Agent skill

Security Audit

by RightNow-AI in RightNow-AI/openfang

Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology

Apache-2.0Auto-check passedSecurity

Install Security Audit

skills CLI
$ npx skills add RightNow-AI/openfang --skill security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install RightNow-AI/openfang security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/RightNow-AI/openfang.git skills-src && mkdir -p .claude/skills && cp -r skills-src/crates/openfang-skills/bundled/security-audit .claude/skills/security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-audit
GitHub stars
18k
Token cost
~858 tokens
SKILL.md length
447 words
Files
1
Skills in repo
68
Repo updated
First seen
Licence
Apache-2.0

At a glance

Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology

  • Tasks that involve Security review
  • SKILL.md covers Key Principles, Techniques, Common Patterns and Pitfalls to Avoid
  • Calls npm and cargo
  • Tasks that involve Web application vulnerabilities

What it does

Security Audit is an agent skill from RightNow-AI/openfang. Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology

Its SKILL.md is about 860 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review, Web application vulnerabilities and Vulnerability scanning. The repository describes itself as: Open-source Agent Operating System. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Security review
  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Vulnerability scanning

Example prompts

  • “/security-audit”

What it can do on your machine

Read from SKILL.md and the folder at commit acf2587. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Audit loads about 858 tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 447 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~858

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from RightNow-AI/openfang at commit acf2587, republished under its Apache-2.0 licence (© RightNow-AI). 447 words, ~858 tokens.

Download SKILL.mdSave it as .claude/skills/security-audit/SKILL.md (or your agent's skills folder).
name
security-audit
description
Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology

Security Audit and Code Review

You are a senior application security engineer with expertise in vulnerability assessment, secure code review, threat modeling, and penetration testing methodology. You systematically identify security flaws using the OWASP framework, analyze CVE reports for impact assessment, and recommend practical remediations that balance security with development velocity. You think like an attacker but communicate like an engineer.

Key Principles

  • Apply defense in depth: no single security control should be the only barrier against a class of attack
  • Validate all input at trust boundaries; sanitize output at rendering boundaries; never trust data from external sources
  • Follow the principle of least privilege for authentication, authorization, file system access, and network connectivity
  • Use well-tested cryptographic libraries rather than implementing algorithms from scratch; prefer high-level APIs over low-level primitives
  • Assume breach: design logging, monitoring, and incident response so that compromises are detected and contained quickly

Techniques

  • Run SAST tools (Semgrep, CodeQL, Bandit) in CI to catch injection flaws, hardcoded credentials, and insecure deserialization before merge
  • Use DAST scanners (OWASP ZAP, Burp Suite) against staging environments to discover runtime vulnerabilities like CORS misconfiguration and header injection
  • Scan dependencies with npm audit, cargo audit, pip-audit, or Snyk to identify known CVEs in transitive dependencies
  • Review authentication flows for session fixation, credential stuffing protection (rate limiting, CAPTCHA), and secure token storage (HttpOnly, Secure, SameSite cookies)
  • Perform threat modeling with STRIDE (Spoofing, Tampering, Repudiation, Information disclosure, DoS, Elevation of privilege) for new features
  • Check authorization logic for IDOR (Insecure Direct Object Reference) by verifying that every data access checks ownership, not just authentication
Show full SKILL.md (188 more words)Show less

Common Patterns

  • Input Validation Layer: Validate type, length, format, and range at the API boundary using schema validation (JSON Schema, Zod, pydantic) before data reaches business logic
  • Parameterized Queries: Use prepared statements or ORM query builders for all database access; string concatenation in SQL is the root cause of injection
  • Content Security Policy: Deploy CSP headers with default-src 'self' and explicit allowlists for scripts, styles, and images to mitigate XSS even when input sanitization fails
  • Secret Rotation: Design systems so that credentials (API keys, database passwords, TLS certificates) can be rotated without downtime using secret managers (Vault, AWS Secrets Manager)

Pitfalls to Avoid

  • Do not rely on client-side validation alone; attackers bypass the UI entirely and send crafted requests directly to the API
  • Do not log sensitive data (passwords, tokens, PII) even at debug level; logs are often stored with weaker access controls than the primary data store
  • Do not use MD5 or SHA-1 for password hashing; use bcrypt, scrypt, or Argon2id with appropriate cost factors
  • Do not expose detailed error messages (stack traces, SQL errors, internal paths) to end users; return generic errors and log details server-side

© RightNow-AI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in crates/openfang-skills/bundled/security-audit of RightNow-AI/openfang.

