Security audit
Skill netresearch/security-audit-skill/skills/security-audit
Agent Skill for PHP security audits - OWASP patterns, vulnerability detection | Claude Code compatible
npx -y skills add netresearch/security-audit-skill --skill security-auditAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
What its author says it does
Copied from the file, not written here
Use when conducting security assessments — OWASP Top 10 / API / LLM, CWE Top 25, CVSS scoring — auditing PHP/TYPO3, APIs, frontend, Terraform/K8s/Docker IaC, AWS cloud, AI agent configs, or scanning dependencies.
The file declares its own license as (MIT AND CC-BY-SA-4.0). See LICENSE-MIT and LICENSE-CC-BY-SA-4.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
3.3 KB, 784 tokens by cl100k_base, as published. Nobody here has run it
Security Audit Skill
Security audit patterns (OWASP Top 10, LLM Top 10 2025, CWE Top 25 2025, CVSS v4.0), cloud/IaC, GitHub security. 80+ PHP/TYPO3 checkpoints (v14.3 LTS in typo3-security.md).
Expertise Areas
- Vulnerabilities: XXE, SQLi, XSS, CSRF, command injection, path traversal, file upload, deserialization, SSRF, SSTI, JWT, type juggling
- Standards: OWASP Top 10 / API / LLM (2025), CWE Top 25, CVSS v3.1/v4.0, OWASP ASVS
- Cloud & IaC: AWS; Terraform, Kubernetes, Docker, Helm
- API & Frontend: REST/GraphQL authZ, rate limits, mass assignment, CSP, DOM-XSS
- AI Agents: SKILL.md/AGENTS.md/CLAUDE.md/mcp.json/hooks.json audit; prompt injection; excessive agency
Reference Files (in references/, .md implied)
- Core: owasp-top10, cwe-top25, xxe-prevention, cvss-scoring, api-key-encryption
- Prevention: deserialization-prevention, path-traversal-prevention, file-upload-security, input-validation, error-message-sanitization
- Architecture: authentication-patterns, security-headers, security-logging, cryptography-guide, security-invariants
- Language features (
*-security-features): php, python, javascript-typescript, nodejs, go - Frameworks (
*-security): typo3, typo3-fluid, typo3-typoscript, symfony, react, vue - Cloud & IaC: aws-security, iac-security
- API & Frontend: api-security, frontend-security
- AI Agent: llm-security (OWASP LLM Top 10 2025)
- Threats: modern-attacks, cve-patterns
- DevSecOps: ci-security-pipeline, supply-chain-security, automated-scanning, gha-security, git-history-secrets
- Incident: supply-chain-incident-response
Security Checklist
-
semgrep/opengrep,trivy fs --severity HIGH,CRITICAL,gitleaksclean - bcrypt/Argon2 passwords, CSRF on state changes, TLS 1.2+
- Server-side input validation; parameterized SQL; XML entities off
- Output encoding + CSP; no unserialize() on user input
- API keys encrypted; exception messages sanitized
- Secrets out of VCS; audit logging on
- Uploads validated, renamed, outside web root
- Headers HSTS + X-Content-Type-Options; dependencies scanned
GitHub Actions Security
- NEVER interpolate
${{ inputs.* }}/${{ github.event.* }}inrun:— useenv: - Dependency triage: upgrade > override > dismiss. Full patterns:
references/gha-security.md.
Verification
./scripts/security-audit-dispatcher.sh /path/to/project # auto-detect stack
./scripts/security-audit.sh /path/to/project # PHP-only
./scripts/github-security-audit.sh owner/repo # GH repo
Dispatcher detects the stack from indicator files and runs matching scripts/scanners/*.sh (13 ecosystems; see references/ index).
Contributing: https://github.com/netresearch/security-audit-skill