Agent skill

Dev Security Audit

by sd0xdev in sd0xdev/sd0x-harness

Comprehensive developer workstation security audit — scans for exposed credentials, compromised application data, persistence mechanisms, and supply chain attack indicators.

MITAuto-check: warningsSecurity

Install Dev Security Audit

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add sd0xdev/sd0x-harness --skill dev-security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sd0xdev/sd0x-harness dev-security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dev-security-audit .claude/skills/dev-security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dev-security-audit
GitHub stars
192
Token cost
~3.6k tokens
SKILL.md length
1,195 words
Files
6 (incl. references)
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Comprehensive developer workstation security audit — scans for exposed credentials, compromised application data, persistence mechanisms, and supply chain attack indicators.

  • Works in 5 steps: Supply Chain IoC Dispatch → Credential & Secret Exposure Scan → Application & Browser Data Scan → …
  • The user suspects their machine may be compromised
  • SKILL.md covers When to Use, When NOT to Use, Workflow Overview and Phase 0: Supply Chain IoC…, plus 6 more sections
  • Calls aws, docker and osascript

What it does

Dev Security Audit is an agent skill from sd0xdev/sd0x-harness. Comprehensive developer workstation security audit — scans for exposed credentials, compromised application data, persistence mechanisms, and supply chain attack indicators. Use this skill whenever the user suspects their machine may be compromised, wants to check for exposed secrets, asks about supply chain attacks, or wants a full security audit of their development environment. Also triggers on: 'am I compromised', 'check my security', 'scan for leaked keys', 'credential audit', 'supply chain attack', 'supply…

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/cases/README.md`, `references/cases/apifox-2026-03.md` and `references/cases/axios-2026-03.md`).

It sits in Security, covering Security review and Supply chain security. The repository describes itself as: The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and… The licence is MIT.

When your agent uses it

  • The user suspects their machine may be compromised
  • Wants to check for exposed secrets
  • Asks about supply chain attacks
  • Wants a full security audit of their development environment

Example prompts

  • “am I compromised”
  • “check my security”
  • “scan for leaked keys”
  • “/dev-security-audit”

Requirements

  • Docker

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Supply Chain IoC Dispatch
  2. Credential & Secret Exposure Scan
  3. Application & Browser Data Scan
  4. Persistence & Backdoor Check
  5. Report Generation

What it can do on your machine

Read from SKILL.md and the folder at commit c9a2036. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws
    • docker
    • osascript

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws and docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dev Security Audit loads about 3.6k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 144 tokens; SKILL.md has 1,195 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~144
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:85
    - AWS (`~/.aws/credentials`, `~/.aws/config`)
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:88
    - Kubernetes (`~/.kube/config`, `~/.kube/custom-contexts/`)
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:90
    - Docker (`~/.docker/config.json`)
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:93
    - SSH keys (`~/.ssh/`)
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:97
    - npm (`~/.npmrc`)
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:98
    - GPG keys (`~/.gnupg/private-keys-v1.d/`)
  • NoteMentions a .env fileSKILL.md:102
    - `.env` files (`find ~ -maxdepth 5 \( -name ".env" -o -name ".env.*" \) 2>/dev/null | grep -v node_modules | grep -v .g
  • NoteMentions a .env fileSKILL.md:117
    to extract tokens from shell history and .env files:
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:176
    Browsers store Login Data, Cookies, and Local Storage accessible to user-space processes:
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:187
    Note: Chrome's Login Data is encrypted via macOS Keychain. Under RCE, the attacker could potentially decrypt it during a

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sd0xdev/sd0x-harness at commit c9a2036, republished under its MIT licence (© sd0xdev). 1,195 words, ~3,553 tokens.

