Security Audit
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.
$ npx skills add zereight/gitlab-mcp --skill security-scan -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install zereight/gitlab-mcp security-scan --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/zereight/gitlab-mcp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/security-scan .claude/skills/security-scan && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-scan" agent skill from https://github.com/zereight/gitlab-mcp/tree/main/.github/skills/security-scan into .claude/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/zereight/gitlab-mcp/tree/main/.github/skills/security-scanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add zereight/gitlab-mcp --skill security-scan -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install zereight/gitlab-mcp security-scan --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zereight/gitlab-mcp.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/security-scan .agents/skills/security-scan && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-scan" agent skill from https://github.com/zereight/gitlab-mcp/tree/main/.github/skills/security-scan into .agents/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zereight/gitlab-mcp --skill security-scan -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install zereight/gitlab-mcp security-scan --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zereight/gitlab-mcp.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/security-scan .cursor/skills/security-scan && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-scan" agent skill from https://github.com/zereight/gitlab-mcp/tree/main/.github/skills/security-scan into .cursor/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/zereight/gitlab-mcp.git --path .github/skills/security-scan--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add zereight/gitlab-mcp --skill security-scan -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install zereight/gitlab-mcp security-scan --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zereight/gitlab-mcp.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/security-scan .gemini/skills/security-scan && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-scan" agent skill from https://github.com/zereight/gitlab-mcp/tree/main/.github/skills/security-scan into .gemini/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install zereight/gitlab-mcp security-scanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add zereight/gitlab-mcp --skill security-scan -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/zereight/gitlab-mcp.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/security-scan .github/skills/security-scan && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-scan" agent skill from https://github.com/zereight/gitlab-mcp/tree/main/.github/skills/security-scan into .github/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add zereight/gitlab-mcp --skill security-scan -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install zereight/gitlab-mcp security-scan --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/zereight/gitlab-mcp.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/security-scan .opencode/skills/security-scan && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-scan" agent skill from https://github.com/zereight/gitlab-mcp/tree/main/.github/skills/security-scan into .opencode/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-scanRuns a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.
The scan is meant to be faster than a full review and focused only on security, run before committing code that touches auth, user input, data storage or external APIs, or right after adding a new dependency. It starts by scoping to the files changed since the last commit, defaulting to git diff --name-only HEAD~1.
A secrets scan greps changed source files for common secret patterns, such as long API-key-shaped strings, and treats any match found in committed code as an immediate blocker. A dependency audit then runs the language-appropriate tool, for example npm audit at a high severity level, and reports the count of critical and high CVEs with their package names.
The remaining steps are a manual spot-check: for files touching user input, whether it is validated, whether SQL queries are parameterized, whether HTML output is escaped and whether file paths are sanitized against traversal; for files touching auth, whether authentication runs before authorization, whether checks exist on every relevant endpoint, whether JWTs are validated on algorithm, signature and expiry, and whether session cookies are HttpOnly, Secure and SameSite=Strict. Findings are reported with a severity table ranking issues from a hardcoded secret, rated critical, down to plain HTTP instead of HTTPS, rated medium.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0109168. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitnpmcargomvnFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pre-Commit Security Scan loads about 859 tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 235 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
# Check .env is in .gitignoreAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from zereight/gitlab-mcp at commit 0109168, republished under its MIT licence (© zereight). 235 words, ~859 tokens.
.claude/skills/security-scan/SKILL.md (or your agent's skills folder).Rapid security sweep for code changes. Faster than a full /review — focused on security only.
# Default: scan recent changes
git diff --name-only HEAD~1
# Or use provided path# Scan for common secret patterns
grep -rn --include="*.{ts,js,py,go,rs,java,cs,yaml,json,env,sh,toml}" \
-e "sk-[A-Za-z0-9]\{32,\}" \
-e "ghp_[A-Za-z0-9]\{36\}" \
-e "AKIA[0-9A-Z]\{16\}" \
-e "api.key\s*=\s*['\"][^'\"]\{8,\}" \
-e "password\s*=\s*['\"][^'\"]\{4,\}" \
-e "secret\s*=\s*['\"][^'\"]\{8,\}" \
.
# Check .env is in .gitignore
cat .gitignore | grep -E "\.env$|\.env\."CRITICAL: Any match in committed code = immediate blocker.
Run language-appropriate audit:
# Node.js
npm audit --audit-level=high
# Python
pip-audit # or: safety check
# Rust
cargo audit
# Go
govulncheck ./...
# Java/Maven
mvn dependency-check:checkReport: Count of critical/high severity CVEs and their package names.
