Agent skill

Security Audit

by seb1n in seb1n/awesome-ai-agent-skills

Perform a broad, authorized security audit across application, infrastructure, identity, dependencies, and operations.

MITAuto-check: notesSecurity

Install Security Audit

skills CLI
$ npx skills add seb1n/awesome-ai-agent-skills --skill security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install seb1n/awesome-ai-agent-skills security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security/security-audit .claude/skills/security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-audit
GitHub stars
206
Token cost
~2.4k tokens
SKILL.md length
1,006 words
Files
1
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Perform a broad, authorized security audit across application, infrastructure, identity, dependencies, and operations.

  • Works in 6 steps: Gather System Information — Collect… → Define Audit Scope and Compliance… → Perform Automated Vulnerability Scanning… → …
  • The user needs a scoped security posture review
  • SKILL.md covers Workflow, Supported Technologies, Usage and Examples, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Audit is an agent skill from seb1n/awesome-ai-agent-skills. Perform a broad, authorized security audit across application, infrastructure, identity, dependencies, and operations. Use when the user needs a scoped security posture review; use the SAST, DAST, dependency-scanning, or threat-modeling skill when the request is limited to one specialist activity.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review, Threat modeling and Static analysis and SAST. The repository describes itself as: 103 ready-to-use AI agent skills for Claude Code, OpenAI Codex, Gemini CLI, Cursor, GitHub Copilot, Windsurf, and other Agent Skills-compatible tools. Complete SKILL.md… The licence is MIT.

When your agent uses it

  • The user needs a scoped security posture review
  • Dependency-scanning
  • Threat-modeling skill when the request is limited to one specialist activity

Example prompts

  • “/security-audit”

Requirements

  • Node.js
  • Docker

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Gather System Information — Collect details about the target environment including the technology stack, architecture diagrams, network…
  2. Define Audit Scope and Compliance Targets — Establish the boundaries of the audit by identifying which components, environments, and data…
  3. Perform Automated Vulnerability Scanning — Run automated scanners against the target to identify known vulnerabilities. Use tools like…
  4. Conduct Manual Security Review — Manually inspect authentication flows, session management, role-based access controls, input sanitization…
  5. Analyze and Classify Findings — Assess each finding for severity (Critical, High, Medium, Low, Informational) using CVSS scoring. Assign…
  6. Generate Audit Report with Remediation Plan — Produce a structured report containing an executive summary, detailed findings with evidence…

What it can do on your machine

Read from SKILL.md and the folder at commit 75865a5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are javascript, bash and json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Audit loads about 2.4k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 1,006 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:57
    igh | JWT secret stored in plaintext in `.env` committed to repo | CWE-798 | A07:2021 Identification and Authentication

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from seb1n/awesome-ai-agent-skills at commit 75865a5, republished under its MIT licence (© seb1n). 1,006 words, ~2,352 tokens.

Download SKILL.mdSave it as .claude/skills/security-audit/SKILL.md (or your agent's skills folder).
name
security-audit
description
Perform a broad, authorized security audit across application, infrastructure, identity, dependencies, and operations. Use when the user needs a scoped security posture review; use the SAST, DAST, dependency-scanning, or threat-modeling skill when the request is limited to one specialist activity.
license
MIT
metadata.author
awesome-ai-agent-skills
metadata.version
1.0.0

Security Audit

This skill enables the agent to conduct a thorough security audit across web applications, APIs, cloud infrastructure, and backend services. The agent systematically examines authentication mechanisms, authorization controls, input validation, encryption practices, logging configurations, and deployment settings. Findings are mapped to industry frameworks such as the OWASP Top 10, CWE identifiers, and compliance standards including SOC 2 and PCI-DSS.

Workflow

  1. Gather System Information — Collect details about the target environment including the technology stack, architecture diagrams, network topology, deployment model, and third-party integrations. Review configuration files, environment variables, and infrastructure-as-code templates to build a complete picture of the attack surface.

