Agent skill

Audit Skills

by sickn33 in sickn33/agentic-awesome-skills

Expert security auditor for AI Skills and Bundles. An agent skill from sickn33/agentic-awesome-skills.

MITAuto-check: warningsSecurity

Install Audit Skills

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill audit-skills -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills audit-skills --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/audit-skills .claude/skills/audit-skills && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-skills
GitHub stars
47k
Used in
2 other repos
Token cost
~1.6k tokens
SKILL.md length
641 words
Files
1
Skills in repo
1,497
Repo updated
First seen
Licence
MIT

At a glance

Expert security auditor for AI Skills and Bundles. An agent skill from sickn33/agentic-awesome-skills.

  • Works in 3 steps: Static Analysis → Platform-Specific Threat Detection → Reporting
  • Tasks that involve Static analysis and SAST
  • SKILL.md covers Overview, When to Use This Skill, How It Works and Examples, plus 4 more sections
  • Calls adb, choco and apt-get

What it does

Audit Skills is an agent skill from sickn33/agentic-awesome-skills. Expert security auditor for AI Skills and Bundles. Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated payloads across Windows, macOS, Linux/Unix, and Mobile (Android/iOS).

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Static analysis and SAST. It works with Android, iOS, macOS and Linux. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve Static analysis and SAST

Example prompts

  • “/audit-skills”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Static Analysis
  2. Platform-Specific Threat Detection
  3. Reporting

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • adb
    • choco
    • apt-get
    • yum
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Skills loads about 1.6k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 641 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:69
    - **Sensible Data**: `.env`, `.ssh`, `cookies.sqlite`, `Keychains` (macOS), `Credentials` (Windows), `keystore` (Android

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 641 words, ~1,550 tokens.

Download SKILL.mdSave it as .claude/skills/audit-skills/SKILL.md (or your agent's skills folder).
name
audit-skills
description
Expert security auditor for AI Skills and Bundles. Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated payloads across Windows, macOS, Linux/Unix, and Mobile (Android/iOS).
category
security
risk
safe
source
community
date_added
2026-03-07
author
MAIOStudio
tags
security, audit, skills, bundles, cross-platform
tools
claude, gemini, gpt, llama, mistral, etc

Audit Skills (Premium Universal Security)

Overview

Expert security auditor for AI Skills and Bundles. Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated payloads across Windows, macOS, Linux/Unix, and Mobile (Android/iOS). 2-4 sentences is perfect.

When to Use This Skill

  • Use when you need to audit AI skills and bundles for security vulnerabilities
  • Use when working with cross-platform security analysis
  • Use when the user asks about verifying skill legitimacy or performing security reviews
  • Use when scanning for mobile threats in AI skills

How It Works

Step 1: Static Analysis

Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated payloads.

Step 2: Platform-Specific Threat Detection

Analyzes code for platform-specific security issues across Windows, macOS, Linux/Unix, and Mobile (Android/iOS).

