Pre-Commit Security Scan
zereight/gitlab-mcp
Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
$ npx skills add TheDecipherist/claude-code-mastery --skill security-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install TheDecipherist/claude-code-mastery security-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-audit .claude/skills/security-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-audit" agent skill from https://github.com/TheDecipherist/claude-code-mastery/tree/main/skills/security-audit into .claude/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/TheDecipherist/claude-code-mastery/tree/main/skills/security-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add TheDecipherist/claude-code-mastery --skill security-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install TheDecipherist/claude-code-mastery security-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security-audit .agents/skills/security-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-audit" agent skill from https://github.com/TheDecipherist/claude-code-mastery/tree/main/skills/security-audit into .agents/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add TheDecipherist/claude-code-mastery --skill security-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install TheDecipherist/claude-code-mastery security-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security-audit .cursor/skills/security-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-audit" agent skill from https://github.com/TheDecipherist/claude-code-mastery/tree/main/skills/security-audit into .cursor/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/TheDecipherist/claude-code-mastery.git --path skills/security-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add TheDecipherist/claude-code-mastery --skill security-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install TheDecipherist/claude-code-mastery security-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security-audit .gemini/skills/security-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/TheDecipherist/claude-code-mastery/tree/main/skills/security-audit into .gemini/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install TheDecipherist/claude-code-mastery security-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add TheDecipherist/claude-code-mastery --skill security-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security-audit .github/skills/security-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/TheDecipherist/claude-code-mastery/tree/main/skills/security-audit into .github/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add TheDecipherist/claude-code-mastery --skill security-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install TheDecipherist/claude-code-mastery security-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security-audit .opencode/skills/security-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-audit" agent skill from https://github.com/TheDecipherist/claude-code-mastery/tree/main/skills/security-audit into .opencode/skills/security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-auditChecks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
A checklist the agent works through when you mention security, audits, vulnerabilities or CVEs, before deployment commands and during pull request reviews. The first area is secrets exposure: grep patterns for keys and tokens, a check that `.env` and key files are in `.gitignore`, and a search of git history. The second is dependencies, with `npm audit` or `yarn audit` for Node.js, `pip-audit` or `safety check` for Python, `govulncheck` for Go and `cargo audit` for Rust.
Pass criteria are explicit, for example no critical vulnerabilities, no high ones older than 30 days and dependencies updated within 90 days. Later sections cover input validation (parameterized SQL, sandboxed file paths, escaped HTML, command injection), authentication and authorization (bcrypt or argon2 hashing, random session tokens, CSRF protection, rate limiting, lockout) and transport security (HSTS, Secure, HttpOnly and SameSite cookie flags, TLS 1.2 or newer).
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0f05fa1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitnpmyarnpnpmcargoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, npm, yarn and pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
API_KEYSTRIPE_KEYSTRIPE_SECRET_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Audit loads about 1.3k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 352 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- `.env` files in `.gitignore`Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from TheDecipherist/claude-code-mastery at commit 0f05fa1, republished under its MIT licence (© TheDecipherist). 352 words, ~1,288 tokens.
.claude/skills/security-audit/SKILL.md (or your agent's skills folder).Perform comprehensive security audits on codebases to identify vulnerabilities before they reach production.
Check for hardcoded secrets:
# Search for common secret patterns
grep -rn "API_KEY\|SECRET\|TOKEN\|PASSWORD" --include="*.{js,ts,py,go,rb,java}" .