  2. Define Audit Scope and Compliance Targets — Establish the boundaries of the audit by identifying which components, environments, and data flows are in scope. Map audit objectives to relevant compliance frameworks such as SOC 2 Type II, PCI-DSS, HIPAA, or internal security policies. Create a checklist derived from the OWASP Top 10 and CWE/SANS Top 25 to ensure systematic coverage.

  3. Perform Automated Vulnerability Scanning — Run automated scanners against the target to identify known vulnerabilities. Use tools like OWASP ZAP for web applications, Trivy or Grype for container images, and ScoutSuite or Prowler for cloud infrastructure. Aggregate raw findings for manual review.

  4. Conduct Manual Security Review — Manually inspect authentication flows, session management, role-based access controls, input sanitization routines, cryptographic implementations, error handling, and logging practices. Examine source code for hardcoded secrets, insecure deserialization, and business logic flaws that automated tools frequently miss.

  5. Analyze and Classify Findings — Assess each finding for severity (Critical, High, Medium, Low, Informational) using CVSS scoring. Assign CWE identifiers and map findings to the relevant OWASP Top 10 category. Evaluate exploitability, blast radius, and business impact to produce a prioritized risk ranking.

  6. Generate Audit Report with Remediation Plan — Produce a structured report containing an executive summary, detailed findings with evidence and reproduction steps, risk ratings, and specific remediation recommendations with estimated effort. Include a compliance gap analysis showing pass/fail status against the targeted framework controls.

Supported Technologies

  • Web Frameworks: Express.js, Django, Flask, Spring Boot, Rails, ASP.NET
  • Cloud Platforms: AWS (IAM, S3, EC2, RDS, Lambda), GCP, Azure
  • Container & Orchestration: Docker, Kubernetes, ECS
  • Scanning Tools: OWASP ZAP, Prowler, ScoutSuite, Trivy, Grype, Checkov
  • Compliance Frameworks: OWASP Top 10, CWE/SANS Top 25, SOC 2, PCI-DSS, HIPAA, NIST 800-53

Usage

Provide the agent with access to the application source code, infrastructure configuration, or a target URL along with the desired compliance scope. The agent will execute the full audit workflow and deliver a prioritized findings report.

Prompt example:

Perform a security audit of the Node.js Express application in /app. Focus on OWASP Top 10 coverage and SOC 2 compliance. Include CWE IDs and remediation steps for every finding.

Examples

Example 1: Auditing a Node.js Express Application

Target: E-commerce API built with Express.js, Sequelize ORM, and JWT authentication.

Findings Report (excerpt):

#SeverityTitleCWEOWASP Category
1CriticalSQL injection in product search endpointCWE-89A03:2021 Injection
2HighJWT secret stored in plaintext in .env committed to repoCWE-798A07:2021 Identification and Authentication Failures
3HighMissing rate limiting on /api/loginCWE-307A07:2021 Identification and Authentication Failures
4MediumVerbose error messages expose stack traces in productionCWE-209A04:2021 Insecure Design
5MediumCORS policy allows wildcard origin with credentialsCWE-942A05:2021 Security Misconfiguration
6LowHTTP security headers missing (X-Content-Type-Options, CSP)CWE-693A05:2021 Security Misconfiguration

Remediation for Finding #1:

javascript
// BEFORE — vulnerable to SQL injection
app.get('/api/products', async (req, res) => {
  const results = await sequelize.query(
    `SELECT * FROM products WHERE name LIKE '%${req.query.search}%'`
  );
  res.json(results);
});

// AFTER — parameterized query
app.get('/api/products', async (req, res) => {
  const results = await sequelize.query(
    'SELECT * FROM products WHERE name LIKE :search',
    { replacements: { search: `%${req.query.search}%` }, type: QueryTypes.SELECT }
  );
  res.json(results);
});
Example 2: Auditing AWS Infrastructure

Target: Production AWS account running a three-tier web application.

