Cyber Neo
Hainrixz/cyber-neo
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -…
$ npx skills add staruhub/ClaudeSkills --skill security-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install staruhub/ClaudeSkills security-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/Geek-skills-security-audit .claude/skills/security-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-audit" agent skill from https://github.com/staruhub/ClaudeSkills/tree/main/skills/Geek-skills-security-audit into .claude/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/staruhub/ClaudeSkills/tree/main/skills/Geek-skills-security-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add staruhub/ClaudeSkills --skill security-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install staruhub/ClaudeSkills security-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/Geek-skills-security-audit .agents/skills/security-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-audit" agent skill from https://github.com/staruhub/ClaudeSkills/tree/main/skills/Geek-skills-security-audit into .agents/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add staruhub/ClaudeSkills --skill security-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install staruhub/ClaudeSkills security-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/Geek-skills-security-audit .cursor/skills/security-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-audit" agent skill from https://github.com/staruhub/ClaudeSkills/tree/main/skills/Geek-skills-security-audit into .cursor/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/staruhub/ClaudeSkills.git --path skills/Geek-skills-security-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add staruhub/ClaudeSkills --skill security-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install staruhub/ClaudeSkills security-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/Geek-skills-security-audit .gemini/skills/security-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/staruhub/ClaudeSkills/tree/main/skills/Geek-skills-security-audit into .gemini/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install staruhub/ClaudeSkills security-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add staruhub/ClaudeSkills --skill security-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/Geek-skills-security-audit .github/skills/security-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/staruhub/ClaudeSkills/tree/main/skills/Geek-skills-security-audit into .github/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add staruhub/ClaudeSkills --skill security-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install staruhub/ClaudeSkills security-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/Geek-skills-security-audit .opencode/skills/security-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/staruhub/ClaudeSkills/tree/main/skills/Geek-skills-security-audit into .opencode/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-audit全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -…
Security Audit is an agent skill from staruhub/ClaudeSkills. 全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 - Docker镜像和Kubernetes配置审计,(6) CI/CD安全检查。触发关键词:"安全检查"、"漏洞扫描"、"代码审计"、"security audit"、"vulnerability scan"、"SAST"、"dependency check"、"CVE检测"等。不用于:修复单个已定位的bug、编写新的安全功能代码、对无授权的第三方系统做扫描或渗透测试。
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `evals/routing-evals.json`, `references/detection_rules.md` and `references/remediation_guide.md`).
It sits in Security, covering Web application vulnerabilities, Security review and Vulnerability scanning. It works with SQL, Docker and Kubernetes. The repository describes itself as: 13 curated Agent Skills for research, product decisions, decks, publishing, audits, and more — portable across skills-compatible agents. The licence is MIT.
2 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 66e02d2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
npmpipxpippython3semgrepgitleakstrivyFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, pipx and pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Audit loads about 1.3k tokens when it runs, and up to ~6.9k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 258 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
sudo ufw status verbosesudo iptables -L -n -vAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from staruhub/ClaudeSkills at commit 66e02d2, republished under its MIT licence (© staruhub). 258 words, ~1,294 tokens.
