Security Audit Scanner
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
STRIDE + OWASP-based security audit with optional auto-fix. An agent skill from withkynam/vibecode-pro-max-kit.
$ npx skills add withkynam/vibecode-pro-max-kit --skill vc-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install withkynam/vibecode-pro-max-kit vc-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/withkynam/vibecode-pro-max-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/vc-security .claude/skills/vc-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vc-security" agent skill from https://github.com/withkynam/vibecode-pro-max-kit/tree/main/.claude/skills/vc-security into .claude/skills/vc-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vc-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/withkynam/vibecode-pro-max-kit/tree/main/.claude/skills/vc-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add withkynam/vibecode-pro-max-kit --skill vc-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install withkynam/vibecode-pro-max-kit vc-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/withkynam/vibecode-pro-max-kit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/vc-security .agents/skills/vc-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vc-security" agent skill from https://github.com/withkynam/vibecode-pro-max-kit/tree/main/.claude/skills/vc-security into .agents/skills/vc-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vc-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add withkynam/vibecode-pro-max-kit --skill vc-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install withkynam/vibecode-pro-max-kit vc-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/withkynam/vibecode-pro-max-kit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/vc-security .cursor/skills/vc-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vc-security" agent skill from https://github.com/withkynam/vibecode-pro-max-kit/tree/main/.claude/skills/vc-security into .cursor/skills/vc-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vc-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/withkynam/vibecode-pro-max-kit.git --path .claude/skills/vc-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add withkynam/vibecode-pro-max-kit --skill vc-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install withkynam/vibecode-pro-max-kit vc-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/withkynam/vibecode-pro-max-kit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/vc-security .gemini/skills/vc-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vc-security" agent skill from https://github.com/withkynam/vibecode-pro-max-kit/tree/main/.claude/skills/vc-security into .gemini/skills/vc-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vc-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install withkynam/vibecode-pro-max-kit vc-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add withkynam/vibecode-pro-max-kit --skill vc-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/withkynam/vibecode-pro-max-kit.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/vc-security .github/skills/vc-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vc-security" agent skill from https://github.com/withkynam/vibecode-pro-max-kit/tree/main/.claude/skills/vc-security into .github/skills/vc-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vc-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add withkynam/vibecode-pro-max-kit --skill vc-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install withkynam/vibecode-pro-max-kit vc-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/withkynam/vibecode-pro-max-kit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/vc-security .opencode/skills/vc-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vc-security" agent skill from https://github.com/withkynam/vibecode-pro-max-kit/tree/main/.claude/skills/vc-security into .opencode/skills/vc-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vc-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vc-securitySTRIDE + OWASP-based security audit with optional auto-fix. An agent skill from withkynam/vibecode-pro-max-kit.
Vc Security is an agent skill from withkynam/vibecode-pro-max-kit. STRIDE + OWASP-based security audit with optional auto-fix. Scans code for vulnerabilities, categorizes by severity, and can iteratively fix findings using vc-autoresearch pattern.
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/secret-patterns.md`, `references/stride-owasp-checklist.md` and `references/vulnerability-patterns.md`).
It sits in Security, covering Web application vulnerabilities, Threat modeling and Security review. The repository describes itself as: Your AI forgets. This remembers. Spec-driven coding harness for vibecoders, product owners, CEOs and real builders — self-improving context memory, 15 agents, 33 skills working…. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 3bcb2f9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmbundleFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vc Security loads about 1.2k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 48 tokens; SKILL.md has 445 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from withkynam/vibecode-pro-max-kit at commit 3bcb2f9, republished under its MIT licence (© withkynam). 445 words, ~1,241 tokens.
.claude/skills/vc-security/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Output style: Follow
process/development-protocols/communication-standards.md— answer-first, plain language, no unexplained jargon, TL;DR on long responses.
Runs a structured STRIDE + OWASP security audit on a given scope. Produces a severity-ranked findings report. With --fix, applies fixes iteratively using the vc-autoresearch guard pattern.
| Mode | Invocation | Behavior |
|---|---|---|
| Audit only | /vc-security <scope> | Scan → categorize → report |
| Audit + Fix | /vc-security <scope> --fix | Scan → categorize → fix iteratively |
| Bounded fix | /vc-security <scope> --fix --iterations N | Limit fix iterations to N |
Expand the provided glob or full keyword into a file list. Read all in-scope files before analysis.
Evaluate each threat category systematically:
Map findings to OWASP categories (A01–A10). See references/stride-owasp-checklist.md for per-category checks.
Run the appropriate package audit tool for the detected stack:
pnpm auditpip-auditgovulncheckbundle auditScan for hardcoded API keys, passwords, tokens, and private keys using regex patterns. See references/stride-owasp-checklist.md → Secret Patterns.
Assign each finding a severity level (see Severity Definitions below).
