Agent skill

Code Safety Audit

by rongxinzy in rongxinzy/RongxinAI

扫描代码安全漏洞,检测依赖漏洞、密钥泄露和OWASP安全模式。当用户提到安全扫描、漏洞检测、依赖审计、密钥泄露、API key、OWASP、npm audit、pip-audit或SQL注入/XSS等关键词时触发。

MITAuto-check passedSecurity

Install Code Safety Audit

skills CLI
$ npx skills add rongxinzy/RongxinAI --skill code-safety-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rongxinzy/RongxinAI code-safety-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rongxinzy/RongxinAI.git skills-src && mkdir -p .claude/skills && cp -r skills-src/SKILLs/code-safety-audit .claude/skills/code-safety-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-safety-audit
GitHub stars
154
Token cost
~868 tokens
SKILL.md length
185 words
Files
6 (incl. scripts)
Skills in repo
94
Repo updated
First seen
Licence
MIT

At a glance

扫描代码安全漏洞,检测依赖漏洞、密钥泄露和OWASP安全模式。当用户提到安全扫描、漏洞检测、依赖审计、密钥泄露、API key、OWASP、npm audit、pip-audit或SQL注入/XSS等关键词时触发。

  • Works in 3 steps: 依赖漏洞扫描 (deps) → 密钥泄露检测 (secrets) → OWASP 模式检测 (owasp)
  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers Quick Start, 扫描模块详情, 参数说明 and 输出格式, plus 2 more sections
  • Runs Python scripts from its folder; calls python3 and npm; needs AWS_KEY

What it does

Code Safety Audit is an agent skill from rongxinzy/RongxinAI. 扫描代码安全漏洞,检测依赖漏洞、密钥泄露和OWASP安全模式。当用户提到安全扫描、漏洞检测、依赖审计、密钥泄露、API key、OWASP、npm audit、pip-audit或SQL注入/XSS等关键词时触发。

Its SKILL.md is about 870 tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts (for example `scripts/security_scan.py` and `zhiyuan/metadata.yaml`).

It sits in Security, covering Web application vulnerabilities and Dependency management. It works with SQL, Python and npm. The repository describes itself as: An all-in-one local AI Agent workspace with a fully self-developed stack. The licence is MIT.

When your agent uses it

  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Dependency management

Example prompts

  • “/code-safety-audit”

Requirements

  • Python 3
  • Node.js
  • A credential in AWS_KEY

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. 依赖漏洞扫描 (deps)
  2. 密钥泄露检测 (secrets)
  3. OWASP 模式检测 (owasp)

What it can do on your machine

Read from SKILL.md and the folder at commit 26406d6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AWS_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Safety Audit loads about 868 tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 185 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~868

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from rongxinzy/RongxinAI at commit 26406d6, republished under its MIT licence (© rongxinzy). 185 words, ~868 tokens.

Download SKILL.mdSave it as .claude/skills/code-safety-audit/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
code-safety-audit
description
扫描代码安全漏洞,检测依赖漏洞、密钥泄露和OWASP安全模式。当用户提到安全扫描、漏洞检测、依赖审计、密钥泄露、API key、OWASP、npm audit、pip-audit或SQL注入/XSS等关键词时触发。
license
MIT

security-scanner

代码安全扫描工具,提供三大扫描能力:

  1. 依赖漏洞扫描 — 自动检测 npm / pip 依赖中的已知漏洞
  2. 密钥泄露检测 — 通过正则匹配 + Shannon 熵值分析发现硬编码的密钥、Token、密码
  3. OWASP 模式检测 — 识别 SQL 注入、XSS、命令注入、不安全反序列化等常见安全反模式

Quick Start

bash
# 扫描当前目录(全部检查项)
python3 scripts/security_scan.py .

# 仅扫描依赖漏洞
python3 scripts/security_scan.py --mode deps .

# 仅检测密钥泄露
python3 scripts/security_scan.py --mode secrets /path/to/project

# 仅检测 OWASP 安全模式
python3 scripts/security_scan.py --mode owasp .

# 输出 JSON 格式报告
python3 scripts/security_scan.py --format json --output report.json .

# 只显示 high 及以上严重级别
python3 scripts/security_scan.py --severity high .

扫描模块详情

1. 依赖漏洞扫描 (deps)

自动检测项目类型并调用相应工具:

项目类型检测文件使用工具
Node.jspackage.json + package-lock.jsonnpm audit
Pythonrequirements.txt / pyproject.toml / Pipfilepip-audit

如果对应的审计工具未安装,会给出提示而不是报错。

2. 密钥泄露检测 (secrets)

通过两种方式检测:

正则匹配:覆盖常见的密钥格式

密钥类型示例模式
AWS Access KeyAKIA 开头的 20 字符
GitHub Tokenghp_、github_pat_ 开头
Slack Tokenxoxb-、xoxp- 开头
Stripe Keysk_live_、pk_live_ 开头
私钥文件-----BEGIN PRIVATE KEY-----
通用 API Keyapi_key = "..." 格式
URL 内嵌凭据https://user:pass@host
JWT TokeneyJ... 格式

Shannon 熵值分析:对代码中的字符串常量计算信息熵(阈值 > 4.5 且长度 >= 20),用于发现非标准格式的密钥。

3. OWASP 模式检测 (owasp)

覆盖 OWASP Top 10 中可静态检测的安全模式:

OWASP 分类检测模式
A02: 密码学失败弱哈希 (MD5/SHA1)、弱加密 (DES/RC4)
A03: 注入SQL 注入、命令注入 (os.system/subprocess shell/eval/exec)、XSS (innerHTML/document.write/dangerouslySetInnerHTML/v-html)
A04: 不安全设计路径遍历
A05: 安全配置错误Debug 模式开启、CORS 通配符、绑定 0.0.0.0
A08: 完整性失败不安全反序列化 (pickle/yaml.load/marshal/unserialize)
A10: SSRF用户输入直接用于 HTTP 请求

支持语言:Python、JavaScript/TypeScript、Java、PHP、Ruby、Go 等。

参数说明

参数说明默认值
TARGET扫描目标目录当前目录
--mode MODE扫描模式:all、deps、secrets、owaspall
--format FORMAT输出格式:text、jsontext
--output FILE输出文件路径stdout
--severity LEVEL最低报告级别:low、medium、high、criticallow
--exclude-dir DIR额外排除的目录(可重复使用)-
--max-file-kb SIZE单文件最大扫描大小 (KB)512
-h, --help显示帮助-

输出格式

文本输出(默认)
=== Security Scan Report ===
Target: /path/to/project
Modules: deps, secrets, owasp

[CRITICAL] AWS Access Key ID
  File: src/config.py:15
  Code: AWS_KEY = "AKIAIOSFODNN7EXAMPLE"

[HIGH] SQL Injection (f-string)
  File: src/db.py:42
  Code: cursor.execute(f"SELECT * FROM users WHERE id={user_id}")

--- Summary ---
Critical: 1 | High: 1 | Medium: 0 | Low: 0
Total findings: 2
JSON 输出
json
{
  "target": "/path/to/project",
  "scan_time": "2026-04-14T10:30:00",
  "findings": [
    {
      "scanner": "secrets",
      "name": "AWS Access Key ID",
      "severity": "critical",
      "file": "src/config.py",
      "line": 15,
      "snippet": "AWS_KEY = \"AKIAIOSFODNN7EXAMPLE\"",
      "category": "secret-pattern"
    }
  ],
  "summary": {"critical": 1, "high": 0, "medium": 0, "low": 0, "total": 1}
}

退出码

退出码含义
0无发现
1有发现(至少一个安全问题)
2扫描器自身错误

前置条件

  • Python 3.7+(仅使用标准库)
  • 依赖扫描需要相应工具:npm(Node.js 项目)、pip-audit(Python 项目)
  • 如缺少审计工具,该模块会跳过并给出提示,不影响其他模块运行

© rongxinzy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts) in SKILLs/code-safety-audit of rongxinzy/RongxinAI.

  • SKILL.md
  • LICENSE
  • requirements.txt
  • scripts/security_scan.py
  • zhiyuan/icon.png
  • zhiyuan/metadata.yaml

Open the folder on GitHubat commit 26406d6

Compare with similar skills

Code Safety Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Safety Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Safety Audit this skillrongxinzy/RongxinAI154—~868Automated safety check: PassMIT
npm Supply Chain Checkmajiayu000/spellbook286—~1.5kAutomated safety check: PassMIT
Golang Securityunxed/f42412 repos~3.6kAutomated safety check: PassMIT
Dependency Scanningsickn33/agentic-awesome-skills47k1 repos~2.4kAutomated safety check: PassMIT
Sast Sqliutkusen/sast-skills1.3k—~6kAutomated safety check: PassMIT
Sca AuditOWASP/secure-agent-playbook187—~494Automated safety check: PassCC-BY-4.0

Similar skills

  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    286 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

    241 GitHub starsUsed in 2 repos~3.6k tokens
    SecurityAuto-check passed
  • Dependency Scanning

    sickn33/agentic-awesome-skills

    Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check.