For changed files that handle user input (API endpoints, form handlers, CLI args):
../ traversal)?For changed files touching auth:
HttpOnly; Secure; SameSite=Strict?## Security Scan Report
**Scope:** [files scanned]
**Date:** [timestamp]
### Secrets
- [ ] No hardcoded secrets found
- ⚠ Found: [file:line — description]
### Dependencies
- Critical CVEs: X
- High CVEs: Y
- Packages: [list if any]
### Input Validation
- [ ] User inputs sanitized in changed files
- ⚠ Risk: [file:line — description]
### Auth
- [ ] Auth/authz checks present on relevant routes
- ⚠ Risk: [file:line — description]
### Verdict
CLEAN / NEEDS ATTENTION / BLOCKER
### Next Steps
- [Action items with file:line references]| Finding | Severity | Action |
|---|---|---|
| Hardcoded secret in committed file | CRITICAL | Rotate key + remove from history |
| Critical CVE in direct dependency | HIGH | Update package immediately |
| SQL injection risk | CRITICAL | Parameterize query before PR |
| Missing auth check on endpoint | HIGH | Add before PR |
| High CVE in transitive dependency | MEDIUM | Track in backlog |
| HTTP instead of HTTPS | MEDIUM | Enforce HTTPS redirect |
@security-reviewer — comprehensive OWASP Top 10 security review/review — full code review including security/coding-standards — baseline code quality rules© zereight, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/security-scan of zereight/gitlab-mcp.
Open the folder on GitHubat commit 0109168
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in zereight/gitlab-mcp, which our catalogue first saw on October 7, 2026.
Pre-Commit Security Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pre-Commit Security Scan this skillzereight/gitlab-mcp | 2k | 1 repos | ~859 | Automated safety check: Notes | MIT | |
| Security AuditTheDecipherist/claude-code-mastery | 550 | — | ~1.3k | Automated safety check: Notes | MIT | |
| CodeQL Security Scantrailofbits/skills | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Security Audit Scannerruvnet/ruflo | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | |
| Code Vuln Auditzebbern/claude-code-guide | 4.6k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Security Vuln Remediationstacklok/toolhive-studio | 170 | — | ~2.3k | Automated safety check: Notes | Apache-2.0 |
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
zebbern/claude-code-guide
Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.
stacklok/toolhive-studio
Remediate security vulnerabilities found by Grype or pnpm audit.
bagofwords1/bagofwords
Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes.
zereight/gitlab-mcp
Detects which autonomous OMG mode is currently active - Autopilot, Ralph, Ultrawork, UltraQA, Team or Self-Improve - and shuts it down cleanly.
zereight/gitlab-mcp
Runs a task through Codex and Gemini CLIs in parallel alongside Claude, then synthesizes the three outputs into one answer with agreements and conflicts called out.
zereight/gitlab-mcp
Shared reference for naming, function size, complexity and error handling rules that reviewer agents apply across TypeScript, Python, Go, Rust, Java, C# and Swift.
zereight/gitlab-mcp
Sorts what you learned in a session into the right memory surface, filtering out ephemeral notes and duplicates before anything is stored.
zereight/gitlab-mcp
Audits a project's skill directories for broken frontmatter, missing template sync and quality gaps, then produces a health report of what needs fixing.
zereight/gitlab-mcp
Reports which OMG modes are active, such as autopilot, ralph, team, ultraqa and self-improve, with phase, story or cycle progress read from their state files.
Works with
Categories
Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps. The scan is meant to be faster than a full review and focused only on security, run before committing code that touches auth, user input, data storage or external APIs, or right after adding a new dependency. It starts by scoping to the files changed since the last commit, defaulting to git diff --name-only HEAD~1.
Pre-Commit Security Scan fits situations like: running a quick security gate before opening a pull request; checking for leaked secrets or vulnerable dependencies after a change; spot-checking new input handling or authorization code for common gaps.
Run `npx skills add zereight/gitlab-mcp --skill security-scan -a claude-code`. Or copy the skill folder (.github/skills/security-scan in zereight/gitlab-mcp) into .claude/skills/security-scan in your project. Claude Code loads it when a task matches its description.
Run `npx skills add zereight/gitlab-mcp --skill security-scan -a codex`. Or copy the skill folder (.github/skills/security-scan in zereight/gitlab-mcp) into .agents/skills/security-scan in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zereight/gitlab-mcp --skill security-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-scan, .gemini/skills/security-scan, .github/skills/security-scan and .opencode/skills/security-scan in your project.
Going by SKILL.md and its folder, Pre-Commit Security Scan needs the command-line tools its instructions call (git, npm, cargo and mvn). Our summary lists: git; A dependency audit tool for the project's language (such as npm).
SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Pre-Commit Security Scan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 859 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Pre-Commit Security Scan: Security Audit (TheDecipherist/claude-code-mastery, 550 stars), CodeQL Security Scan (trailofbits/skills, 7.4k stars), Security Audit Scanner (ruvnet/ruflo, 74k stars) and Code Vuln Audit (zebbern/claude-code-guide, 4.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
zereight (a GitHub user) maintains it in zereight/gitlab-mcp, which has 2,027 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 6, 2026.
Source: zereight/gitlab-mcp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.