Prowler scan command:

bash
prowler aws --compliance soc2 pci_dss --output-formats json html --output-directory ./audit-report

Findings Report (excerpt):

#SeverityFindingAWS ServiceCompliance Control
1CriticalS3 bucket prod-user-uploads has public read access enabledS3PCI-DSS 7.1, SOC 2 CC6.1
2HighIAM user deploy-bot has inline AdministratorAccess policyIAMSOC 2 CC6.3
3HighRDS instance prod-db has encryption at rest disabledRDSPCI-DSS 3.4, SOC 2 CC6.1
4MediumCloudTrail logging is not enabled for all regionsCloudTrailSOC 2 CC7.2
5MediumSecurity group sg-0abc123 allows SSH (port 22) from 0.0.0.0/0EC2PCI-DSS 1.3

Remediation for Finding #2:

json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["ecr:GetAuthorizationToken", "ecs:UpdateService", "ecs:DescribeServices"],
      "Resource": "arn:aws:ecs:us-east-1:123456789012:service/prod-cluster/web-service"
    }
  ]
}
Show full SKILL.md (370 more words)Show less

Best Practices

  • Audit regularly on a schedule — perform audits quarterly at minimum and after every major release or infrastructure change, not just annually.
  • Combine automated and manual testing — automated scanners catch known vulnerability patterns, but manual review is essential for business logic flaws, authorization bypasses, and chained attack scenarios.
  • Use CWE and CVSS consistently — assign CWE identifiers and CVSS scores to every finding so that stakeholders can compare severity across audits and track remediation trends.
  • Verify remediation with retesting — after fixes are deployed, re-run the relevant audit checks to confirm the vulnerability is resolved and no regressions were introduced.
  • Maintain an audit trail — store all audit reports, evidence, and remediation records in a centralized repository to support compliance reviews and incident investigations.
  • Scope audits to include third-party integrations — payment gateways, OAuth providers, and SaaS APIs introduce risk that is easy to overlook when auditing only first-party code.

Safety Boundaries

  • Work only on systems the user owns or is explicitly authorized to assess, and record the approved scope before testing.
  • Start with passive or read-only inspection. Obtain explicit approval before active scanning, exploitation, load generation, or disruptive remediation.
  • Never expose secrets, extract unrelated data, weaken production controls, or expand beyond the approved targets.
  • Preserve evidence, minimize impact, stop on instability, and provide rollback or containment steps for every material change.

Edge Cases

  • Microservices with inconsistent security postures — one service may enforce authentication while another internal service trusts all traffic. Audit inter-service communication and verify that zero-trust principles are applied even within the private network.
  • Legacy systems without source code access — when source code is unavailable, rely on black-box testing, traffic analysis, and configuration review. Document the reduced coverage explicitly in the audit report.
  • Serverless and event-driven architectures — Lambda functions, Step Functions, and event triggers have ephemeral execution contexts. Audit IAM execution roles, event source permissions, and ensure sensitive data is not logged to CloudWatch in plaintext.
  • Multi-tenant applications — verify that tenant isolation is enforced at the data layer, API layer, and infrastructure layer. Test for horizontal privilege escalation between tenant accounts.
  • Applications behind WAF or CDN — automated scanners may only test the WAF-filtered surface. Where possible, also test the origin directly to identify vulnerabilities the WAF is masking rather than fixing.

© seb1n, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in security/security-audit of seb1n/awesome-ai-agent-skills.