    47k GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check passed
  • Sast Sqli

    utkusen/sast-skills

    Detect SQL injection vulnerabilities in a codebase using a three-phase approach: recon (find unsafe SQL construction sites), batched verify (trace user input to those sites in parallel subagents, 3…

    1.3k GitHub stars~6k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Sca Audit

    OWASP/secure-agent-playbook

    Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.

    187 GitHub stars~494 tokensUpdated 13 days ago
    SecurityAuto-check passed
  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    430 GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check: notes

More from rongxinzy/RongxinAI

All 94 skills in this repo
  • SaaS Metrics Coach

    rongxinzy/RongxinAI

    SaaS financial health advisor. An agent skill from rongxinzy/RongxinAI.

    154 GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed
  • Churn Prevention

    rongxinzy/RongxinAI

    Reduce voluntary and involuntary churn through cancel flow design, save offers, exit surveys, and dunning sequences.

    154 GitHub starsUsed in 3 repos~2.6k tokens
    Auto-check passed
  • Presentation Studio

    rongxinzy/RongxinAI

    The only skill for creating a new PowerPoint deck. An agent skill from rongxinzy/RongxinAI.

    154 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Cantian Bazi

    rongxinzy/RongxinAI

    以命理场景为主的八字排盘、黄历查询与大运/流年/流月/流日/流时区间查询技能。用于用户请求“算八字”“四柱排盘”“阳历/农历转八字”“查黄历/宜忌”“查未来10年流年”“查下个月流日/流时”等场景;关键词包括:八字、四柱、命理、大运、流年、流月、流日、流时、时辰、阳历转八字、农历转八字、黄历、宜忌、干支日期。真太阳时换算属于辅助能力,仅在需要校时定盘时使用。

    154 GitHub starsUsed in 2 repos~2.1k tokens
    Auto-check passed
  • Zhiyuan Expert Manager

    rongxinzy/RongxinAI

    ZhiYuan Agent expert package lifecycle manager for the pi engine.

    154 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Lark Mail

    rongxinzy/RongxinAI

    飞书邮箱:Use when user mentions 起草邮件、写邮件、草稿、发送/回复/转发邮件、查阅邮件、看邮件、搜索邮件、邮件文件夹、邮件标签、邮件联系人、监听新邮件、邮件收信规则等;use for mail/email intent only.

    154 GitHub starsUsed in 4 repos~4.1k tokens
    Auto-check: warnings

Works with

Categories

Questions about Code Safety Audit

What does Code Safety Audit do?

扫描代码安全漏洞,检测依赖漏洞、密钥泄露和OWASP安全模式。当用户提到安全扫描、漏洞检测、依赖审计、密钥泄露、API key、OWASP、npm audit、pip-audit或SQL注入/XSS等关键词时触发。. Code Safety Audit is an agent skill from rongxinzy/RongxinAI.

When should I use Code Safety Audit?

Code Safety Audit fits situations like: tasks that involve Web application vulnerabilities; tasks that involve Dependency management.

How do I install Code Safety Audit in Claude Code?

Run `npx skills add rongxinzy/RongxinAI --skill code-safety-audit -a claude-code`. Or copy the skill folder (SKILLs/code-safety-audit in rongxinzy/RongxinAI) into .claude/skills/code-safety-audit in your project. Claude Code loads it when a task matches its description.

How do I install Code Safety Audit in Codex?

Run `npx skills add rongxinzy/RongxinAI --skill code-safety-audit -a codex`. Or copy the skill folder (SKILLs/code-safety-audit in rongxinzy/RongxinAI) into .agents/skills/code-safety-audit in your project. Codex loads it when a task matches its description.

Can I use Code Safety Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rongxinzy/RongxinAI --skill code-safety-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-safety-audit, .gemini/skills/code-safety-audit, .github/skills/code-safety-audit and .opencode/skills/code-safety-audit in your project.

What does Code Safety Audit need to run?

Going by SKILL.md and its folder, Code Safety Audit needs Python for the scripts in its folder, the command-line tools its instructions call (python3 and npm) and credentials named AWS_KEY. Our summary lists: Python 3; Node.js; A credential in AWS_KEY.

Does Code Safety Audit access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Safety Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Code Safety Audit use?

Code Safety Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Safety Audit use?

About 868 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Safety Audit?

Skills that share tags, products or a category with Code Safety Audit: npm Supply Chain Check (majiayu000/spellbook, 286 stars), Golang Security (unxed/f4, 241 stars), Dependency Scanning (sickn33/agentic-awesome-skills, 47k stars) and Sast Sqli (utkusen/sast-skills, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Safety Audit?

rongxinzy (a GitHub organization) maintains it in rongxinzy/RongxinAI, which has 154 GitHub stars. The repository holds 94 skills in this directory. The repository was last updated on October 8, 2026.

Source: rongxinzy/RongxinAI on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.