1. Privilege, Ownership & Metadata Manipulation
  • Elevated Access: sudo, chown, chmod, TakeOwnership, icacls, Set-ExecutionPolicy.
  • Metadata Tampering: touch -t, setfile (macOS), attrib (Windows), Set-ItemProperty, chflags.
  • Risk: Unauthorized access, masking activity, or making files immutable.
2. File/Folder Locking & Resource Denial
  • Patterns: chmod 000, chattr +i (immutable), attrib +r +s +h, Deny ACEs in icacls.
  • Global Actions: Locking or hiding folders in %USERPROFILE%, /Users/, or /etc/.
  • Risk: Denial of service or data locking.
3. Script Execution & Batch Invocation
  • Legacy/Batch Windows: .bat, .cmd, cmd.exe /c, vbs, cscript, wscript.
  • Unix Shell: .sh, .bash, .zsh, chmod +x followed by execution.
  • PowerShell: .ps1, powershell -ExecutionPolicy Bypass -File ....
  • Hidden Flags: -WindowStyle Hidden, -w hidden, -noprofile.
4. Dangerous Install/Uninstall & System Changes
  • Windows: msiexec /qn, choco uninstall, reg delete.
  • Linux/Unix: apt-get purge, yum remove, rm -rf /usr/bin/....
  • macOS: brew uninstall, deleting from /Applications.
  • Risk: Removing security software or creating unmonitored installation paths.
5. Mobile Application & OS Security (Android/iOS)
  • Android Tools: adb shell, pm install, am start, apktool, dex2jar, keytool.
  • Android Files: Manipulation of AndroidManifest.xml (permissions), classes.dex, or strings.xml.
  • iOS Tools: xcodebuild, codesign, security find-identity, fastlane, xcrun.
  • iOS Files: Manipulation of Info.plist, Entitlements.plist, or Provisioning Profiles.
  • Mobile Patterns: Jailbreak/Root detection bypasses, hardcoded API keys in mobile source, or sensitive permission requests (Camera, GPS, Contacts) in non-mobile skills.
  • Risk: Malicious mobile package injection, credential theft from mobile builds, or device manipulation via ADB.
6. Information Disclosure & Network Exfiltration
  • Patterns: curl, wget, Invoke-WebRequest, Invoke-RestMethod, scp, ftp, nc, socat.
  • Sensible Data: .env, .ssh, cookies.sqlite, Keychains (macOS), Credentials (Windows), keystore (Android).
  • Intranet: Scanning internal IPs or mapping local services.
Show full SKILL.md (259 more words)Show less
7. Service, Process & Stability Manipulation
  • Windows: Stop-Service, taskkill /f, sc.exe delete.
  • Unix/Mac: kill -9, pkill, systemctl disable/stop, launchctl unload.
  • Low-level: Direct disk access (dd), firmware/BIOS calls, kernel module management.
8. Obfuscation & Persistence
  • Encoding: Base64, Hex, XOR loops, atob().
  • Persistence: reg add (Run keys), schtasks, crontab, launchctl (macOS), systemd units.
  • Remote script piping: network fetch commands that stream directly into a shell or PowerShell evaluator.
9. Legitimacy & Scope (Universal)
  • Registry Alignment: Cross-reference with CATALOG.md.
  • Structural Integrity: Does it follow the standard repo layout?
  • Healthy Scope: Does a "UI Design" skill need adb shell or sudo?
Step 3: Reporting

Generates a security report with a score (0-10), platform target identification, flagged actions, threat analysis, and mitigation recommendations.

Examples

Example 1: Security Review
markdown
"Perform a security audit on this skill bundle"
Example 2: Cross-Platform Threat Analysis
markdown
"Scan for mobile threats in this AI skill"

Best Practices

  • ✅ Perform non-intrusive analysis
  • ✅ Check for privilege escalation patterns
  • ✅ Look for information disclosure vulnerabilities
  • ✅ Analyze cross-platform threats
  • ❌ Don't execute potentially malicious code during audit
  • ❌ Don't modify the code being audited
  • ❌ Don't ignore mobile-specific security concerns

Common Pitfalls

  • Problem: Executing code during audit Solution: Stick to static analysis methods only

  • Problem: Missing cross-platform threats Solution: Check for platform-specific security issues on all supported platforms

  • Problem: Failing to detect obfuscated payloads Solution: Look for encoding patterns like Base64, Hex, XOR loops, and atob()

  • @security-scanner - Additional security scanning capabilities

Limitations

  • Use this skill only when the task clearly matches the scope described above.
  • Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
  • Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/audit-skills of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit b84d35a

