Security Auditor
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
Dual-model code review via Codex CLI. An agent skill from suyuan2022/suyuan-skill.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add suyuan2022/suyuan-skill --skill codex-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install suyuan2022/suyuan-skill codex-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/suyuan2022/suyuan-skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/codex-review .claude/skills/codex-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "codex-review" agent skill from https://github.com/suyuan2022/suyuan-skill/tree/main/codex-review into .claude/skills/codex-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/suyuan2022/suyuan-skill/tree/main/codex-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add suyuan2022/suyuan-skill --skill codex-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install suyuan2022/suyuan-skill codex-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/suyuan2022/suyuan-skill.git skills-src && mkdir -p .agents/skills && cp -r skills-src/codex-review .agents/skills/codex-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "codex-review" agent skill from https://github.com/suyuan2022/suyuan-skill/tree/main/codex-review into .agents/skills/codex-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add suyuan2022/suyuan-skill --skill codex-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install suyuan2022/suyuan-skill codex-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/suyuan2022/suyuan-skill.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/codex-review .cursor/skills/codex-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "codex-review" agent skill from https://github.com/suyuan2022/suyuan-skill/tree/main/codex-review into .cursor/skills/codex-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/suyuan2022/suyuan-skill.git --path codex-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add suyuan2022/suyuan-skill --skill codex-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install suyuan2022/suyuan-skill codex-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/suyuan2022/suyuan-skill.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/codex-review .gemini/skills/codex-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "codex-review" agent skill from https://github.com/suyuan2022/suyuan-skill/tree/main/codex-review into .gemini/skills/codex-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install suyuan2022/suyuan-skill codex-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add suyuan2022/suyuan-skill --skill codex-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/suyuan2022/suyuan-skill.git skills-src && mkdir -p .github/skills && cp -r skills-src/codex-review .github/skills/codex-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "codex-review" agent skill from https://github.com/suyuan2022/suyuan-skill/tree/main/codex-review into .github/skills/codex-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add suyuan2022/suyuan-skill --skill codex-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install suyuan2022/suyuan-skill codex-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/suyuan2022/suyuan-skill.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/codex-review .opencode/skills/codex-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "codex-review" agent skill from https://github.com/suyuan2022/suyuan-skill/tree/main/codex-review into .opencode/skills/codex-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
codex-reviewDual-model code review via Codex CLI. An agent skill from suyuan2022/suyuan-skill.
Codex Review is an agent skill from suyuan2022/suyuan-skill. Dual-model code review via Codex CLI. Two GPT models review independently, Claude arbitrates disagreements. Supports review (read-only), fix (write), audit (full security scan), and autopilot (unattended) modes. Triggers on "review", "let Codex check", "security audit", "OWASP", "full scan". Also auto-triggers after complex coding tasks.
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/code-security.md`, `references/experience-log.md` and `references/general.md`).
It sits in Security, covering Security review and Web application vulnerabilities. It works with OpenAI. The repository describes itself as: Claude Code Skills by Suyuan — AI-native productivity tools for real practitioners. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 423473d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
codexnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Codex Review loads about 3.5k tokens when it runs, and up to ~8.3k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 1,293 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
e arbitrates and decides whether to fix without asking the user. Decision criteria:Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from suyuan2022/suyuan-skill at commit 423473d, republished under its MIT licence (© suyuan2022). 1,293 words, ~3,548 tokens.
.claude/skills/codex-review/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.npm install -g @openai/codex then codex login| Signal | Mode | Sandbox |
|---|---|---|
| review / check / look at | review | read-only |
| fix / modify / let Codex fix | fix | workspace-write |
| security audit / OWASP / full scan | audit | read-only |
| autopilot / unattended / long-running | autopilot | read-only |
| unclear | default to review | read-only |
autopilot mode: When the user is away and Claude is executing code tasks autonomously. After Codex review results come back, Claude arbitrates and decides whether to fix without asking the user. Decision criteria:
Autopilot is not the default — requires explicit user request ("autopilot", "unattended", "run without me").