Download SKILL.mdSave it as .claude/skills/dev-security-audit/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
dev-security-audit
description
Comprehensive developer workstation security audit — scans for exposed credentials, compromised application data, persistence mechanisms, and supply chain attack indicators. Use this skill whenever the user suspects their machine may be compromised, wants to check for exposed secrets, asks about supply chain attacks, or wants a full security audit of their development environment. Also triggers on: 'am I compromised', 'check my security', 'scan for leaked keys', 'credential audit', 'supply chain attack', 'supply chain check', 'check if I was hacked'.

Developer Workstation Security Audit

A systematic, multi-phase security audit for developer workstations. Checks for supply chain compromise indicators (via case-based IoC library at references/cases/), scans for exposed credentials across 20+ categories, and generates a prioritized remediation plan.

When to Use

  • User suspects their machine was compromised
  • User wants to check for exposed secrets/credentials
  • User heard about a supply chain attack and wants to check if affected
  • User wants a general security audit of their dev environment
  • Post-incident response: credential rotation planning

When NOT to Use

  • Code-level security review (use /codex-security or /security-review)
  • Dependency vulnerability audit (use /dep-audit)
  • OWASP Top 10 web app audit (use /codex-security)
  • Runtime application security testing

Workflow Overview

mermaid
sequenceDiagram
    participant U as User
    participant C as Claude
    participant S as System
    C->>S: Phase 0: Supply Chain IoC Dispatch (case-driven)
    C->>S: Phase 1: Credential & Secret Exposure Scan
    C->>S: Phase 2: Application & Browser Data Scan
    C->>S: Phase 3: Persistence & Backdoor Check
    C->>U: Phase 4: Report Generation & Remediation Plan

Run phases sequentially. Each phase produces findings that feed into the final report. Use the reference files for detailed scan targets and IoC lists.

Evidence preservation: Before any cleanup or deletion, always copy/archive artifacts for forensic analysis. Never destroy evidence before the report is generated.

Phase 0: Supply Chain IoC Dispatch

Check for known supply chain compromises using the case library (references/cases/). This phase is conditional — it runs only when matching cases are found.

Dispatch Algorithm
  1. Detect platform: macOS / Linux / Windows
  2. Load case catalog: Read references/cases/README.md for active cases
  3. Scan product presence: For each active case, check if the product is installed on the system
  4. Execute matching cases: Load the case file and run its Detection Commands section
Dispatch Rules
ConditionAction
No matching case (product not installed)Skip Phase 0, proceed to Phase 1
Single matchLoad case file, run detection + interpretation
Multiple matchesIterate: execute each case sequentially
Output Contract

For each matched case, report:

FieldDescription
case_idFrom case frontmatter (e.g., PRODUCT-YYYY-MM)
statusCOMPROMISED / INCONCLUSIVE / CLEAN / NOT_INSTALLED
confidenceFrom case frontmatter + detection result

If any case returns COMPROMISED, execute evidence preservation per case file instructions before proceeding.

Phase 1: Credential & Secret Exposure Scan

Scan for ALL sensitive files an attacker with user-space read access could have exfiltrated. This scan reveals credential hygiene issues regardless of supply chain compromise status.

Read references/scan-targets.md for the complete list. Below is the execution strategy.

Scan Strategy

Run scans in parallel where possible (use subagents for independent categories). Group into 3 parallel tracks:

Track A — Cloud & Infrastructure Credentials:

  • AWS (~/.aws/credentials, ~/.aws/config)
  • GCP (~/.config/gcloud/ — credentials.db, access_tokens.db, application_default_credentials.json)
  • Azure (~/.azure/)
  • Kubernetes (~/.kube/config, ~/.kube/custom-contexts/)
  • Terraform (~/.terraform.d/credentials.tfrc.json)
  • Docker (~/.docker/config.json)

Track B — Development Tool Tokens:

  • SSH keys (~/.ssh/)
  • Git credentials (~/.git-credentials, ~/.gitconfig)
  • GitHub CLI (~/.config/gh/)
  • GitLab CLI (~/.config/glab-cli/)
  • npm (~/.npmrc)
  • GPG keys (~/.gnupg/private-keys-v1.d/)

