Back to list
aiskillstore

security-audit

by aiskillstore

Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified.

102🍴 3📅 Jan 23, 2026

SKILL.md


name: security-audit description: Review security of command execution, tool permissions, and API key handling. Use when user mentions "security review", "audit", "check security", "vulnerabilities", or before deploying to production. allowed-tools: Read, Grep, Glob

Security Audit

Instructions

  1. Command Execution Review (backend/main.py):

    • Check run_terminal_command() for shell injection vulnerabilities
    • Verify timeout is enforced (should be 15 seconds)
    • Look for dangerous command patterns
  2. Tool Permission Review:

    • Verify Chat mode only allows: read_file, web_search
    • Check Agent mode tool restrictions
    • Look for permission bypass vulnerabilities
  3. Secrets Management:

    • Ensure .env is in .gitignore
    • Check no API keys are hardcoded
    • Verify python-dotenv usage for environment variables
  4. WebSocket Security:

    • Check for authentication on /ws endpoint
    • Review message validation
    • Look for injection points in user input
  5. Frontend Security:

    • Check for XSS in markdown rendering
    • Review image upload handling (base64 encoding)
    • Verify no sensitive data in client-side code
  6. Generate report with:

    • Critical issues (immediate action required)
    • Warnings (should fix before production)
    • Recommendations (best practices)

Examples

  • "Run a security audit"
  • "Check for vulnerabilities"
  • "Review security before deploy"

Guardrails

  • This is a READ-ONLY audit; do not modify files
  • Report findings without exploiting vulnerabilities
  • Recommend fixes but get user approval before implementing
  • Never log or expose discovered secrets

Score

Total Score

60/100

Based on repository quality metrics

SKILL.md

SKILL.mdファイルが含まれている

+20
LICENSE

ライセンスが設定されている

0/10
説明文

100文字以上の説明がある

0/10
人気

GitHub Stars 100以上

+5
最近の活動

1ヶ月以内に更新

+10
フォーク

10回以上フォークされている

0/5
Issue管理

オープンIssueが50未満

+5
言語

プログラミング言語が設定されている

+5
タグ

1つ以上のタグが設定されている

+5

Reviews

💬

Reviews coming soon