Security audit
Skill henriquescastilho/my-claude/.claude/skills/security-audit
Setup público e sanitizado de um Claude Code full-stack: 8 sub-agents com roteamento por modelo, 792 skills, hooks de segurança, MCP servers e metodologia opinativa. Desenhado para um agente de IA se auto-configurar.From the repository description
npx -y skills add henriquescastilho/my-claude --skill security-auditAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
3.0 KB, 631 tokens by cl100k_base, as published. Nobody here has run it
allowed-tools: Read, Bash, Grep, Glob argument-hint: [focus-area] | --full description: Perform comprehensive security assessment and vulnerability analysis
Security Audit
Perform comprehensive security assessment: $ARGUMENTS
Current Environment
- Dependency scan: !
npm audit --audit-level=moderate 2>/dev/null || pip check 2>/dev/null || echo "No package manager detected" - Environment files: @.env* (if exists)
- Security config: @.github/workflows/security.yml or @security/ (if exists)
- Recent commits: !
git log --oneline --grep="security\|fix" -10
Task
Perform systematic security audit following these steps:
-
Environment Setup
- Identify the technology stack and framework
- Check for existing security tools and configurations
- Review deployment and infrastructure setup
-
Dependency Security
- Scan all dependencies for known vulnerabilities
- Check for outdated packages with security issues
- Review dependency sources and integrity
- Use appropriate tools:
npm audit,pip check,cargo audit, etc.
-
Authentication & Authorization
- Review authentication mechanisms and implementation
- Check for proper session management
- Verify authorization controls and access restrictions
- Examine password policies and storage
-
Input Validation & Sanitization
- Check all user input validation and sanitization
- Look for SQL injection vulnerabilities
- Identify potential XSS (Cross-Site Scripting) issues
- Review file upload security and validation
-
Data Protection
- Identify sensitive data handling practices
- Check encryption implementation for data at rest and in transit
- Review data masking and anonymization practices
- Verify secure communication protocols (HTTPS, TLS)
-
Secrets Management
- Scan for hardcoded secrets, API keys, and passwords
- Check for proper secrets management practices
- Review environment variable security
- Identify exposed configuration files
-
Error Handling & Logging
- Review error messages for information disclosure
- Check logging practices for security events
- Verify sensitive data is not logged
- Assess error handling robustness
-
Infrastructure Security
- Review containerization security (Docker, etc.)
- Check CI/CD pipeline security
- Examine cloud configuration and permissions
- Assess network security configurations
-
Security Headers & CORS
- Check security headers implementation
- Review CORS configuration
- Verify CSP (Content Security Policy) settings
- Examine cookie security attributes
-
Reporting
- Document all findings with severity levels (Critical, High, Medium, Low)
- Provide specific remediation steps for each issue
- Include code examples and file references
- Create an executive summary with key recommendations
Use automated security scanning tools when available and provide manual review for complex security patterns.
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.