## Security Audit Report
### Summary
- Files scanned: N
- Findings: X critical, Y high, Z medium, W low, V info
### Findings
| # | Severity | Category | File:Line | Description | Fix Recommendation |
|---|----------|----------|-----------|-------------|-------------------|
| 1 | Critical | Injection | api/users.ts:45 | SQL string concatenation | Use parameterized queries |
| 2 | High | Auth | auth/login.ts:12 | No rate limiting | Add express-rate-limit |When --fix is provided, apply fixes iteratively after the audit:
security(fix-N): <short description>
d. Advance to next findingvc-autoresearch guard pattern for regression preventionTip: Use
--iterations Nto cap total fix iterations when scope is large.
| Severity | Description | Fix Priority |
|---|---|---|
| Critical | Exploitable now, data breach or RCE risk | Immediate — block release |
| High | Exploitable with moderate effort, significant impact | This sprint |
| Medium | Limited exploitability or impact | Next sprint |
| Low | Theoretical risk, defense-in-depth improvement | Backlog |
| Info | Best practice suggestion, no direct risk | Optional |
vc-predict when the security persona flags concernsvc-autoresearch --fix for automated remediationvc-scenario with --focus authorization for deeper auth flow testinggenerate-plan / plan-agent to schedule Medium/Low findings as sprint tasks# Audit API layer only
/vc-security src/api/**/*.ts
# Audit entire src/ and auto-fix, max 15 iterations
/vc-security src/ --fix --iterations 15
# Full codebase audit (no fix)
/vc-security fullSee references/stride-owasp-checklist.md for the detailed per-category checklist and secret detection regex patterns.
© withkynam, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in .claude/skills/vc-security of withkynam/vibecode-pro-max-kit.
Open the folder on GitHubat commit 3bcb2f9
Vc Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vc Security this skillwithkynam/vibecode-pro-max-kit | 1.1k | — | ~1.2k | Automated safety check: Pass | MIT | |
| Security Audit Scannerruvnet/ruflo | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | |
| CybersecurityAgriciDaniel/claude-cybersecurity | 227 | — | ~11k | Automated safety check: Warn | MIT | |
| Securitygaragon/nanostack | 207 | — | ~3.7k | Automated safety check: Notes | Apache-2.0 | |
| Csono-session/pstack | 131 | — | ~12k | Automated safety check: Notes | MIT | |
| 007sickn33/agentic-awesome-skills | 47k | 2 repos | ~410 | Automated safety check: Pass | MIT |
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
AgriciDaniel/claude-cybersecurity
Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.
garagon/nanostack
Use before shipping to production. An agent skill from garagon/nanostack.
no-session/pstack
Chief Security Officer mode. An agent skill from no-session/pstack.
sickn33/agentic-awesome-skills
Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
fossasia/eventyay-interpretation
A skill your agent uses for security reviews of VoxBento code.
withkynam/vibecode-pro-max-kit
Looks up library and framework documentation through Context7 first, with bundled Node scripts as a fallback that fetch and analyze llms.txt files.
withkynam/vibecode-pro-max-kit
Apply step-by-step analysis for complex problems with revision capability.
withkynam/vibecode-pro-max-kit
Drives a browser through the agent-browser CLI, using compact snapshots with element refs to keep context small in long sessions, plus video recording and cloud browsers.
withkynam/vibecode-pro-max-kit
Audits a project's context routing, skill discoverability and skill wiring by running a chain of validator scripts and fixing whatever they report.
withkynam/vibecode-pro-max-kit
Reviews a codebase's active plan files for staleness and completion, then archives only the ones confirmed done or obsolete against the real code.
withkynam/vibecode-pro-max-kit
Forces root-cause investigation before any fix, combining a four-phase debugging method with log, CI and performance investigation techniques and a rule against unverified completion claims.
Categories
STRIDE + OWASP-based security audit with optional auto-fix. An agent skill from withkynam/vibecode-pro-max-kit. Vc Security is an agent skill from withkynam/vibecode-pro-max-kit. STRIDE + OWASP-based security audit with optional auto-fix.
Vc Security fits situations like: tasks that involve Web application vulnerabilities; tasks that involve Threat modeling; tasks that involve Security review.
Run `npx skills add withkynam/vibecode-pro-max-kit --skill vc-security -a claude-code`. Or copy the skill folder (.claude/skills/vc-security in withkynam/vibecode-pro-max-kit) into .claude/skills/vc-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add withkynam/vibecode-pro-max-kit --skill vc-security -a codex`. Or copy the skill folder (.claude/skills/vc-security in withkynam/vibecode-pro-max-kit) into .agents/skills/vc-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add withkynam/vibecode-pro-max-kit --skill vc-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vc-security, .gemini/skills/vc-security, .github/skills/vc-security and .opencode/skills/vc-security in your project.
Going by SKILL.md and its folder, Vc Security needs the command-line tools its instructions call (pnpm and bundle). Our summary lists: Node.js.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Vc Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Vc Security: Security Audit Scanner (ruvnet/ruflo, 74k stars), Cybersecurity (AgriciDaniel/claude-cybersecurity, 227 stars), Security (garagon/nanostack, 207 stars) and Cso (no-session/pstack, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
withkynam (a GitHub user) maintains it in withkynam/vibecode-pro-max-kit, which has 1,144 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on June 21, 2026.
Source: withkynam/vibecode-pro-max-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.