After arbitration, Claude handles each finding by these rules:
Fix directly (don't ask the user):
Must ask the user (don't skip any):
In autopilot mode, "must ask" items are accumulated and batch-reported at the end without interrupting execution.
Each review dispatches two parallel codex exec calls via Bash, one per model:
# Model A (run in parallel with Model B)
codex exec -m "gpt-5.4" -s "read-only" -C "$REPO_DIR" \
--skip-git-repo-check --ephemeral \
-o /tmp/codex-review-a.md \
- <<'PROMPT'
[constructed prompt here]
PROMPT
# Model B (run in parallel with Model A)
codex exec -m "gpt-5.2" -s "read-only" -C "$REPO_DIR" \
--skip-git-repo-check --ephemeral \
-o /tmp/codex-review-b.md \
- <<'PROMPT'
[same prompt here]
PROMPTBoth calls use the same prompt but different models. Wait for both results before entering arbitration.
For fix mode, only one model executes the fix (default Model A), but the review phase still uses both models:
codex exec -m "gpt-5.4" -s "workspace-write" -C "$REPO_DIR" \
--skip-git-repo-check --full-auto \
-o /tmp/codex-fix.md \
- <<'PROMPT'
[fix prompt here]
PROMPTTo resume a session (for review-fix-review cycles):
codex exec resume SESSION_ID "follow-up prompt here"The session ID is printed in the codex exec output header (look for session id: xxx).
When both sets of findings arrive, Claude processes them in three zones:
Consensus zone — Both models flagged the same issue. Essentially confirmed; adopt directly. If fix suggestions differ, pick the one with harder evidence (file:line + code quote > vague description).
Single-source zone — Only one model flagged it. Claude reads the code to verify:
Conflict zone — Two models disagree (A says problem, B says fine). Claude reads the code and rules. If unresolvable (e.g., business logic judgment), escalate to user.
Output format: Tag each finding with its source — [A+B] consensus, [A] or [B] single-source, [Conflict→Claude] conflict. User sees at a glance which findings are iron-clad vs. single opinions.
-C must be set to the current working directory (Codex needs access to the same codebase).
Don't embed file contents in the prompt — Codex can read files itself. Only provide absolute paths in the prompt and let Codex read them. Save the token budget for review requirements, context, and focus areas.
Use --ephemeral for one-shot reviews (no session persistence needed). Omit it when you plan to do review-fix-review cycles.
Use --skip-git-repo-check when the target directory isn't a git repo.
Maximize initial review input — On the first call, give Codex the full review scope up front. Locating code is the most expensive phase of the first review; specific paths and ranges skip it entirely:
path:line-range) or precise diff range (<base>..<head> commit range / direct patch)⚠️ Hard constraint — the path list is a locator, not a scope cap: The prompt must tell Codex explicitly — the file list/line ranges are locators to help you find entry points quickly, NOT a scope lock restricting your review to only these paths. Codex's review must be as comprehensive as possible:
- Follow call chains; inspect files outside the list if they are affected
- Check cross-file side effects, error paths, edge cases — don't constrain yourself to the listed paths
- If you find issues outside the list, report them. Do NOT skip findings with "not in the given scope" reasoning
Include language like this in the prompt:
"The file list above is a locator to save you from scanning the repo from scratch. It is NOT a scope lock. Your review must be comprehensive — follow call chains, inspect files outside the list if they are affected, and report any issues you find there. Do not limit findings to the listed paths."
