agentsclimarketplace

Audit security

Skill designgrappler/agent-os/claude/skills/audit-security

Scans a project for security vulnerabilities, hardcoded secrets, insecure patterns, and dependency risks.From its SKILL.md

Install
npx -y skills add designgrappler/agent-os --skill audit-security

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

3 things to look at

  • skips confirmationTells the agent to proceed without asking first, 1 time: "Zero-pause: When you announce a scan step, trigger the tool call in the same turn.".
  • 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
  • runs commandsInstructs the agent to run 7 commands, including `grep -rn --include="*.{ts,tsx,js,jsx,py,go,rb,env,yaml,yml,json,toml}" -E "(api_key|apikey|secret|password|token|private_key|access_key)\s*=\s*['\"][^'\"][^\"]{8,}" .` and 6 more.

SKILL.md

4.4 KB, ~1.0k tokens by cl100k_base, as published. Nobody here has run it

Audit Security

Scans a project for security vulnerabilities, hardcoded secrets, insecure patterns, and dependency risks. Works on any project — no Agent OS installation required. If Agent OS is present, findings are written to tracks.md and block further handoffs until critical issues are resolved.

When to Run

  • Before any production deployment or PR merge
  • After a specialist completes a track involving auth, data handling, or external APIs
  • On-demand for any project, with or without Agent OS installed

Rules

  • Read-only by default: Do not modify source files. Report findings only — remediation is the developer's job.
  • Zero-pause: When you announce a scan step (e.g., "Running secrets sweep now"), trigger the tool call in the same turn.
  • Severity discipline: Every finding must carry a severity level. Do not pad with Low findings to appear thorough.
  • Agent OS aware: If AGENTIC.md exists, cross-reference findings against the project's declared security constraints. If it does not exist, skip that step.

Scan Protocol

Run the following checks in order. Do not skip a step because a prior step found issues — complete all steps, then report.

Step 1 — Secrets Sweep

Search for hardcoded credentials, API keys, tokens, and passwords.

# Patterns to grep for across all source files:
grep -rn --include="*.{ts,tsx,js,jsx,py,go,rb,env,yaml,yml,json,toml}" \
  -E "(api_key|apikey|secret|password|token|private_key|access_key)\s*=\s*['\"][^'\"]{8,}" .

Also check:

  • .env files committed to the repo (should be in .gitignore)
  • Any hardcoded URLs containing credentials (e.g., postgres://user:pass@host)

Step 2 — Dependency Audit

Run the appropriate package audit command for the detected stack.

StackCommand
Node.js / Bunnpm audit --audit-level=moderate or bun audit
Pythonpip-audit or safety check
Rubybundle audit
Gogovulncheck ./...

Record the count of Critical, High, and Moderate vulnerabilities. Skip Low unless total count is zero.

Step 3 — Configuration Review

Check for insecure configuration patterns:

  • CORS set to * in production config
  • Missing auth middleware on routes that handle sensitive data
  • Debug mode or verbose error output enabled outside of development
  • .env.example containing real credentials instead of placeholders
  • console.log statements that output sensitive data

Step 4 — Code Pattern Scan

Scan for common vulnerability patterns:

PatternRisk
eval(, exec(, Function( on user inputRemote code execution
Unparameterized SQL stringsSQL injection
innerHTML = / dangerouslySetInnerHTMLXSS
Math.random() for tokens or IDsInsecure randomness
Missing await on auth checksAuth bypass
Unvalidated redirect URLsOpen redirect

Step 5 — Agent OS Gate (skip if Agent OS not installed)

If AGENTIC.md exists:

  • Read the security constraints declared there
  • Flag any findings that violate those constraints as Critical regardless of generic severity
  • If any Critical findings exist, write a blocked status to tracks.md before reporting

Findings Report

Always produce the full report, even if findings are empty.

## Security Audit Report
**Project:** [project name or current directory]
**Date:** [date]
**Agent OS:** [Installed / Not installed]

---

### Summary
| Severity | Count |
|---|---|
| 🔴 Critical | [N] |
| 🟠 High | [N] |
| 🟡 Moderate | [N] |
| 🔵 Low | [N] |

**Overall verdict:** CLEAR / REVIEW REQUIRED / BLOCKED

---

### Findings

#### 🔴 Critical
[Finding 1]
- **Location:** [file:line or package name]
- **Issue:** [what it is]
- **Remediation:** [specific fix]

[Repeat for each critical finding]

#### 🟠 High
[Same format]

#### 🟡 Moderate
[Same format — omit section if empty]

---

### Agent OS Status
[If installed: "1 Critical finding written to tracks.md — handoffs blocked until resolved." ]
[If not installed: "Agent OS not detected — findings not written to project state."]

Verdict rules:

  • BLOCKED — any Critical finding
  • REVIEW REQUIRED — any High finding, no Critical
  • CLEAR — no Critical or High findings

Trigger

Run /audit-security at any time. Works with or without Agent OS installed.

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.