Agent skill

Security Audit Scanner

by ruvnet in ruvnet/ruflo

Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

MITAuto-check passedSecurity

Install Security Audit Scanner

skills CLI
$ npx skills add ruvnet/ruflo --skill security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ruvnet/ruflo security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ruvnet/ruflo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-audit .claude/skills/security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-audit
GitHub stars
74k
Used in
2 other repos
Token cost
~823 tokens
SKILL.md length
195 words
Files
3 (incl. scripts)
Skills in repo
264
Repo updated
First seen
Licence
MIT

At a glance

Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

  • Works in 4 steps: Check memory for existing patterns… → Use hierarchical topology for coordination → Store successful patterns after completion → …
  • Adding authentication or authorization logic that needs a security check
  • SKILL.md covers Purpose, When to Trigger, When to Skip and Commands, plus 3 more sections
  • Runs Shell scripts from its folder; calls npx

What it does

This skill maps security checks to commands of the claude-flow CLI, run through npx @claude-flow/cli. A scan can cover the whole codebase or be limited to one area such as input validation, path traversal, SQL injection or cross-site scripting, pointed at a path like ./src/api, and saved as a JSON report. Separate commands check dependencies for known CVEs by severity, look for hardcoded secrets and run a threat-modeling analysis.

A report command produces a full audit in Markdown, for example as SECURITY.md. Two shell scripts are bundled: security-scan.sh for the complete scanning pipeline and cve-remediate.sh for automatic remediation of known CVEs. A security checklist document is referenced as well. The skill is aimed at work on login and permission logic, payments, user data, API endpoints, uploads, database queries and external API calls, and says to skip it for read-only access to public data, internal tooling, static docs and styling changes.

When your agent uses it

  • Adding authentication or authorization logic that needs a security check
  • Reviewing code that handles payments or personal user data
  • Checking a new upload handler or API endpoint for injection and path traversal
  • Scanning dependencies for known CVEs and writing up the findings

Example prompts

  • “Run a full security scan on this repo and save the report as security-report.json.”
  • “Check ./src/api for input validation problems and tell me what to fix first.”
  • “Scan our dependencies for high-severity CVEs and write the audit to SECURITY.md.”

Requirements

  • Node.js with npx, to run @claude-flow/cli
  • A shell that can run the bundled .sh scripts

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Check memory for existing patterns before starting
  2. Use hierarchical topology for coordination
  3. Store successful patterns after completion
  4. Document any new learnings

What it can do on your machine

Read from SKILL.md and the folder at commit de590e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Audit Scanner loads about 823 tokens when it runs. Until then it costs about 123 tokens; SKILL.md has 195 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~123
When it runs · the whole SKILL.md, loaded when a task matches
~823

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ruvnet/ruflo at commit de590e1, republished under its MIT licence (© ruvnet). 195 words, ~823 tokens.

Download SKILL.mdSave it as .claude/skills/security-audit/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
security-audit
description
Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment processing, user data handling, API endpoint creation, file upload handling, database queries, external API integration. Skip when: read-only operations on public data, internal development tooling, static documentation, styling changes.

Security Audit Skill

Purpose

Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement.

When to Trigger

  • authentication implementation
  • authorization logic
  • payment processing
  • user data handling
  • API endpoint creation
  • file upload handling
  • database queries
  • external API integration

When to Skip

  • read-only operations on public data
  • internal development tooling
  • static documentation
  • styling changes

Commands

Full Security Scan

Run comprehensive security analysis on the codebase

bash
npx @claude-flow/cli security scan --depth full

Example:

bash
npx @claude-flow/cli security scan --depth full --output security-report.json
Input Validation Check

Check for input validation issues

bash
npx @claude-flow/cli security scan --check input-validation

Example:

bash
npx @claude-flow/cli security scan --check input-validation --path ./src/api
Path Traversal Check

Check for path traversal vulnerabilities

bash
npx @claude-flow/cli security scan --check path-traversal
SQL Injection Check

Check for SQL injection vulnerabilities

bash
npx @claude-flow/cli security scan --check sql-injection
XSS Check

Check for cross-site scripting vulnerabilities

bash
npx @claude-flow/cli security scan --check xss
CVE Scan

Scan dependencies for known CVEs

bash
npx @claude-flow/cli security cve --scan

Example:

bash
npx @claude-flow/cli security cve --scan --severity high
Security Audit Report

Generate full security audit report

bash
npx @claude-flow/cli security audit --report

Example:

bash
npx @claude-flow/cli security audit --report --format markdown --output SECURITY.md
Threat Modeling

Run threat modeling analysis

bash
npx @claude-flow/cli security threats --analyze
Validate Secrets

Check for hardcoded secrets

bash
npx @claude-flow/cli security validate --check secrets

Scripts

ScriptPathDescription
security-scan.agents/scripts/security-scan.shRun full security scan pipeline
cve-remediate.agents/scripts/cve-remediate.shAuto-remediate known CVEs

References

DocumentPathDescription
Security Checklistdocs/security-checklist.mdSecurity review checklist
OWASP Guidedocs/owasp-top10.mdOWASP Top 10 mitigation guide

Best Practices

  1. Check memory for existing patterns before starting
  2. Use hierarchical topology for coordination
  3. Store successful patterns after completion
  4. Document any new learnings

© ruvnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in .agents/skills/security-audit of ruvnet/ruflo.

