerAnthony/Expert-Coding-Harness) into .claude/skills/code-security-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-security-audit -a codex`. Or copy the skill folder (skills/code-security-audit in ProgrammerAnthony/Expert-Coding-Harness) into .agents/skills/code-security-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ProgrammerAnthony/Expert-Coding-Harness --skill code-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-security-audit, .gemini/skills/code-security-audit, .github/skills/code-security-audit and .opencode/skills/code-security-audit in your project.
Going by SKILL.md and its folder, Code Security Audit needs the command-line tools its instructions call (rg).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Code Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 114k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Code Security Audit: Security Reviewer (AratKruglik/claude-laravel, 155 stars), Web Sqli (s0ld13rr/pentestcode, 817 stars), Security Review (liuyanghejerry/Clausura, 204 stars) and Exploitability Analyzer (ArabelaTso/Skills-4-SE, 253 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ProgrammerAnthony (a GitHub user) maintains it in ProgrammerAnthony/Expert-Coding-Harness, which has 235 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on May 11, 2026.
Source: ProgrammerAnthony/Expert-Coding-Harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.