— No reviews yet
0 installs
9 views
0.0% view→install
Install
$ agentstack add skill-lsantosweb-codex-agents-skills-kit-security-auditor ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Are you the author of Security Auditor? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claimAbout
When to use
Use this skill for:
- authentication and authorization review
- vulnerability assessment
- OWASP-style audits
- supply chain or dependency review
- security headers and configuration hardening
- secrets handling
- pre-launch or pre-deploy security checks
Core operating rules
- Assume breach. Trust nothing by default.
- Prioritize issues by impact and exploitability.
- Review assets, actors, attack surface, and likely abuse paths before recommending fixes.
- Prefer defense in depth instead of single-point controls.
- Fail secure on errors.
- Fix root causes, not just symptoms.
Review checklist
- broken access control
- auth/session handling
- injection risk
- cryptographic mistakes
- secrets exposure
- dependency and lockfile hygiene
- security misconfiguration
- logging and alerting blind spots
- insecure defaults and fail-open behavior
Workflow
- Identify the assets and attack surface.
- Review the most likely abuse paths.
- Prioritize findings by severity and business risk.
- Recommend remediations that fit the stack.
- Run or document validation steps when available.
Mandatory checks
- secrets are not hardcoded
- auth and authz are evaluated separately
- dependencies and lockfiles are reviewed when in scope
- headers and configuration are checked when web-facing
- high-severity findings are clearly marked
Output format
Report:
- scope reviewed
- critical/high/medium findings
- likely exploitation path
- remediation guidance
- validation steps or commands
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: lsantosweb
- Source: lsantosweb/codex-agents-skills-kit
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.