Track C — Application Secrets & History:

  • Shell history token scan (grep for patterns below)
  • .env files (find ~ -maxdepth 5 \( -name ".env" -o -name ".env.*" \) 2>/dev/null | grep -v node_modules | grep -v .git)
  • Crypto wallets (Solana, Electrum, etc.)
  • VPN configs (*.ovpn, WireGuard)
Parallel Scan Merge Rules
#RuleDescription
1Subagent parallelTracks A/B/C may run via subagents in parallel for speed
2Unified output schemaAll tracks emit: Category | Path | Severity | Redacted Sample | Action
3Dedup by keyMerge results using (Path + Indicator Type + Token Prefix) as dedup key
4Critical bubble-upCritical/Critical+ findings surface immediately — do not wait for full scan
Token Pattern Reference

Use these regex patterns to extract tokens from shell history and .env files:

OpenAI:           sk-[a-zA-Z0-9_-]{20,}
Anthropic:        sk-ant-[a-zA-Z0-9_-]{20,}
GitHub Classic:   gh[posur]_[a-zA-Z0-9]{20,}
GitHub Fine-grain: github_pat_[a-zA-Z0-9_]{20,}
GitLab PAT:       glpat-[a-zA-Z0-9_-]{20,}
AWS Access:       AKIA[A-Z0-9]{16}
AWS Temp:         ASIA[A-Z0-9]{16}
HuggingFace:      hf_[a-zA-Z0-9]{20,}
npm:              npm_[a-zA-Z0-9]{20,}
Docker Hub:       dckr_pat_[a-zA-Z0-9_-]{20,}
Slack:            xox[bsrp]-[a-zA-Z0-9-]{20,}
Stripe:           [rs]k_live_[a-zA-Z0-9]{20,}
Firebase:         AIza[a-zA-Z0-9_-]{30,}
JWT:              eyJ[a-zA-Z0-9_-]+\.eyJ[a-zA-Z0-9_-]+\.[a-zA-Z0-9_-]+
Vercel:           vercel_[a-zA-Z0-9_-]{20,}
Supabase:         sbp_[a-zA-Z0-9]{20,}

When displaying found tokens to the user, always partially redact them (show first 8 and last 4 chars) so they can identify which token it is without fully exposing it in conversation history.

Crypto Wallet Check

Crypto wallets deserve special urgency — asset theft is irreversible:

WalletPathKey Storage
Solana CLI~/.config/solana/id.jsonPlaintext 64-byte keypair
Electrum~/.electrum/wallets/Encrypted (but copyable for offline brute force)
OneKey~/Library/Application Support/@onekeyhq/desktop/Encrypted in LevelDB
Ledger Live~/Library/Application Support/Ledger Live/Hardware key (safe), but addresses exposed
Tonkeeper~/Library/Application Support/@tonkeeper/desktop/Check LevelDB

For plaintext keys (Solana), immediately check balance via RPC. For encrypted wallets (Electrum), the wallet files could have been copied for offline cracking — advise transferring funds to a new wallet.

Phase 2: Application & Browser Data Scan

User-space RCE can read any application's local data. Electron apps are especially vulnerable because they store data in unencrypted LevelDB.

Electron App Scan

List all Electron apps by checking for LevelDB in Local Storage:

bash
find ~/Library/Application\ Support/*/Local\ Storage/leveldb -maxdepth 0 2>/dev/null

High-priority Electron apps to check:

  • Communication: Slack, Discord, Telegram, LINE, WhatsApp Desktop
  • Dev tools: VS Code, GitKraken, Postman, MongoDB Compass
  • Crypto: OneKey, Ledger Live, Tonkeeper
  • AI: Claude Desktop, ChatGPT Desktop

For each, run strings on the LevelDB files and grep for token, secret, password, auth, session. Always pipe through redaction before output: sed -E 's/(.{8}).{4,}(.{4})/\1****\2/g'. Never print raw secrets to conversation or report — redact at the pipeline level, not as an afterthought.