.claude/skills/security-audit/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.全面的安全审计工具,覆盖代码静态分析(SAST)、依赖检查(SCA)和服务器配置审计。
本文件不维护具体CVE清单。凡涉及"某版本是否有漏洞"的结论,必须现场查询:
用 web search 查 [框架/库名] CVE advisory [当前年份],或查官方 security advisory 页面。
正文中出现的具体CVE(如 Log4Shell CVE-2021-44228)仅作为漏洞类别的历史案例,不代表当前威胁全貌。
安全审计遵循以下步骤:
# 安装核心Python扫描工具(优先用 venv/pipx,避免污染系统 Python)
pipx install bandit semgrep || pip install safety bandit semgrep pip-audit
# 安装Node.js安全工具(如需要)
npm install -g npm-audit-html retire运行综合扫描脚本:
python3 /path/to/skill/scripts/full_scan.py /path/to/project只需单项检查时用独立脚本:scripts/dependency_check.py(仅依赖漏洞)、scripts/secrets_scan.py(仅敏感信息/密钥,输出已对命中值脱敏)。
注意:dependency_check.py 内置的是离线基线表(会过时),命中结果标注 source: offline-baseline,必须用 pip-audit/npm audit 或官方 advisory 实时确认后才能下结论——与上文"不维护 CVE 清单"原则一致,基线表是预筛工具而非权威来源。
| 漏洞类型 | 历史案例 | 检测方式 |
|---|---|---|
| 框架/依赖 RCE | Log4Shell (CVE-2021-44228) | 依赖版本检查 + 现场搜索最新 advisory |
| SQL注入 | CWE-89 | SAST + 模式匹配 |
| 命令注入 | CWE-78 | SAST + 模式匹配 |
框架级 RCE 层出不穷(React/Next.js 等生态近年多次爆出),检查依赖前先 web search 该框架当年的 CVE 列表。
运行时先 web search 确认当前版本(现行为 2025 版);无法联网时使用下面这份记录时点的离线清单,并在报告中标注可能过时。以下条目为通用类别参考:
# Bandit - Python SAST
bandit -r ./src -f json -o bandit_report.json
# Safety - 依赖漏洞检查
safety check --json > safety_report.json
# pip-audit - 依赖审计
pip-audit --format json > pip_audit.json# npm audit - 依赖漏洞
npm audit --json > npm_audit.json
# Retire.js - 检测过时库
retire --js --outputformat json > retire_report.json框架专项检查:先 web search 确认该框架当前的高危 CVE 及官方检测工具,再执行(历史案例见 references/remediation_guide.md)。
# Semgrep - 多语言SAST
semgrep scan --config=auto --json > semgrep_report.json
# Gitleaks - 密钥泄露检测
gitleaks detect --source . --report-format json --report-path gitleaks.json
# Trivy - 容器/依赖扫描
trivy fs --format json --output trivy.json .# 检查SSH配置
grep -E "^(PermitRootLogin|PasswordAuthentication|PubkeyAuthentication)" /etc/ssh/sshd_config# UFW状态
sudo ufw status verbose
# iptables规则
sudo iptables -L -n -v# 查找SUID文件
find / -perm -4000 -type f 2>/dev/null
# 检查world-writable文件
find / -perm -002 -type f 2>/dev/null具体漏洞的修复命令和历史案例(含 React2Shell 完整处置记录)详见 references/remediation_guide.md。
full_scan.py 在 security_report/ 下生成:
security_report/
├── summary.md # 执行摘要 + 覆盖范围声明(工具缺失时列出缩窄项)
└── security_report.json # 结构化发现,按 critical/high/medium/low/info 分级 + skipped_toolssecrets_scan.py 另行生成 secrets_report.{json,md}(命中值已脱敏)。
汇总多来源发现、按严重性分文件时,从 security_report.json 的分级结构派生即可,不必依赖固定的六文件布局。
| 陷阱 | 具体表现 | 应对 |
|---|---|---|
| 扫描工具缺失时静默跳过 | 环境装不上 bandit/semgrep,直接不扫也不说明 | 降级为 grep 模式匹配,并在报告中明确声明覆盖范围缩窄 |
| 把"扫描通过"当"安全" | 工具零报告就写"系统安全" | 工具只覆盖已知模式;结论必须限定范围并列出未检查项 |
--break-system-packages 污染环境 | 全局 pip 安装扫描工具破坏系统 Python | 优先用 venv 或 pipx;用户环境受限时先征求同意 |
| 误报未过滤直接进报告 | SAST 把测试夹具、示例代码报为漏洞 | 每条 Critical 人工复核上下文,误报标注原因后移出 critical 列表 |
references/detection_rules.mdreferences/remediation_guide.mdreferences/server_hardening.mdevals/routing-evals.json(改动本 skill 的 description 后应重跑)© staruhub, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (scripts, references) in skills/Geek-skills-security-audit of staruhub/ClaudeSkills.
Open the folder on GitHubat commit 66e02d2
Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Audit this skillstaruhub/ClaudeSkills | 727 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Cyber NeoHainrixz/cyber-neo | 281 | — | ~5.9k | Automated safety check: Warn | MIT | |
| Security Analyzeraiskillstore/marketplace | 430 | — | ~1.2k | Automated safety check: Notes | None | |
| Code Audit3stoneBrother/code-audit | 893 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Secknowledge SkillPa55w0rd/secknowledge-skill | 423 | — | ~2.7k | Automated safety check: Pass | None | |
| Cyberowlaikarimhabush/cyberowl | 263 | — | ~2.5k | Automated safety check: Pass | MIT |
Hainrixz/cyber-neo
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
aiskillstore/marketplace
Comprehensive security vulnerability analysis for codebases and infrastructure.
