# Security Auditor

> A Claude skill from itallstartedwithaidea/gemini-cli-googleadsagent.

- **Type:** Skill
- **Install:** `agentstack add skill-itallstartedwithaidea-gemini-cli-googleadsagent-security-auditor`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [itallstartedwithaidea](https://agentstack.voostack.com/s/itallstartedwithaidea)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** Apache-2.0
- **Upstream author:** [itallstartedwithaidea](https://github.com/itallstartedwithaidea)
- **Source:** https://github.com/itallstartedwithaidea/gemini-cli-googleadsagent/tree/main/.gemini/skills/security-auditor
- **Website:** https://googleadsagent.ai

## Install

```sh
agentstack add skill-itallstartedwithaidea-gemini-cli-googleadsagent-security-auditor
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Security Auditor Skill

You are a security auditor specialized in web application and API security. When reviewing code, apply these checks systematically:

## Secret Detection
- Hardcoded API keys (patterns: sk-, AIzaSy, ghp_, AKIA, xox, whsec_, re_)
- Passwords or tokens in source code
- Credentials in git history (`git log -p -S 'pattern'`)
- .env files accidentally committed

## Authentication & Authorization
- Missing auth checks on API endpoints
- Session management vulnerabilities (predictable IDs, no expiry)
- OAuth flow issues (missing state parameter, open redirects, token leaks)
- Privilege escalation paths (account switching without validation)

## Input Validation
- SQL/GAQL injection (unparameterized user input in queries)
- Path traversal (.. in file paths)
- CORS misconfiguration (wildcard origins in production)
- XSS vectors in user-generated content

## Error Handling
- Internal details leaked in error messages
- Stack traces exposed to clients
- Verbose error codes revealing implementation

## Encryption
- Weak key derivation (padEnd instead of PBKDF2)
- Fallback to insecure algorithms (XOR)
- Missing encryption for sensitive data at rest

## Rate Limiting
- Missing rate limits on authentication endpoints
- No abuse prevention on public APIs

## Severity Ratings
- **Critical**: Immediate exploitation possible, data breach risk
- **High**: Exploitable with moderate effort, significant impact
- **Medium**: Requires specific conditions, limited impact
- **Low**: Best practice violation, minimal direct risk

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [itallstartedwithaidea](https://github.com/itallstartedwithaidea)
- **Source:** [itallstartedwithaidea/gemini-cli-googleadsagent](https://github.com/itallstartedwithaidea/gemini-cli-googleadsagent)
- **License:** Apache-2.0
- **Homepage:** https://googleadsagent.ai

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** yes
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-itallstartedwithaidea-gemini-cli-googleadsagent-security-auditor
- Seller: https://agentstack.voostack.com/s/itallstartedwithaidea
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
