AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL unreviewed MIT Self-run

Qa Security

skill-christopherlouet-claude-base-qa-security · by christopherlouet

Perform a security audit based on OWASP. Use when the user wants to verify security, look for vulnerabilities, or before a production deployment.

— No reviews yet
0 installs
40 views
0.0% view→install

Install

$ agentstack add skill-christopherlouet-claude-base-qa-security

Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.

Security review

⚠ Flagged

1 finding(s); flagged for manual review. · v0.1.0 How review works →

  • • Prompt-injection patterns
  • • Secret / credential exfiltration
  • • Dangerous shell & filesystem operations
  • • Untrusted network calls
  • • Known-malicious package signatures
  • high Dangerous shell/eval execution.

What it can access

  • ✓ Network access No
  • ✓ Filesystem access No
  • ✓ Shell / process execution No
  • ✓ Environment & secrets No
  • ● Dynamic code execution Used

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Reliability & compatibility

— Not yet reviewed
0 installs to date
— no reviews yet
● 2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Qa Security? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Security Audit

Objective

Identify security vulnerabilities based on OWASP Top 10.

Instructions

1. Automated scan

# npm dependency audit
npm audit --audit-level=moderate

# Secret search
npx secretlint "**/*"

# Static security analysis
npx eslint --plugin security src/

2. OWASP Top 10 Checklist

A01 - Broken Access Control
  • [ ] Authorization checks on every endpoint
  • [ ] No IDOR (direct access via predictable IDs)
  • [ ] CORS correctly configured
  • [ ] Principle of least privilege
A02 - Cryptographic Failures
  • [ ] Sensitive data encrypted (at rest + in transit)
  • [ ] No secrets in code
  • [ ] Secure hash algorithms (bcrypt, argon2)
  • [ ] TLS/HTTPS enforced
A03 - Injection
  • [ ] SQL: Parameterized queries / ORM
  • [ ] XSS: HTML output escaping
  • [ ] Command injection: No shell with user input
  • [ ] NoSQL: Query validation
A04 - Insecure Design
  • [ ] Server-side validation (not just client)
  • [ ] Rate limiting on sensitive endpoints
  • [ ] Environment separation
A05 - Security Misconfiguration
  • [ ] Security headers (CSP, X-Frame-Options)
  • [ ] No stack traces in production
  • [ ] Correct file permissions
A06 - Vulnerable Components
  • [ ] npm audit with no critical vulnerabilities
  • [ ] Dependencies maintained and up to date
A07 - Authentication Failures
  • [ ] Passwords hashed correctly
  • [ ] Protection against brute force
  • [ ] Secure sessions (httpOnly, secure, sameSite)
A08 - Data Integrity Failures
  • [ ] Validation of incoming data
  • [ ] Secure deserialization
A09 - Logging Failures
  • [ ] Logs of security events
  • [ ] No sensitive data in logs
A10 - SSRF
  • [ ] Validation of user URLs
  • [ ] Whitelist of allowed domains

3. Search patterns

# Potential secrets
grep -rn "password\s*=" --include="*.ts"
grep -rn "api_key\s*=" --include="*.ts"
grep -rn "secret\s*=" --include="*.ts"

# Potential SQL Injection
grep -rn "query.*\$\{" --include="*.ts"
grep -rn "execute.*\+" --include="*.ts"

# Potential XSS
grep -rn "innerHTML" --include="*.tsx"
grep -rn "dangerouslySetInnerHTML" --include="*.tsx"

# Dangerous eval
grep -rn "eval(" --include="*.ts"
grep -rn "new Function(" --include="*.ts"

4. Recommended security headers

// Express with Helmet
app.use(helmet({
  contentSecurityPolicy: {
    directives: {
      defaultSrc: ["'self'"],
      scriptSrc: ["'self'"],
      styleSrc: ["'self'", "'unsafe-inline'"],
      imgSrc: ["'self'", "data:", "https:"],
    }
  },
  hsts: { maxAge: 31536000, includeSubDomains: true }
}));

Expected output

## Security Report

### Summary
- **Overall risk level**: [Critical/High/Medium/Low]
- **Vulnerabilities found**: X
- **Vulnerable dependencies**: Y

### Critical vulnerabilities
| Severity | Category | File:Line | Description | Remediation |
|----------|----------|-----------|-------------|-------------|
| CRITICAL | A03 | auth.ts:45 | SQL injection | Parameterized query |

### Important vulnerabilities
[...]

### Priority recommendations
1. [Immediate action]
2. [Short term]
3. [Medium term]

### Dependencies to update
| Package | Version | Vulnerability | Severity |
|---------|---------|---------------|----------|
| lodash | 4.17.19 | Prototype pollution | High |

Rules

  • IMPORTANT: Check all 10 OWASP categories
  • IMPORTANT: Prioritize by severity
  • YOU MUST propose concrete remediations
  • NEVER ignore critical vulnerabilities

Think hard about every potential attack vector.

See also

Two community sources complement this skill:

  • agamm/claude-code-owasp (171★, last commit 2026-04-28) — covers OWASP Top 10:2025, ASVS 5.0, and 20 language-specific quirks. Independent author. Adoption is modest at the time of this audit; the value is in pointing to a faithful implementation of the canonical OWASP standard rather than in popularity.
  • semgrep official Claude plugin — Semgrep is an independent security company; their plugin integrates the static-analysis engine into Claude Code sessions for automated scanning.

When working on a security audit, install one or both alongside this skill. This skill captures the manual review workflow (when to invoke, what to escalate, blocking criteria); the OWASP skill captures the canonical attack catalogue with current 2025-2026 categories; the Semgrep plugin adds the automated scanner layer.

Install command and full list of validated vendor skills: docs/recipes/recommended-vendor-skills.md. Audit pilot trace: specs/marketplace-audit/qa-skills-pilot-2026-05-06.md.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.