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
Pa55w0rd/secknowledge-skill
Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。
karimhabush/cyberowl
Check if recent cybersecurity alerts from 10 international CERTs affect your current project.
AratKruglik/claude-laravel
A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.
staruhub/ClaudeSkills
A skill your agent uses when the user wants an evidence-based research memo, literature review, market/policy/technical landscape, or a multi-source decision brief with citations, trade-offs, and a…
staruhub/ClaudeSkills
用火山引擎 Podcast AI 模型生成中文双人对话播客。当用户要把文章、报告、话题文本转成播客音频、生成对话式音频内容时使用,需要环境具备火山引擎 APPID 和 ACCESSKEY。支持 mp3/oggopus/pcm/aac、语速调节、自定义音色、断点续传。不用于:单人朗读式 TTS(用普通语音合成)、英文播客(模型主要优化中文)、播客文稿本身的撰写(先用写作类 skill…
staruhub/ClaudeSkills
专业微信公众号文章助手,支持四个独立且可组合模式:article 写正文;image-prompts 从文章生成版本化、provider-neutral 的图片提示词 manifest 与稳定占位符,但不调用生图;layout 把文章和 manifest 确定性转换为微信安全的内联 HTML;full-pipeline…
staruhub/ClaudeSkills
A股分析研究助手,提供行情数据获取与技术面/基本面分析框架(仅供研究参考,不构成投资建议)。适用于:(1) 获取A股行情和历史数据,(2) 技术面分析(K线形态、MACD、KDJ、RSI、布林带等),(3) 基本面分析(财务指标、估值分析),(4) 板块热点追踪,(5) 选股策略筛选与量化因子分析,(6)…
staruhub/ClaudeSkills
Windows C盘清理和磁盘空间管理。当用户说C盘满了、磁盘空间不足、清理临时文件/缓存/回收站/系统日志、查找大文件、分析磁盘占用时使用。仅适用于 Windows 环境。不用于:macOS/Linux 磁盘清理、卸载软件(引导用户走系统卸载)、清理用户个人文件(只报告位置,删除决定权在用户)。
staruhub/ClaudeSkills
资深高考命题专家助手,提供专业的命题指导和评审服务。适用于创作高考试题、评审试题质量、分析试卷结构、了解命题趋势等场景。结合文档工具提取解压文件,使用网络搜索了解当年最新命题趋势,使用分析工具评估题目质量和试卷结构。涵盖"一核四层四翼"评价体系、题型规范、评分标准、命题流程等多个维度。不用于:大学/考研/中考命题(体系不同,仅可借鉴)、日常作业题编写、直接替考生解题。
Works with
Categories
全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -…. Security Audit is an agent skill from staruhub/ClaudeSkills.
Security Audit fits situations like: tasks that involve Web application vulnerabilities; tasks that involve Security review; tasks that involve Vulnerability scanning.
Run `npx skills add staruhub/ClaudeSkills --skill security-audit -a claude-code`. Or copy the skill folder (skills/Geek-skills-security-audit in staruhub/ClaudeSkills) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add staruhub/ClaudeSkills --skill security-audit -a codex`. Or copy the skill folder (skills/Geek-skills-security-audit in staruhub/ClaudeSkills) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add staruhub/ClaudeSkills --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.
Going by SKILL.md and its folder, Security Audit needs Python for the scripts in its folder and the command-line tools its instructions call (npm, pipx, pip, python3, semgrep and gitleaks). Our summary lists: Python 3; Node.js; Docker.
SKILL.md contains no URLs. Its commands use npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Security Audit: Cyber Neo (Hainrixz/cyber-neo, 281 stars), Security Analyzer (aiskillstore/marketplace, 430 stars), Code Audit (3stoneBrother/code-audit, 893 stars) and Secknowledge Skill (Pa55w0rd/secknowledge-skill, 423 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
staruhub (a GitHub user) maintains it in staruhub/ClaudeSkills, which has 727 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on August 13, 2026.
Source: staruhub/ClaudeSkills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.