Show full SKILL.md (441 more words)Show less
Browser Data

Browsers store Login Data, Cookies, and Local Storage accessible to user-space processes:

bash
# Chrome profiles
ls ~/Library/Application\ Support/Google/Chrome/*/Login\ Data 2>/dev/null
# Firefox
ls ~/Library/Application\ Support/Firefox/Profiles/*/logins.json 2>/dev/null
# Arc
ls ~/Library/Application\ Support/Arc/*/Login\ Data 2>/dev/null

Note: Chrome's Login Data is encrypted via macOS Keychain. Under RCE, the attacker could potentially decrypt it during an active user session via the security CLI or Chrome DevTools Protocol.

macOS Keychain
bash
ls ~/Library/Keychains/ 2>/dev/null

Keychain files are encrypted, but during an active session with RCE, the attacker could use security dump-keychain or security find-generic-password to extract individual items. This is a medium risk — it requires the keychain to be unlocked (which it usually is during a user session).

Phase 3: Persistence & Backdoor Check

Check whether the attacker established any persistence mechanisms to survive application removal. Case-specific persistence indicators (e.g., known backdoor binaries) are checked in Phase 0 via case files.

macOS
bash
# User LaunchAgents (most common persistence vector)
ls ~/Library/LaunchAgents/

# System LaunchDaemons (requires root, less likely for user-space attack)
ls /Library/LaunchDaemons/

# Non-Apple launchctl services
launchctl list | grep -v com.apple

# Cron jobs
crontab -l

# Login items
osascript -e 'tell application "System Events" to get the name of every login item' 2>/dev/null
Linux
bash
crontab -l
ls /etc/cron.d/
systemctl list-unit-files --type=service | grep -v disabled
Windows (instruct user to run)
schtasks /query /fo LIST /v
sc query type=service state=all | findstr /v /i "Microsoft Windows"
reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Run"
Suspicious Binary Check

Scan common binary locations for unsigned or unexpected executables:

bash
ls -la /usr/local/bin/ | head -30
# List executables modified within a suspected attack window
# Use dates from Phase 0 case match (attack_window.start/end) or user-provided window
WINDOW_START="${ATTACK_WINDOW_START:?Set ATTACK_WINDOW_START from Phase 0 case match}"
WINDOW_END="${ATTACK_WINDOW_END:?Set ATTACK_WINDOW_END from Phase 0 case match}"
find /usr/local/bin -type f -newermt "$WINDOW_START" ! -newermt "$WINDOW_END" 2>/dev/null | while read f; do
  file "$f" 2>/dev/null | grep -q "executable" && echo "SUSPECT: $f ($(stat -f '%Sm' "$f" 2>/dev/null || stat -c '%y' "$f" 2>/dev/null))"
done

Phase 4: Report Generation

After all scans complete, generate a prioritized report and save to /tmp/.

Report Output

Write the report to a secure temp file via mktemp. This keeps the report outside the repo (no accidental commit of sensitive findings) and accessible for the user to review, copy, or forward.

bash
umask 077
REPORT_PATH="${TMPDIR:-/tmp}/security-audit-$(hostname -s)-$(date +%Y%m%d-%H%M%S).md"
touch "$REPORT_PATH" && chmod 600 "$REPORT_PATH"
# Write report content to $REPORT_PATH
echo "Report saved to: $REPORT_PATH"

Example output: /tmp/security-audit-macbook-pro-20260325-143052.md

Severity Classification
SeverityCriteriaExamples
Critical+Immediate asset loss riskCrypto wallet private keys, plaintext
CriticalFull account/infrastructure takeoverAWS keys, GCP refresh tokens, K8s admin tokens
HighAccount access or data theftGit tokens, npm tokens, API keys, VPN configs
MediumEncrypted/protected but potentially exposedKeychain, encrypted wallets, browser Login Data
LowInformation disclosure onlyknown_hosts, directory structure, git config
Report Template
markdown
# Security Audit Report

