agentsclimarketplace

Security audit

Skill AvinashP/AgentsAtlas/skills/security-audit

Minimal workflow for building production-ready projects with Claude Code & Codex. 8 commands, fresh context, quality execution.

Install
npx -y skills add AvinashP/AgentsAtlas --skill security-audit

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 7 stars7 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Audits code for security vulnerabilities. Use when asked to check security, find vulnerabilities, or audit for OWASP issues.

SKILL.md

5.1 KB, as published. Nobody here has run it

Security Audit Skill

Systematically audit code for common security vulnerabilities.

Workflow

1. Identify Attack Surface

Map entry points:

  • API endpoints
  • User input forms
  • File uploads
  • URL parameters
  • Headers and cookies
  • WebSocket messages
# Find API routes
grep -r "app.get\|app.post\|router\." --include="*.ts" --include="*.js"

# Find form handlers
grep -r "onSubmit\|handleSubmit" --include="*.tsx" --include="*.jsx"

2. Check OWASP Top 10

Go through each category systematically:

#CategoryWhat to Check
1Broken Access ControlAuth checks on all endpoints
2Cryptographic FailuresSensitive data exposure
3InjectionUser input in queries/commands
4Insecure DesignBusiness logic flaws
5Security MisconfigurationDefault configs, headers
6Vulnerable ComponentsOutdated dependencies
7Auth FailuresWeak passwords, session issues
8Data Integrity FailuresUnverified updates, CI/CD
9Logging FailuresMissing audit trails
10SSRFServer-side request forgery

3. Review Code Patterns

Search for dangerous patterns:

# SQL injection risks
grep -r "query.*\${" --include="*.ts"
grep -r "execute.*+" --include="*.py"

# Command injection risks
grep -r "exec\|spawn\|system" --include="*.ts" --include="*.js"

# XSS risks
grep -r "innerHTML\|dangerouslySetInnerHTML" --include="*.tsx"

# Hardcoded secrets
grep -r "password\|secret\|api_key\|token" --include="*.ts" --include="*.env*"

4. Check Dependencies

# JavaScript
npm audit
npx snyk test

# Python
pip-audit
safety check

5. Document Findings

For each vulnerability:

  • Severity (Critical/High/Medium/Low)
  • Location (file:line)
  • Description
  • Proof of concept (if safe)
  • Recommended fix

Quick Reference

Common Vulnerabilities

Injection (SQL, NoSQL, Command, LDAP)

Vulnerable:

// SQL injection
const query = `SELECT * FROM users WHERE id = ${userId}`;

// Command injection
exec(`convert ${userFilename} output.png`);

// NoSQL injection
User.find({ username: req.body.username });

Fixed:

// Parameterized query
const query = 'SELECT * FROM users WHERE id = ?';
db.query(query, [userId]);

// Validate/escape input
const safeFilename = path.basename(userFilename);
exec(`convert ${shellescape([safeFilename])} output.png`);

// Sanitize NoSQL input
User.find({ username: String(req.body.username) });

Cross-Site Scripting (XSS)

Vulnerable:

// Reflected XSS
element.innerHTML = userInput;

// Stored XSS
<div dangerouslySetInnerHTML={{ __html: comment }} />

Fixed:

// Use textContent
element.textContent = userInput;

// Sanitize HTML
import DOMPurify from 'dompurify';
<div dangerouslySetInnerHTML={{ __html: DOMPurify.sanitize(comment) }} />

Broken Authentication

Vulnerable:

// Weak session
const sessionId = Math.random().toString();

// No rate limiting on login
app.post('/login', (req, res) => { /* no limit */ });

// Password in URL
window.location = `/login?password=${password}`;

Fixed:

// Strong session ID
const sessionId = crypto.randomBytes(32).toString('hex');

// Rate limiting
app.post('/login', rateLimit({ max: 5, windowMs: 15*60*1000 }), ...);

// POST body for credentials
fetch('/login', { method: 'POST', body: JSON.stringify({ password }) });

Sensitive Data Exposure

Vulnerable:

// Logging sensitive data
console.log('User login:', { email, password });

// Error details to client
res.status(500).json({ error: err.stack });

// Hardcoded secrets
const API_KEY = 'sk-1234567890abcdef';

Fixed:

// Sanitize logs
console.log('User login:', { email, password: '[REDACTED]' });

// Generic error
res.status(500).json({ error: 'Internal server error' });

// Environment variables
const API_KEY = process.env.API_KEY;

Security Headers Checklist

// Required headers
helmet({
  contentSecurityPolicy: true,      // XSS protection
  hsts: true,                       // Force HTTPS
  noSniff: true,                    // MIME type sniffing
  frameguard: { action: 'deny' },   // Clickjacking
  xssFilter: true                   // XSS filter
});

Authentication Checklist

  • Passwords hashed with bcrypt/argon2
  • Session tokens are cryptographically random
  • Sessions expire and can be invalidated
  • MFA available for sensitive operations
  • Password requirements enforced
  • Account lockout after failed attempts
  • Secure cookie flags (HttpOnly, Secure, SameSite)

Authorization Checklist

  • Every endpoint checks permissions
  • IDs in URLs are validated against user
  • Elevation of privilege paths reviewed
  • Admin functions separated
  • Default deny policy

See Also

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.