grep -rn "sk-\|pk_\|api_\|secret_" --include="*.{js,ts,py,go,rb,java}" .Verify .gitignore:
# Ensure sensitive files are ignored
cat .gitignore | grep -E "\.env|secret|credential|\.pem|\.key"Check git history for leaked secrets:
# Search recent commits (requires git-secrets or truffleHog)
git log -p --all -S "API_KEY" --since="30 days ago"✅ Pass criteria:
.env files in .gitignoreNode.js:
npm audit
# or
yarn audit
# or
pnpm auditPython:
pip-audit
# or
safety checkGo:
govulncheck ./...Rust:
cargo audit✅ Pass criteria:
Check for:
Common vulnerable patterns:
// BAD: SQL injection
db.query(`SELECT * FROM users WHERE id = ${userId}`)
// GOOD: Parameterized query
db.query('SELECT * FROM users WHERE id = ?', [userId])# BAD: Command injection
os.system(f"convert {user_file}")
# GOOD: Use subprocess with list
subprocess.run(["convert", user_file], check=True)Check for:
Look for:
// BAD: Weak hashing
crypto.createHash('md5').update(password)
// GOOD: Bcrypt
bcrypt.hash(password, 12)Check for:
Secure, HttpOnly, SameSite)Check for:
// BAD: Exposes internals
res.status(500).send({ error: err.stack })
// GOOD: Generic message
res.status(500).send({ error: 'An unexpected error occurred' })If file uploads exist:
| Level | Description | Action Required |
|---|---|---|
| 🔴 Critical | Actively exploitable | Block deployment |
| 🟠 High | Exploitable with effort | Fix within 7 days |
| 🟡 Medium | Requires conditions | Fix within 30 days |
| 🟢 Low | Minimal impact | Fix when convenient |
## Security Audit Results
**Project:** [name]
**Date:** [date]
**Auditor:** Claude (automated)
### Summary
| Severity | Count |
|----------|-------|
| 🔴 Critical | 0 |
| 🟠 High | 1 |
| 🟡 Medium | 2 |
| 🟢 Low | 3 |
### Findings
#### 1. [🟠 High] Hardcoded API Key
**Location:** `src/config.js:15`
**Description:** API key for payment provider is hardcoded
**Risk:** If source code is leaked, attackers gain API access
**Recommendation:** Move to environment variable
```diff
- const STRIPE_KEY = 'sk_live_abc123...'
+ const STRIPE_KEY = process.env.STRIPE_SECRET_KEYLocation: src/routes/auth.js
Description: Login endpoint has no rate limiting
Risk: Enables brute force attacks
Recommendation: Add rate limiting middleware
## Commands to Run
After completing the audit, provide the user with:
1. Summary of findings
2. Prioritized fix list
3. Commands to address each issue
4. Timeline recommendation© TheDecipherist, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/security-audit of TheDecipherist/claude-code-mastery.
Open the folder on GitHubat commit 0f05fa1
Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Audit this skillTheDecipherist/claude-code-mastery | 550 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Pre-Commit Security Scanzereight/gitlab-mcp | 2k | 1 repos | ~859 | Automated safety check: Notes | MIT | |
| CodeQL Security Scantrailofbits/skills | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Pyspector Security AuditParzivalHack/PySpector | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | |
| Security Reviewgithub/awesome-copilot | 40k | 1 repos | ~2.3k | Automated safety check: Notes | MIT | |
| Time Aware Dependency Cve ScannerArabelaTso/Skills-4-SE | 253 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 |
zereight/gitlab-mcp
Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
ParzivalHack/PySpector
Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.
github/awesome-copilot
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…
ArabelaTso/Skills-4-SE
Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date.
jwynia/agent-skills
Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.
TheDecipherist/claude-code-mastery
Writes clear, Conventional-Commits-formatted commit messages by analyzing staged changes, their type and scope.
Categories
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge. A checklist the agent works through when you mention security, audits, vulnerabilities or CVEs, before deployment commands and during pull request reviews.gitignore`, and a search of git history.
Security Audit fits situations like: reviewing a pull request for security problems before it merges; checking project dependencies for known vulnerabilities; running a security pass before a deployment; looking for leaked keys or passwords in code and git history.
Run `npx skills add TheDecipherist/claude-code-mastery --skill security-audit -a claude-code`. Or copy the skill folder (skills/security-audit in TheDecipherist/claude-code-mastery) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add TheDecipherist/claude-code-mastery --skill security-audit -a codex`. Or copy the skill folder (skills/security-audit in TheDecipherist/claude-code-mastery) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TheDecipherist/claude-code-mastery --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.
Going by SKILL.md and its folder, Security Audit needs the command-line tools its instructions call (git, npm, yarn, pnpm and cargo) and credentials named API_KEY, STRIPE_KEY and STRIPE_SECRET_KEY. Our summary lists: Audit tools for your stack, such as `npm audit`, `pip-audit`, `govulncheck` or `cargo audit`.
SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Audit: Pre-Commit Security Scan (zereight/gitlab-mcp, 2k stars), CodeQL Security Scan (trailofbits/skills, 7.4k stars), Pyspector Security Audit (ParzivalHack/PySpector, 151 stars) and Security Review (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
TheDecipherist (a GitHub user) maintains it in TheDecipherist/claude-code-mastery, which has 550 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on May 7, 2026.
Source: TheDecipherist/claude-code-mastery on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.