Used in 2 other repositories

We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Audit Skills next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Skills compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Skills this skillsickn33/agentic-awesome-skills47k2 repos~1.6kAutomated safety check: WarnMIT
Engine Whats Newflutter/flutter179k—~978Automated safety check: PassBSD-3-Clause
Jetpack Composedarriousliu/PiPixiv263—~1.5kAutomated safety check: PassApache-2.0
Maui AI DebuggingRedth/Maui.Gtk101—~4.1kAutomated safety check: PassMIT
Commitmanhpham90vn/Deskhub133—~978Automated safety check: PassMIT
flutter_soloud Setupalnitak/flutter_soloud425—~3.6kAutomated safety check: NotesMIT

Similar skills

  • Engine Whats New

    flutter/flutter

    Generates the "what's new" release summary and diff file for changes in the Flutter engine (//engine/src/flutter) between two releases (e.g., 3.47 vs 3.44).

    179k GitHub stars~978 tokensUpdated today
    MobileAuto-check passed
  • Jetpack Compose

    darriousliu/PiPixiv

    Jetpack Compose expert skill for Android UI development. An agent skill from darriousliu/PiPixiv.

    263 GitHub stars~1.5k tokensUpdated yesterday
    MobileAuto-check passed
  • Maui AI Debugging

    Redth/Maui.Gtk

    End-to-end workflow for building, deploying, inspecting, and debugging .NET MAUI and MAUI Blazor Hybrid apps as an AI agent.

    101 GitHub stars~4.1k tokensUpdated 5 mo ago
    MobileAuto-check passed
  • Commit

    manhpham90vn/Deskhub

    Write a Deskhub commit message. An agent skill from manhpham90vn/Deskhub.

    133 GitHub stars~978 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • flutter_soloud Setup

    alnitak/flutter_soloud

    Walks through adding the flutter_soloud audio engine to a Flutter app, with per-platform setup, initialization, binary-size and logging options, and output device switching.

    425 GitHub stars~3.6k tokensUpdated yesterday
    MobileAuto-check: notes
  • Fkit Setup

    Joker-x-dev/FlutterKit

    将 FlutterKit 脚手架初始化为新的应用项目,统一修改应用显示名称、Dart 包名、Android Application ID、Apple Bundle ID、Linux/Windows 标识、Web 名称、运行时品牌文案、Logo、桌面图标和启动页。用户拉取模板后要求改名、改包名、替换品牌资源或完成首次项目配置时使用。

    127 GitHub stars~720 tokensUpdated 2 mo ago
    MobileAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about Audit Skills

What does Audit Skills do?

Expert security auditor for AI Skills and Bundles. An agent skill from sickn33/agentic-awesome-skills. Audit Skills is an agent skill from sickn33/agentic-awesome-skills. Expert security auditor for AI Skills and Bundles.

When should I use Audit Skills?

Audit Skills fits situations like: tasks that involve Static analysis and SAST.

How do I install Audit Skills in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill audit-skills -a claude-code`. Or copy the skill folder (skills/audit-skills in sickn33/agentic-awesome-skills) into .claude/skills/audit-skills in your project. Claude Code loads it when a task matches its description.

How do I install Audit Skills in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill audit-skills -a codex`. Or copy the skill folder (skills/audit-skills in sickn33/agentic-awesome-skills) into .agents/skills/audit-skills in your project. Codex loads it when a task matches its description.

Can I use Audit Skills in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill audit-skills -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-skills, .gemini/skills/audit-skills, .github/skills/audit-skills and .opencode/skills/audit-skills in your project.

What does Audit Skills need to run?

Going by SKILL.md and its folder, Audit Skills needs the command-line tools its instructions call (adb, choco, apt-get, yum and brew).

Does Audit Skills access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Audit Skills safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Audit Skills use?

Audit Skills is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Skills use?

About 1.6k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Skills?

Skills that share tags, products or a category with Audit Skills: Engine Whats New (flutter/flutter, 179k stars), Jetpack Compose (darriousliu/PiPixiv, 263 stars), Maui AI Debugging (Redth/Maui.Gtk, 101 stars) and Commit (manhpham90vn/Deskhub, 133 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Skills?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.