Agent skill

Security Audit

by ThibautBaissac in ThibautBaissac/rails_ai_agents

Audits Rails application security against OWASP Top 10, detects vulnerabilities with Brakeman, and verifies Pundit authorization policies.

MITAuto-check: notesSecurity

Install Security Audit

skills CLI
$ npx skills add ThibautBaissac/rails_ai_agents --skill security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ThibautBaissac/rails_ai_agents security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ThibautBaissac/rails_ai_agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-audit .claude/skills/security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-audit
GitHub stars
665
Token cost
~846 tokens
SKILL.md length
164 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Audits Rails application security against OWASP Top 10, detects vulnerabilities with Brakeman, and verifies Pundit authorization policies.

  • Works in 12 steps: Run Security Tools → Manual Code Review → Report Findings → …
  • The user wants a security audit
  • SKILL.md covers Audit Process, OWASP Top 10 — Rails Patterns and Security Checklist
  • Calls bundle

What it does

Security Audit is an agent skill from ThibautBaissac/rails_ai_agents. Audits Rails application security against OWASP Top 10, detects vulnerabilities with Brakeman, and verifies Pundit authorization policies. Use when the user wants a security audit, vulnerability scan, or when user mentions security, OWASP, Brakeman, XSS, SQL injection, or authorization. WHEN NOT: Implementing security fixes (use specialist agents), setting up authentication (use authentication-flow), or writing Pundit policies (use policy-agent).

Its SKILL.md is about 850 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities, Security review and Backend development. The repository describes itself as: Specialized AI skills, agents, rules and hooks for modern Rails AI driven-development + Spec-Driven-Development kit + MCP. The licence is MIT.

When your agent uses it

  • The user wants a security audit
  • Vulnerability scan
  • User mentions security

Example prompts

  • “Use the security-audit skill to audit Rails application security against OWASP Top 10, detects vulnerabilities with Brakeman, and verifies Pundit…”
  • “/security-audit”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Run Security Tools
  2. Manual Code Review
  3. Report Findings
  4. Injection (SQL, Command)
  5. Broken Authentication
  6. Sensitive Data Exposure
  7. XXE
  8. Broken Access Control
  9. Security Misconfiguration
  10. XSS
  11. Insecure Deserialization
  12. Vulnerable Dependencies

What it can do on your machine

Read from SKILL.md and the folder at commit 03622f2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bundle

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Audit loads about 846 tokens when it runs. Until then it costs about 116 tokens; SKILL.md has 164 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~846

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ThibautBaissac/rails_ai_agents at commit 03622f2, republished under its MIT licence (© ThibautBaissac). 164 words, ~846 tokens.

Download SKILL.mdSave it as .claude/skills/security-audit/SKILL.md (or your agent's skills folder).
name
security-audit
description
Audits Rails application security against OWASP Top 10, detects vulnerabilities with Brakeman, and verifies Pundit authorization policies. Use when the user wants a security audit, vulnerability scan, or when user mentions security, OWASP, Brakeman, XSS, SQL injection, or authorization. WHEN NOT: Implementing security fixes (use specialist agents), setting up authentication (use authentication-flow), or writing Pundit policies (use policy-agent).
allowed-tools
Read, Grep, Glob, Bash
context
fork
agent
Explore
model
opus
effort
high
user-invocable
true
argument-hint
[file or directory path]

Security Audit

You are an expert in Rails application security, OWASP Top 10, and common web vulnerabilities. You NEVER modify credentials, secrets, or production files.

Audit Process

Step 1: Run Security Tools
bash
bin/brakeman
bin/bundler-audit check --update
bundle exec rspec spec/policies/
Step 2: Manual Code Review

Audit all files in app/controllers/, app/models/, app/services/, app/queries/, app/forms/, app/views/, app/policies/, config/.

Step 3: Report Findings

Format: Vulnerability → Location (file:line) → Risk → Fix (code example) Prioritize: P0 (critical) → P1 (high) → P2 (medium) → P3 (low)

OWASP Top 10 — Rails Patterns

1. Injection (SQL, Command)
ruby
# Bad — SQL Injection
User.where("email = '#{params[:email]}'")

# Good — Bound parameters
User.where(email: params[:email])
2. Broken Authentication
ruby
# Bad — Predictable token
user.update(reset_token: SecureRandom.hex(4))

# Good — Sufficiently long token
user.update(reset_token: SecureRandom.urlsafe_base64(32))
3. Sensitive Data Exposure
ruby
# Bad — Logging sensitive data
Rails.logger.info("Password: #{password}")

# Good — Filter sensitive params
Rails.application.config.filter_parameters += [:password, :token, :secret]
4. XXE
ruby
# Bad
Nokogiri::XML(user_input)

# Good
Nokogiri::XML(user_input) { |config| config.nonet.noent }
5. Broken Access Control
ruby
# Bad — No authorization
@entity = Entity.find(params[:id])

# Good — Pundit
@entity = Entity.find(params[:id])
authorize @entity
6. Security Misconfiguration
ruby
# production.rb
config.force_ssl = true
7. XSS
erb
<%# Bad %>
<%= raw user_input %>
<%= user_input.html_safe %>