## Summary
- Scan date: YYYY-MM-DD
- Platform: macOS/Linux/Windows
- Supply Chain IoC: [per-case status from Phase 0, or "No active cases matched"]
- Total findings: N (N critical, N high, N medium, N low)

## Supply Chain Status
[Per-case results table: case_id | status | confidence]

## Critical Findings (Immediate Action Required)
| # | Category | Item | Path | Action |

## High Findings (Action Within 24h)
| # | Category | Item | Path | Action |

## Medium Findings (Evaluate & Monitor)
| # | Category | Item | Path | Action |

## Recommended Action Plan
### Tier 0 — Immediately (minutes)
### Tier 1 — Today (hours)
### Tier 2 — This Week
### Tier 3 — Contingency Triggers

## What Was NOT Found (Good News)
[List of categories that came back clean]
Remediation Priority Rules
  1. Crypto wallets with plaintext keys — Check balance first, transfer if needed, then delete key
  2. Cloud provider credentials (AWS/GCP/Azure) — Revoke immediately (can re-mint access)
  3. Git platform tokens (GitHub/GitLab) — Revoke (can push malicious code)
  4. npm/PyPI/registry tokens — Revoke (supply chain risk)
  5. SSH keys — Generate new keys, update all services, then delete old
  6. Shell history — Clear after extracting token list for revocation
  7. VPN configs — Notify IT team
  8. .env.production files — Audit and rotate all contained secrets
  9. Communication app tokens — Re-login to invalidate sessions
  10. Browser passwords — Evaluate scope, consider full password rotation

Verification Checklist

  • Supply chain IoC cases checked (Phase 0 dispatch)
  • All cloud provider credential paths checked
  • Shell history scanned for token patterns
  • .env files enumerated
  • Crypto wallet paths checked
  • SSH directory fully inventoried
  • Electron app LevelDB scanned
  • Browser Login Data enumerated
  • Persistence mechanisms checked
  • Report generated with severity classification
  • Remediation plan prioritized by risk

References

FilePurpose
references/scan-targets.mdComplete list of file paths to scan per platform
references/remediation.mdDetailed remediation procedures per category
references/cases/Supply chain incident case library (IoC + detection + cleanup per case)

© sd0xdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/dev-security-audit of sd0xdev/sd0x-harness.

  • SKILL.md
  • references/cases/README.md
  • references/cases/apifox-2026-03.md
  • references/cases/axios-2026-03.md
  • references/remediation.md
  • references/scan-targets.md

Open the folder on GitHubat commit c9a2036

Compare with similar skills

Dev Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dev Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dev Security Audit this skillsd0xdev/sd0x-harness192—~3.6kAutomated safety check: WarnMIT
Kesekit Checkcdppcorp/KESE-KIT359—~1.3kAutomated safety check: PassMIT
EdgeOne ClawScanTencent/AI-Infra-Guard6.8k—~9.5kAutomated safety check: PassMIT
Security Reviewvalory-xyz/open-autonomy129—~11kAutomated safety check: NotesApache-2.0
Container Security Hardeningsickn33/agentic-awesome-skills47k1 repos~1kAutomated safety check: NotesMIT
Securitynotque/vexjoy-agent435—~2.6kAutomated safety check: NotesMIT

Similar skills

  • Kesekit Check

    cdppcorp/KESE-KIT

    Run a pre-deployment security compliance checklist based on KISA guidelines.

    359 GitHub stars~1.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • EdgeOne ClawScan

    Tencent/AI-Infra-Guard

    Runs a security health check on an OpenClaw environment and audits skills before or after installation for supply-chain and data-leak risks.

