Agent skill

Security Audit

by TheDecipherist in TheDecipherist/claude-code-mastery

Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

MITAuto-check: notesSecurity

Install Security Audit

skills CLI
$ npx skills add TheDecipherist/claude-code-mastery --skill security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install TheDecipherist/claude-code-mastery security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-audit .claude/skills/security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-audit
GitHub stars
550
Token cost
~1.3k tokens
SKILL.md length
352 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

  • Works in 8 steps: Secrets Exposure → Dependency Vulnerabilities → Input Validation → …
  • Reviewing a pull request for security problems before it merges
  • SKILL.md covers When to Use This Skill, Audit Checklist, Severity Levels and Output Format
  • Calls git, npm and yarn; needs API_KEY and STRIPE_KEY

What it does

A checklist the agent works through when you mention security, audits, vulnerabilities or CVEs, before deployment commands and during pull request reviews. The first area is secrets exposure: grep patterns for keys and tokens, a check that `.env` and key files are in `.gitignore`, and a search of git history. The second is dependencies, with `npm audit` or `yarn audit` for Node.js, `pip-audit` or `safety check` for Python, `govulncheck` for Go and `cargo audit` for Rust.

Pass criteria are explicit, for example no critical vulnerabilities, no high ones older than 30 days and dependencies updated within 90 days. Later sections cover input validation (parameterized SQL, sandboxed file paths, escaped HTML, command injection), authentication and authorization (bcrypt or argon2 hashing, random session tokens, CSRF protection, rate limiting, lockout) and transport security (HSTS, Secure, HttpOnly and SameSite cookie flags, TLS 1.2 or newer).

When your agent uses it

  • Reviewing a pull request for security problems before it merges
  • Checking project dependencies for known vulnerabilities
  • Running a security pass before a deployment
  • Looking for leaked keys or passwords in code and git history

Example prompts

  • “Run a security audit on this repo before I deploy on Friday.”
  • “Check whether any API keys or passwords are hardcoded or sitting in git history.”
  • “Audit our dependencies and tell me which vulnerabilities are critical.”

Requirements

  • Audit tools for your stack, such as `npm audit`, `pip-audit`, `govulncheck` or `cargo audit`

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Secrets Exposure
  2. Dependency Vulnerabilities
  3. Input Validation
  4. Authentication & Authorization
  5. HTTPS & Transport Security
  6. Error Handling
  7. File Upload Security
  8. API Security

What it can do on your machine

Read from SKILL.md and the folder at commit 0f05fa1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • npm
    • yarn
    • pnpm
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, npm, yarn and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY
    • STRIPE_KEY
    • STRIPE_SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Audit loads about 1.3k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 352 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:43
    - `.env` files in `.gitignore`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from TheDecipherist/claude-code-mastery at commit 0f05fa1, republished under its MIT licence (© TheDecipherist). 352 words, ~1,288 tokens.

Download SKILL.mdSave it as .claude/skills/security-audit/SKILL.md (or your agent's skills folder).
name
security-audit
description
Audit code and dependencies for security vulnerabilities. Use when reviewing PRs, checking dependencies, preparing for deployment, or when user mentions security, vulnerabilities, or audit.

Security Audit Skill

Perform comprehensive security audits on codebases to identify vulnerabilities before they reach production.

When to Use This Skill

  • User mentions "security", "audit", "vulnerability", "CVE"
  • Before deployment commands
  • During PR reviews
  • User asks about dependencies
  • Periodic security checks

Audit Checklist

1. Secrets Exposure

Check for hardcoded secrets:

bash
# Search for common secret patterns
grep -rn "API_KEY\|SECRET\|TOKEN\|PASSWORD" --include="*.{js,ts,py,go,rb,java}" .
grep -rn "sk-\|pk_\|api_\|secret_" --include="*.{js,ts,py,go,rb,java}" .

Verify .gitignore:

bash
# Ensure sensitive files are ignored
cat .gitignore | grep -E "\.env|secret|credential|\.pem|\.key"

Check git history for leaked secrets:

bash
# Search recent commits (requires git-secrets or truffleHog)
git log -p --all -S "API_KEY" --since="30 days ago"

✅ Pass criteria:

  • No hardcoded API keys, tokens, or passwords
  • .env files in .gitignore
  • No secrets in git history
2. Dependency Vulnerabilities

Node.js:

bash
npm audit
# or
yarn audit
# or  
pnpm audit

Python:

bash
pip-audit
# or
safety check

Go:

bash
govulncheck ./...

Rust:

bash
cargo audit

✅ Pass criteria:

  • No critical vulnerabilities
  • No high vulnerabilities > 30 days old
  • Dependencies updated within last 90 days
3. Input Validation

Check for:

  • User inputs sanitized before use
  • SQL queries use parameterized statements
  • File paths validated and sandboxed
  • HTML content escaped before rendering
  • Command injection prevention

Common vulnerable patterns:

javascript
// BAD: SQL injection
db.query(`SELECT * FROM users WHERE id = ${userId}`)

// GOOD: Parameterized query
db.query('SELECT * FROM users WHERE id = ?', [userId])
python
# BAD: Command injection
os.system(f"convert {user_file}")

# GOOD: Use subprocess with list
subprocess.run(["convert", user_file], check=True)
4. Authentication & Authorization

Check for:

  • Passwords hashed with bcrypt/argon2 (not MD5/SHA1)
  • Session tokens are cryptographically random
  • Sessions expire appropriately
  • CSRF protection on state-changing endpoints
  • Rate limiting on auth endpoints
  • Account lockout after failed attempts

Look for:

javascript
// BAD: Weak hashing
crypto.createHash('md5').update(password)