Before constructing the prompt, assess the scenario and read the corresponding reference file:
| Scenario | Reference |
|---|---|
| Security audit (full scan) | references/security-audit.md |
| Security-sensitive (auth/payment/data/crypto) | references/code-security.md |
| Non-code (docs/config/prompts) | references/non-code.md |
| Other | references/general.md |
| Before every prompt | Scan references/experience-log.md for known pitfalls |
All prompts sent to Codex use XML blocks, each with a fixed responsibility:
| XML Block | Purpose | Principle |
|---|---|---|
<task> | Define the task and review objective | One run = one task, no mixing |
<context> | Code/content/diff/project background | Facts only, no judgments; paths for Codex to read |
<instructions> | Review dimensions + per-finding output format | Require evidence: file:line + issue + reason + fix |
<grounding_rules> | Inference vs. confirmation boundary | Inferences must be labeled "Inference:"; never stated as confirmed |
<verification_loop> | Anti-rubber-stamp | Final check: each finding is material, supported, reproducible |
<dig_deeper_nudge> | Second-order check list | Guide Codex to check cross-file impact, edge cases, error paths |
<review_coverage> | Review scope declaration | Explicitly state what was and wasn't checked |
<verdict> | Final judgment | Pass / Conditional pass / Fail |
<default_follow_through_policy> | Behavior on missing context | Write "Cannot verify: [reason]" when uncertain; don't guess |
<action_safety> | Fix mode only | Restrict change scope, no unrelated refactoring |
Block selection by mode: review/audit must include grounding_rules + verification_loop + dig_deeper_nudge + review_coverage + verdict; fix mode adds action_safety, removes dig_deeper_nudge.
Anti-rubber-stamp: If either model returns "No issues found", check review_coverage scope adequacy. If scope is too narrow, do one more round. Both models say clean + adequate scope → pass.
Re-review prompt (resume session, or new session with diff):
Re-review's bottleneck isn't "finding the entry point" — it's verification. Codex has to confirm every fix actually landed and check for second-order problems. A natural-language summary ("fixed the AuthModal logic") forces Codex to locate code on its own, wasting its most expensive time.
You must provide a "Fix Evidence Index" structured at file:line granularity:
Fixed the previous round's findings. Fix evidence index below:
## Finding → Fix Mapping (finding → file:line → reason, all three required)
Every entry must include all three pieces: **what the finding is + where it landed (file:line) + why this fix**. A bare `file:line` without a reason forces Codex to reconstruct the "root cause → fix" logic chain on its own — defeating the purpose of the index.
- **[Finding-1 title]** → `<path>:<line-range>` [VERIFIED FIXED]
- Reason: <what was done + why this approach; one line connecting root cause → fix>
- **[Finding-2 title]** → `<path>:<line-range>` [VERIFIED FIXED]
- Reason: <...>
- **[Finding-3 title]** → [ACCEPTED — not fixing]
- Reason: <why not fixing: risk/cost/unnecessary, or decided in earlier round>
- **[Finding-4 title]** → `<path>:<lines>` [PARTIALLY FIXED]
- Reason: <what portion was fixed, why the rest is deferred, next-step plan>
(Reason is what Codex uses to judge whether the fix is on-target — not decoration. Without it, re-review either skips verification or spends time re-deriving the fix logic from code. Either way defeats the index.)
> **⚠️ Hard constraint — Reason is Claude's self-report, not Codex's conclusion**:
> The prompt must tell Codex explicitly — **the Reason field is Claude's own claim about the fix rationale (an unverified premise), NOT a fact you can cite as your conclusion**. Codex must:
> - Independently read the code at `<path>:<line-range>` and judge on its own whether the fix addresses the root cause
> - If agreeing with the Reason, produce **its own independent evidence from reading the code** (line number + code quote + reasoning for why this evidence supports the Reason). "Reason looks correct" or simply echoing Claude's wording is NOT acceptable.
> - If disagreeing, state exactly what's wrong and provide counter-evidence
> - ACCEPTED / PARTIALLY FIXED entries also require independent verification of whether the stated justification holds
>
> Include language like this in the prompt:
> > "The Reason field is Claude's self-reported fix rationale — treat it as an unverified claim, not a conclusion. For each VERIFIED FIXED entry, read the code at the stated path:line and produce your OWN independent evidence (line number + code quote + reasoning) for why the fix does or doesn't address the root cause. Echoing Claude's Reason without independent evidence is not acceptable."
## Files Changed This Round
- <path1>: <one-line summary of change>
- <path2>: <one-line summary of change>
(List only files actually touched this round. No vague summaries like "mainly updated marketing files".)