    6.8k GitHub stars~9.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Review

    valory-xyz/open-autonomy

    Security review of an open-autonomy agent service — cryptographic key handling, dynamic code execution, ABCI authentication and replay, secret exposure, dependency supply chain, and deployment…

    129 GitHub stars~11k tokensUpdated 23 days ago
    SecurityAuto-check: notes
  • Container Security Hardening

    sickn33/agentic-awesome-skills

    Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

    47k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes
  • Security

    notque/vexjoy-agent

    Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks.

    435 GitHub stars~2.6k tokensUpdated 4 days ago
    SecurityAuto-check: notes
  • Gha Security Review

    getsentry/skills

    Official

    GitHub Actions security review for workflow exploitation vulnerabilities.

    1k GitHub starsUsed in 3 repos~2.2k tokens
    SecurityAuto-check: notes

More from sd0xdev/sd0x-harness

All 91 skills in this repo
  • Adr

    sd0xdev/sd0x-harness

    Write an Architecture Decision Record (ADR) for a feature — Context / Decision / Status / Consequences / Alternatives, filed as docs/features/<feature/adr-<NNN-<title.md with a 3-digit zero-padded…

    192 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Load PR Review

    sd0xdev/sd0x-harness

    Load GitHub PR review comments into AI session — analyze, triage, plan.

    192 GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • Next Step

    sd0xdev/sd0x-harness

    Change-aware next step advisor. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Obsidian CLI

    sd0xdev/sd0x-harness

    Obsidian vault integration via official CLI. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Orchestrate

    sd0xdev/sd0x-harness

    Agent-driven workflow orchestration (v1 report-only). An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • PR Comment

    sd0xdev/sd0x-harness

    Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review.

    192 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Dev Security Audit

What does Dev Security Audit do?

Comprehensive developer workstation security audit — scans for exposed credentials, compromised application data, persistence mechanisms, and supply chain attack indicators. Dev Security Audit is an agent skill from sd0xdev/sd0x-harness. Comprehensive developer workstation security audit — scans for exposed credentials, compromised application data, persistence mechanisms, and supply chain attack indicators.

When should I use Dev Security Audit?

Dev Security Audit fits situations like: the user suspects their machine may be compromised; wants to check for exposed secrets; asks about supply chain attacks; wants a full security audit of their development environment.

How do I install Dev Security Audit in Claude Code?

Run `npx skills add sd0xdev/sd0x-harness --skill dev-security-audit -a claude-code`. Or copy the skill folder (skills/dev-security-audit in sd0xdev/sd0x-harness) into .claude/skills/dev-security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Dev Security Audit in Codex?

Run `npx skills add sd0xdev/sd0x-harness --skill dev-security-audit -a codex`. Or copy the skill folder (skills/dev-security-audit in sd0xdev/sd0x-harness) into .agents/skills/dev-security-audit in your project. Codex loads it when a task matches its description.

Can I use Dev Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sd0xdev/sd0x-harness --skill dev-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dev-security-audit, .gemini/skills/dev-security-audit, .github/skills/dev-security-audit and .opencode/skills/dev-security-audit in your project.

What does Dev Security Audit need to run?

Going by SKILL.md and its folder, Dev Security Audit needs the command-line tools its instructions call (aws, docker and osascript). Our summary lists: Docker.

Does Dev Security Audit access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dev Security Audit safe to install?

Our automated static check of SKILL.md flagged 8 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Dev Security Audit use?

Dev Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dev Security Audit use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 10k tokens, read only when the agent opens those files.

What are the alternatives to Dev Security Audit?

Skills that share tags, products or a category with Dev Security Audit: Kesekit Check (cdppcorp/KESE-KIT, 359 stars), EdgeOne ClawScan (Tencent/AI-Infra-Guard, 6.8k stars), Security Review (valory-xyz/open-autonomy, 129 stars) and Container Security Hardening (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dev Security Audit?

sd0xdev (a GitHub user) maintains it in sd0xdev/sd0x-harness, which has 192 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 6, 2026.

Source: sd0xdev/sd0x-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.