Security Audit

Perform comprehensive security audits on codebases by scanning for OWASP Top 10 vulnerabilities, checking dependencies for known CVEs, detecting leaked secrets and API keys, and generating prioritized fix recommendations. This skill combines static analysis patterns with dependency auditing tools.

Overview

The Security Audit skill, hosted in the TerminalSkills/skills repository, provides automated security assessment capabilities for AI agents like Codex and Claude. It facilitates codebase reviews by identifying common security risks aligned with the OWASP Top 10 framework. The tool integrates static analysis patterns to detect vulnerabilities and scans project dependencies against databases of known CVEs. Additionally, it identifies exposed sensitive information such as API keys and secrets within the source code. Upon completion of an audit, the skill generates a list of prioritized recommendations to assist developers in remediating discovered issues. This utility is maintained within a repository that has garnered 72 stars, reflecting its utility for developers seeking to integrate security validation into their automated workflows.

Use Cases

Identifying OWASP Top 10 vulnerabilities within application source code.
Auditing project dependencies to detect and report known CVEs.
Scanning repositories for accidentally committed API keys or credentials.

Install Notes

# Review source first
open https://github.com/TerminalSkills/skills/blob/main/skills/security-audit/SKILL.md

Copy or clone the skill folder into your agent skills directory after reviewing its instructions and scripts.

Security Notes

This skill performs analysis of codebases and dependencies to identify potential vulnerabilities. Users should ensure the AI agent has appropriate read permissions for the target directory and be aware that automated scans may require manual verification to confirm findings and mitigate false positives.

Related Skills

Security And Hardening

addyosmani/agent-skills

Security

Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.

typescriptjavascript
81,373 StarsMIT

Trailmark Summary

trailofbits/skills

Security

Runs a Trailmark summary analysis on a codebase. Returns auto-detected languages, entry point count, and dependency list. Use when vivisect or galvanize needs a quick structural overview. Triggers: trailmark summary, code summary, structural overview.

Claude CodeClaude
pythonsecurity
6,407 StarsSource linked

Skill Improver

trailofbits/skills

Security

Iteratively reviews and fixes Claude Code skill quality issues until they meet standards. Runs automated fix-review cycles using the skill-reviewer agent. Use to fix skill quality issues, improve skill descriptions, run automated skill review loops, or iteratively refine a skill. Triggers on 'fix my skill', 'improve...

Claude CodeClaude
securityreview
6,407 StarsSource linked

Sarif Parsing

trailofbits/skills

Security

Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. Triggers on "parse sarif", "read scan results", "aggregate findings", "deduplicate alerts", or "process sarif output". Handles filtering, deduplication, format conversion, and CI/CD integration of SARIF data. Does NO...

Claude CodeClaude
pythonsecurity
6,407 StarsSource linked

Trailmark Structural

trailofbits/skills

Security

Runs full Trailmark structural analysis by building a graph, running `preanalysis()`, and reporting hotspots, taint, blast radius, privilege boundaries, attack surface, and version-gated Trailmark 0.4+/0.5+ data such as proxy counts, subgraph edges, type/reference summaries, and entrypoint attributes. Use when vivis...

Claude CodeClaude
pythonsecurity
6,407 StarsSource linked

Variant Analysis

trailofbits/skills

Security

Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing systematic code audits after finding an initial issue.

Claude CodeClaude
pythonsecurity
6,407 StarsSource linked