  • SKILL.md
  • scripts/cve-remediate.sh
  • scripts/security-scan.sh

Open the folder on GitHubat commit de590e1

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in ruvnet/ruflo, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Audit Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Audit Scanner compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Audit Scanner this skillruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Security Scanericrisco/rsc-harness156—~2.8kAutomated safety check: NotesMIT
Security And Hardeningdzhalaevd/Donatello135—~5.1kAutomated safety check: NotesApache-2.0
Discover Securityrand/cc-polymath181—~1.9kAutomated safety check: PassMIT
Security Auditoraiskillstore/marketplace4306 repos~2.6kAutomated safety check: PassNone
Security Assessmentrsmdt/the-startup536—~1.3kAutomated safety check: PassMIT

Similar skills

  • Security Scan

    ericrisco/rsc-harness

    A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

    156 GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check: notes
  • Security And Hardening

    dzhalaevd/Donatello

    Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.

    135 GitHub stars~5.1k tokensUpdated 3 days ago
    SecurityAuto-check: notes
  • Discover Security

    rand/cc-polymath

    Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management.

    181 GitHub stars~1.9k tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • Security Auditor

    aiskillstore/marketplace

    Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.

    430 GitHub starsUsed in 6 repos~2.6k tokens
    SecurityAuto-check passed
  • Security Assessment

    rsmdt/the-startup

    Vulnerability review, threat modeling, OWASP patterns, and secure coding assessment.

    536 GitHub stars~1.3k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes

More from ruvnet/ruflo

All 264 skills in this repo
  • Stores, searches, and retrieves successful patterns with HNSW-indexed semantic search so agents can reuse past solutions instead of relearning them.

    74k GitHub starsUsed in 2 repos~830 tokens
    Auto-check passed
  • Applies the SPARC method (specification, pseudocode, architecture, refinement, completion) with 17 specialized modes and multi-agent orchestration, from research to deployment.

    74k GitHub starsUsed in 2 repos~829 tokens
    Auto-check passed
  • Coordinates a hierarchical swarm of specialized agents through the claude-flow CLI for work that spans several files or modules at once.

    74k GitHub starsUsed in 2 repos~779 tokens
    Auto-check passed
  • Sets up and drives Ruflo, an npm-installed orchestration layer for multi-agent swarms, persistent memory, routing, hooks and its MCP tool catalog.

    74k GitHub starsUsed in 1 repo~975 tokens
    Auto-check passed
  • Agent Coordination

    ruvnet/ruflo

    Reference for spawning, listing, monitoring and stopping agents with claude-flow commands, with agent type families, routing codes and coordination tips.

    74k GitHub starsUsed in 2 repos~519 tokens
    Auto-check passed
  • Claims

    ruvnet/ruflo

    Claims-based authorization for agents and operations. An agent skill from ruvnet/ruflo.

    74k GitHub starsUsed in 2 repos~1.1k tokens
    Auto-check passed

Questions about Security Audit Scanner

What does Security Audit Scanner do?

Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report. This skill maps security checks to commands of the claude-flow CLI, run through npx @claude-flow/cli./src/api, and saved as a JSON report.

When should I use Security Audit Scanner?

Security Audit Scanner fits situations like: adding authentication or authorization logic that needs a security check; reviewing code that handles payments or personal user data; checking a new upload handler or API endpoint for injection and path traversal; scanning dependencies for known CVEs and writing up the findings.

How do I install Security Audit Scanner in Claude Code?

Run `npx skills add ruvnet/ruflo --skill security-audit -a claude-code`. Or copy the skill folder (.agents/skills/security-audit in ruvnet/ruflo) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Security Audit Scanner in Codex?

Run `npx skills add ruvnet/ruflo --skill security-audit -a codex`. Or copy the skill folder (.agents/skills/security-audit in ruvnet/ruflo) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.

Can I use Security Audit Scanner in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ruvnet/ruflo --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.

What does Security Audit Scanner need to run?

Going by SKILL.md and its folder, Security Audit Scanner needs a shell for the scripts in its folder and the command-line tools its instructions call (npx). Our summary lists: Node.js with npx, to run @claude-flow/cli; A shell that can run the bundled .sh scripts.

Does Security Audit Scanner access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Audit Scanner safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Audit Scanner use?

Security Audit Scanner is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Audit Scanner use?

About 823 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Audit Scanner?

Skills that share tags, products or a category with Security Audit Scanner: Security Scan (ericrisco/rsc-harness, 156 stars), Security And Hardening (dzhalaevd/Donatello, 135 stars), Discover Security (rand/cc-polymath, 181 stars) and Security Auditor (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Audit Scanner?

ruvnet (a GitHub user) maintains it in ruvnet/ruflo, which has 74,012 GitHub stars. The repository holds 264 skills in this directory. The repository was last updated on October 7, 2026.

Source: ruvnet/ruflo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.