Open the folder on GitHubat commit acf2587

Compare with similar skills

Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Audit this skillRightNow-AI/openfang18k—~858Automated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone
Security Auditdavila7/claude-code-templates32k4 repos~1.3kAutomated safety check: PassMIT
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Strix Code Vulnerability Scanusestrix/strix67k—~1.1kAutomated safety check: PassApache-2.0
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence

Similar skills

  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Security Audit

    davila7/claude-code-templates

    Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.

    32k GitHub starsUsed in 4 repos~1.3k tokens
    SecurityAuto-check passed
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    67k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed

More from RightNow-AI/openfang

All 68 skills in this repo
  • Reference of CSS selectors, step-by-step web workflows and error recovery tactics for an agent that browses, fills forms and compares prices on live sites.

    18k GitHub stars~1k tokensUpdated 3 mo ago
    Auto-check passed
  • Reference knowledge for open-source intelligence collection: the collection cycle, source reliability tiers, search query patterns and entity extraction.

    18k GitHub stars~2.1k tokensUpdated 3 mo ago
    Auto-check passed
  • Lead Generation Research Guide

    RightNow-AI/openfang

    Reference knowledge for AI lead generation: building an ideal customer profile, researching prospects on the web, enriching lead records and finding email formats.

    18k GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • Video Clipping Reference

    RightNow-AI/openfang

    Command reference for cutting clips from online video: yt-dlp downloads, whisper transcription, SRT subtitle files and ffmpeg processing, with Windows, macOS and Linux differences.

    18k GitHub stars~4.1k tokensUpdated 3 mo ago
    Auto-check: warnings
  • Forecasting Expert Knowledge

    RightNow-AI/openfang

    Reference knowledge for AI forecasting: superforecasting principles, a signal taxonomy, confidence calibration rules and reasoning chains for making and tracking predictions.

    18k GitHub stars~2.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Deep Research Methodology

    RightNow-AI/openfang

    Reference knowledge for AI deep research: a five-phase process, strategies by question type, CRAAP source scoring, cross-referencing, synthesis and citation formats.

    18k GitHub stars~2.6k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Security Audit

What does Security Audit do?

Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology. Security Audit is an agent skill from RightNow-AI/openfang.

When should I use Security Audit?

Security Audit fits situations like: tasks that involve Security review; tasks that involve Web application vulnerabilities; tasks that involve Vulnerability scanning.

How do I install Security Audit in Claude Code?

Run `npx skills add RightNow-AI/openfang --skill security-audit -a claude-code`. Or copy the skill folder (crates/openfang-skills/bundled/security-audit in RightNow-AI/openfang) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Security Audit in Codex?

Run `npx skills add RightNow-AI/openfang --skill security-audit -a codex`. Or copy the skill folder (crates/openfang-skills/bundled/security-audit in RightNow-AI/openfang) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.

Can I use Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add RightNow-AI/openfang --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.

What does Security Audit need to run?

Going by SKILL.md and its folder, Security Audit needs the command-line tools its instructions call (npm and cargo).

Does Security Audit access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Audit use?

Security Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Audit use?

About 858 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Audit?

Skills that share tags, products or a category with Security Audit: Code Audit (3stoneBrother/code-audit, 892 stars), Security Audit (davila7/claude-code-templates, 32k stars), Security Auditor (eigent-ai/eigent, 15k stars) and Strix Code Vulnerability Scan (usestrix/strix, 67k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Audit?

RightNow-AI (a GitHub organization) maintains it in RightNow-AI/openfang, which has 18,216 GitHub stars. The repository holds 68 skills in this directory. The repository was last updated on July 2, 2026.

Source: RightNow-AI/openfang on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.