## Diff Range
Commit range: <base>..<head> or patch below
[Optional: inline diff]
## Verifications Already Run This Round
- `<command>`: <key result>
- `<command>`: <key result>
(e.g., `tsc --noEmit`: no errors; `rg "@gsap/react"`: 0 matches)
Please re-review based on this index:
1. For each [VERIFIED FIXED], confirm it actually landed (read the corresponding file:line)
2. Check for second-order issues (did changing A affect B?)
3. Evaluate whether ACCEPTED decisions are reasonable
4. Assess whether PARTIALLY FIXED remainders are criticalWhy this format: Real Codex feedback shows ~70-80% of re-review time is spent on "locating and cross-referencing code", only 20-30% on actual thinking. A structured index front-loads the verification paths into the prompt so Codex can jump straight to file:line without translating natural-language descriptions into search targets.
After each review, report both session IDs to the user:
Model A session: SESSION_ID_A
Model B session: SESSION_ID_BReview needed: New features (>=2 files or new functions), refactoring, complex bug fixes, user explicitly requests, high-risk scenarios.
Skip: Typos/naming/comments, single-line simple fixes, formatting adjustments, user asks for quick turnaround.
© suyuan2022, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (references) in codex-review of suyuan2022/suyuan-skill.
Open the folder on GitHubat commit 423473d
Codex Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Codex Review this skillsuyuan2022/suyuan-skill | 290 | — | ~3.5k | Automated safety check: Warn | MIT | |
| Security Auditoreigent-ai/eigent | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | |
| Security Reviewjewbetcha/opentrace | 116 | 18 repos | ~3.1k | Automated safety check: Notes | MIT | |
| Code Audit3stoneBrother/code-audit | 892 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Security Audit Scannerruvnet/ruflo | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | |
| Vibe Checkbenavlabs/vibe-check | 118 | — | ~1.1k | Automated safety check: Notes | MIT |
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
benavlabs/vibe-check
Security audit for web apps, especially AI-built ("vibe coded") ones.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
suyuan2022/suyuan-skill
Audit and safely modify local Claude Code and Claude Desktop cleanup/privacy settings on macOS.
suyuan2022/suyuan-skill
在 macOS 上安全审计、完整备份、清理或重置 Claude Code 与 Claude Desktop 本机状态。适用于清理可再生缓存和日志、轮换本地 ID、重置桌面端登录态、移除应用、继承现有遥测状态、启用最小提示词模式或修改台北时区;不用于规避封禁或平台风控。
suyuan2022/suyuan-skill
Task triage with position-based thinking. An agent skill from suyuan2022/suyuan-skill.
suyuan2022/suyuan-skill
Break AI Slop — force the AI to think like a real expert before doing anything.
suyuan2022/suyuan-skill
What Is This — explain anything as a picture-first HTML page.
Works with
Categories
Dual-model code review via Codex CLI. An agent skill from suyuan2022/suyuan-skill. Codex Review is an agent skill from suyuan2022/suyuan-skill. Dual-model code review via Codex CLI.
Codex Review fits situations like: let Codex check; after complex coding tasks.
Run `npx skills add suyuan2022/suyuan-skill --skill codex-review -a claude-code`. Or copy the skill folder (codex-review in suyuan2022/suyuan-skill) into .claude/skills/codex-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add suyuan2022/suyuan-skill --skill codex-review -a codex`. Or copy the skill folder (codex-review in suyuan2022/suyuan-skill) into .agents/skills/codex-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add suyuan2022/suyuan-skill --skill codex-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codex-review, .gemini/skills/codex-review, .github/skills/codex-review and .opencode/skills/codex-review in your project.
Going by SKILL.md and its folder, Codex Review needs the command-line tools its instructions call (codex and npm). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): tells the agent its actions are pre-authorized / not to stop for confirmation. Read the flagged lines before installing; the check is not a guarantee either way.
Codex Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Codex Review: Security Auditor (eigent-ai/eigent, 15k stars), Security Review (jewbetcha/opentrace, 116 stars), Code Audit (3stoneBrother/code-audit, 892 stars) and Security Audit Scanner (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
suyuan2022 (a GitHub user) maintains it in suyuan2022/suyuan-skill, which has 290 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on August 24, 2026.
Source: suyuan2022/suyuan-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.