Open the folder on GitHubat commit 75865a5

Compare with similar skills

Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Audit this skillseb1n/awesome-ai-agent-skills206—~2.4kAutomated safety check: NotesMIT
Audit Integritygithub/awesome-copilot40k—~1kAutomated safety check: PassMIT
CSO Security Auditgarrytan/gstack136k—~4.5kAutomated safety check: PassMIT
Trailmark Code Graphstrailofbits/skills7.4k1 repos~4.3kAutomated safety check: PassCC-BY-SA-4.0
Security Scanericrisco/rsc-harness167—~2.8kAutomated safety check: NotesMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Audit Integrity

    github/awesome-copilot

    Official

    Enforce output quality, evidence verification, and quality gates across security audits.

    40k GitHub stars~1k tokensUpdated today
    SecurityAuto-check passed
  • CSO Security Audit

    garrytan/gstack

    Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled.

    136k GitHub stars~4.5k tokensUpdated today
    SecurityAuto-check passed
  • Trailmark Code Graphs

    trailofbits/skills

    Official

    Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots.

    7.4k GitHub starsUsed in 1 repo~4.3k tokens
    SecurityAuto-check passed
  • Security Scan

    ericrisco/rsc-harness

    A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

    167 GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated today
    SecurityAuto-check: notes
  • CodeCrucible Security Scans

    block/codecrucible

    Official

    Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results.

    117 GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check passed

More from seb1n/awesome-ai-agent-skills

All 91 skills in this repo
  • Agent Red Teaming

    seb1n/awesome-ai-agent-skills

    Plan, execute, document, and retest authorized security assessments of AI agents and multi-agent workflows using safe adversarial cases, synthetic identities, canaries, and evidence-based findings.

    206 GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Eu AI Act Readiness

    seb1n/awesome-ai-agent-skills

    Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…

    206 GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Human In The Loop

    seb1n/awesome-ai-agent-skills

    Design and verify auditable human oversight, approval gates, escalation paths, and safe state transitions for AI agent workflows.

    206 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check passed
  • MCP Server Building

    seb1n/awesome-ai-agent-skills

    Design, implement, harden, and verify Model Context Protocol (MCP) servers with precise tool contracts, least-privilege authorization, safe transports, structured errors, and interoperability tests.

    206 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Skill Supply Chain Audit

    seb1n/awesome-ai-agent-skills

    Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk.

    206 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spreadsheet Analysis

    seb1n/awesome-ai-agent-skills

    Inspect, profile, clean, reconcile, analyze, visualize, and verify spreadsheet data while preserving formulas, formatting, types, and source files.

    206 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Security Audit

What does Security Audit do?

Perform a broad, authorized security audit across application, infrastructure, identity, dependencies, and operations. Security Audit is an agent skill from seb1n/awesome-ai-agent-skills. Perform a broad, authorized security audit across application, infrastructure, identity, dependencies, and operations.

When should I use Security Audit?

Security Audit fits situations like: the user needs a scoped security posture review; dependency-scanning; threat-modeling skill when the request is limited to one specialist activity.

How do I install Security Audit in Claude Code?

Run `npx skills add seb1n/awesome-ai-agent-skills --skill security-audit -a claude-code`. Or copy the skill folder (security/security-audit in seb1n/awesome-ai-agent-skills) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Security Audit in Codex?

Run `npx skills add seb1n/awesome-ai-agent-skills --skill security-audit -a codex`. Or copy the skill folder (security/security-audit in seb1n/awesome-ai-agent-skills) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.

Can I use Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add seb1n/awesome-ai-agent-skills --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.

What does Security Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Audit is instructions for the agent only. Our summary lists: Node.js; Docker.

Does Security Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Audit use?

Security Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Audit use?

About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Audit?

Skills that share tags, products or a category with Security Audit: Audit Integrity (github/awesome-copilot, 40k stars), CSO Security Audit (garrytan/gstack, 136k stars), Trailmark Code Graphs (trailofbits/skills, 7.4k stars) and Security Scan (ericrisco/rsc-harness, 167 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Audit?

seb1n (a GitHub user) maintains it in seb1n/awesome-ai-agent-skills, which has 206 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on August 9, 2026.

Source: seb1n/awesome-ai-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.