// GOOD: Bcrypt
bcrypt.hash(password, 12)
5. HTTPS & Transport Security

Check for:

  • HTTPS enforced (HSTS header)
  • Secure cookie flags (Secure, HttpOnly, SameSite)
  • No mixed content warnings
  • TLS 1.2+ required
6. Error Handling

Check for:

  • Stack traces not exposed in production
  • Generic error messages for users
  • Detailed errors only in logs
  • Sensitive data not in error messages
javascript
// BAD: Exposes internals
res.status(500).send({ error: err.stack })

// GOOD: Generic message
res.status(500).send({ error: 'An unexpected error occurred' })
Show full SKILL.md (136 more words)Show less
7. File Upload Security

If file uploads exist:

  • Validate file type server-side (not just extension)
  • Limit file size
  • Scan for malware
  • Store outside webroot
  • Rename uploaded files
8. API Security
  • Authentication required on all sensitive endpoints
  • Authorization checks per resource
  • Rate limiting implemented
  • CORS configured restrictively
  • API versioning in place

Severity Levels

LevelDescriptionAction Required
🔴 CriticalActively exploitableBlock deployment
🟠 HighExploitable with effortFix within 7 days
🟡 MediumRequires conditionsFix within 30 days
🟢 LowMinimal impactFix when convenient

Output Format

markdown
## Security Audit Results

**Project:** [name]
**Date:** [date]
**Auditor:** Claude (automated)

### Summary

| Severity | Count |
|----------|-------|
| 🔴 Critical | 0 |
| 🟠 High | 1 |
| 🟡 Medium | 2 |
| 🟢 Low | 3 |

### Findings

#### 1. [🟠 High] Hardcoded API Key

**Location:** `src/config.js:15`
**Description:** API key for payment provider is hardcoded
**Risk:** If source code is leaked, attackers gain API access
**Recommendation:** Move to environment variable

```diff
- const STRIPE_KEY = 'sk_live_abc123...'
+ const STRIPE_KEY = process.env.STRIPE_SECRET_KEY
2. [🟡 Medium] Missing Rate Limiting

Location: src/routes/auth.js Description: Login endpoint has no rate limiting Risk: Enables brute force attacks Recommendation: Add rate limiting middleware

Recommendations
  1. Fix critical and high issues before next deployment
  2. Schedule medium issues for next sprint
  3. Add low issues to backlog
  4. Re-run audit after fixes

## Commands to Run

After completing the audit, provide the user with:

1. Summary of findings
2. Prioritized fix list
3. Commands to address each issue
4. Timeline recommendation

© TheDecipherist, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security-audit of TheDecipherist/claude-code-mastery.

Open the folder on GitHubat commit 0f05fa1

Compare with similar skills

Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Audit this skillTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Pre-Commit Security Scanzereight/gitlab-mcp2k1 repos~859Automated safety check: NotesMIT
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Time Aware Dependency Cve ScannerArabelaTso/Skills-4-SE253—~2.1kAutomated safety check: PassApache-2.0

Similar skills

  • Pre-Commit Security Scan

    zereight/gitlab-mcp

    Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

    2k GitHub starsUsed in 1 repo~859 tokens
    SecurityAuto-check: notes
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated 9 days ago
    SecurityAuto-check: notes
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Time Aware Dependency Cve Scanner

    ArabelaTso/Skills-4-SE

    Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date.

    253 GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Dependency Scan

    jwynia/agent-skills

    Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.

    165 GitHub stars~1.7k tokensUpdated 7 mo ago
    SecurityAuto-check passed

More from TheDecipherist/claude-code-mastery

  • Conventional Commit Message Writer

    TheDecipherist/claude-code-mastery

    Writes clear, Conventional-Commits-formatted commit messages by analyzing staged changes, their type and scope.

    550 GitHub stars~878 tokensUpdated 5 mo ago
    Auto-check passed

Works with

Questions about Security Audit

What does Security Audit do?

Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge. A checklist the agent works through when you mention security, audits, vulnerabilities or CVEs, before deployment commands and during pull request reviews.gitignore`, and a search of git history.

When should I use Security Audit?

Security Audit fits situations like: reviewing a pull request for security problems before it merges; checking project dependencies for known vulnerabilities; running a security pass before a deployment; looking for leaked keys or passwords in code and git history.

How do I install Security Audit in Claude Code?

Run `npx skills add TheDecipherist/claude-code-mastery --skill security-audit -a claude-code`. Or copy the skill folder (skills/security-audit in TheDecipherist/claude-code-mastery) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Security Audit in Codex?

Run `npx skills add TheDecipherist/claude-code-mastery --skill security-audit -a codex`. Or copy the skill folder (skills/security-audit in TheDecipherist/claude-code-mastery) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.

Can I use Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TheDecipherist/claude-code-mastery --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.

What does Security Audit need to run?

Going by SKILL.md and its folder, Security Audit needs the command-line tools its instructions call (git, npm, yarn, pnpm and cargo) and credentials named API_KEY, STRIPE_KEY and STRIPE_SECRET_KEY. Our summary lists: Audit tools for your stack, such as `npm audit`, `pip-audit`, `govulncheck` or `cargo audit`.

Does Security Audit access the network?

SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Audit use?

Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Audit use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Audit?

Skills that share tags, products or a category with Security Audit: Pre-Commit Security Scan (zereight/gitlab-mcp, 2k stars), CodeQL Security Scan (trailofbits/skills, 7.4k stars), Pyspector Security Audit (ParzivalHack/PySpector, 151 stars) and Security Review (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Audit?

TheDecipherist (a GitHub user) maintains it in TheDecipherist/claude-code-mastery, which has 550 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on May 7, 2026.

Source: TheDecipherist/claude-code-mastery on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.