<%# Good %>
<%= user_input %>
<%= sanitize(user_input) %>
8. Insecure Deserialization
ruby
# Bad
YAML.load(user_input)

# Good
YAML.safe_load(user_input, permitted_classes: [Symbol, Date])
9. Vulnerable Dependencies
bash
bin/bundler-audit check --update
10. Insufficient Logging
ruby
Rails.logger.warn("Failed login for #{email} from #{request.remote_ip}")

Security Checklist

Configuration
  • config.force_ssl = true in production
  • CSRF protection enabled
  • Content Security Policy configured
  • Sensitive parameters filtered from logs
  • Secure sessions (httponly, secure, same_site)
Code
  • Strong Parameters on all controllers
  • Pundit authorize on all actions
  • No html_safe/raw on user input
  • Parameterized SQL queries only
  • File upload validation
Dependencies
  • Bundler Audit clean
  • Gems up to date
  • No abandoned gems

© ThibautBaissac, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/security-audit of ThibautBaissac/rails_ai_agents.

Open the folder on GitHubat commit 03622f2

Compare with similar skills

Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Audit this skillThibautBaissac/rails_ai_agents665—~846Automated safety check: NotesMIT
Psalm Security Analysiscachethq/core230—~4.7kAutomated safety check: PassCustom licence
Laravel Security Auditaiskillstore/marketplace4304 repos~1.1kAutomated safety check: NotesNone
Django Access Reviewgetsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.0
Experience Lwc Security Validateforcedotcom/sf-skills1.1k—~2.6kAutomated safety check: PassApache-2.0
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0

Similar skills

  • Runs and interprets Psalm security (taint) analysis on a Laravel project.

    230 GitHub stars~4.7k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Laravel Security Audit

    aiskillstore/marketplace

    Security auditor for Laravel applications. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 4 repos~1.1k tokens
    SecurityAuto-check: notes
  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Backend & APIsAuto-check: notes
  • Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (.js, .ts, .html, .css, .js-meta.xml) — the canonical LWS/Product-Security review for…

    1.1k GitHub stars~2.6k tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes

More from ThibautBaissac/rails_ai_agents

All 19 skills in this repo
  • Accessibility Review

    ThibautBaissac/rails_ai_agents

    Audits Rails application accessibility against WCAG 2.2 Level AA, detects violations with axe-core / Lighthouse / Pa11y, and reports remediation guidance for ERB views, ViewComponents, Stimulus…

    665 GitHub stars~2.9k tokensUpdated 4 mo ago
    Auto-check: notes
  • Action Cable Patterns

    ThibautBaissac/rails_ai_agents

    Implements real-time features with Action Cable and WebSockets.

    665 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Active Storage Setup

    ThibautBaissac/rails_ai_agents

    Configures Active Storage for file uploads with variants and direct uploads.

    665 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Authentication Flow

    ThibautBaissac/rails_ai_agents

    Implements authentication using Rails 8 built-in generator. An agent skill from ThibautBaissac/rails_ai_agents.

    665 GitHub stars~1.9k tokensUpdated 4 mo ago
    Auto-check passed
  • Caching Strategies

    ThibautBaissac/rails_ai_agents

    Implements Rails caching patterns for performance optimization.

    665 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed
  • I18n Patterns

    ThibautBaissac/rails_ai_agents

    Implements internationalization with Rails I18n for multi-language support.

    665 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Security Audit

What does Security Audit do?

Audits Rails application security against OWASP Top 10, detects vulnerabilities with Brakeman, and verifies Pundit authorization policies. Security Audit is an agent skill from ThibautBaissac/rails_ai_agents. Audits Rails application security against OWASP Top 10, detects vulnerabilities with Brakeman, and verifies Pundit authorization policies.

When should I use Security Audit?

Security Audit fits situations like: the user wants a security audit; vulnerability scan; user mentions security.

How do I install Security Audit in Claude Code?

Run `npx skills add ThibautBaissac/rails_ai_agents --skill security-audit -a claude-code`. Or copy the skill folder (.agents/skills/security-audit in ThibautBaissac/rails_ai_agents) into .claude/skills/security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Security Audit in Codex?

Run `npx skills add ThibautBaissac/rails_ai_agents --skill security-audit -a codex`. Or copy the skill folder (.agents/skills/security-audit in ThibautBaissac/rails_ai_agents) into .agents/skills/security-audit in your project. Codex loads it when a task matches its description.

Can I use Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ThibautBaissac/rails_ai_agents --skill security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit, .gemini/skills/security-audit, .github/skills/security-audit and .opencode/skills/security-audit in your project.

What does Security Audit need to run?

Going by SKILL.md and its folder, Security Audit needs the command-line tools its instructions call (bundle). Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash.

Does Security Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Audit safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Security Audit use?

Security Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Audit use?

About 846 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Audit?

Skills that share tags, products or a category with Security Audit: Psalm Security Analysis (cachethq/core, 230 stars), Laravel Security Audit (aiskillstore/marketplace, 430 stars), Django Access Review (getsentry/skills, 1k stars) and Experience Lwc Security Validate (forcedotcom/sf-skills, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Audit?

ThibautBaissac (a GitHub user) maintains it in ThibautBaissac/rails_ai_agents, which has 665 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on June 1, 2026.

Source: ThibautBaissac/rails_ai_agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.