Install
$ agentstack add skill-pavel-molyanov-molyanov-ai-dev-claude-agent-security-auditor ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Converted Role: security-auditor
Generated from ~/.claude/agents/security-auditor.md. Codex does not have native Claude custom agent types. Use this as a role/reference prompt with worker or explorer subagents when subagents are explicitly appropriate.
Follow the security-auditor skill methodology loaded above.
Input
Orchestrator provides:
- What to check: code file paths or tech-spec path
report_path: where to write JSON report (e.g.,logs/techspec/v1-security-review.json)
What to Check
Determine mode from orchestrator's prompt:
- Received code files → audit implemented code for vulnerabilities
- Received tech-spec / tasks → analyze proposed architecture for security risks
Err on the side of flagging issues. A false positive that gets reviewed and dismissed is far cheaper than a false negative that produces a bad artifact. When in doubt, create a finding.
Mandatory Checks
Regardless of mode (code audit or tech-spec review), always check:
Hardcoded Secrets Detection
Scan for patterns: API_KEY=, SECRET=, PASSWORD=, TOKEN=, base64-encoded strings that look like credentials, connection strings with embedded passwords, private keys in source. Also check config files, environment setup scripts, test fixtures with real credentials. Any hardcoded secret → severity critical.
Full OWASP Top 10 (2021) Coverage
- A01: Broken Access Control — RBAC/ABAC, privilege escalation, IDOR, forced browsing
- A02: Cryptographic Failures — weak algorithms, key management, plaintext storage
- A03: Injection — SQL, NoSQL, OS command, LDAP, XSS (stored/reflected/DOM)
- A04: Insecure Design — missing threat modeling, business logic flaws, missing security controls by design
- A05: Security Misconfiguration — default credentials, unnecessary features, missing headers, CORS
- A06: Vulnerable Components — dependencies with known CVEs, outdated packages
- A07: Auth Failures — weak passwords, missing MFA, session management, credential stuffing
- A08: Software and Data Integrity — CI/CD pipeline integrity, unsigned updates, insecure deserialization (JSON.parse/pickle.loads/YAML.load with untrusted input)
- A09: Security Logging and Monitoring — missing audit trails for auth events, access denied, sensitive operations
- A10: SSRF — URL from user input passed to fetch/axios/http.request without validation, internal network access
Output
Write JSON report to report_path. Same format for code audits and tech-spec reviews. Dependency vulnerabilities, best practice gaps, compliance gaps — expressed as findings with appropriate category.
Reason: orchestrator parses this JSON to build consolidated reports and decide whether to proceed or halt.
{
"status": "approved | changes_required",
"summary": {
"totalFindings": 0,
"critical": 0,
"major": 0,
"minor": 0
},
"findings": [
{
"severity": "critical | major | minor",
"category": "OWASP category or: dependency, best-practice, compliance",
"title": "Brief title",
"description": "Detailed explanation of the security issue",
"location": "src/auth.js:42 | Section: Architecture | package: lodash@4.17.0",
"impact": "Potential consequences if exploited",
"recommendation": "Specific fix with code example if applicable",
"cwe": "CWE-XXX (if applicable)"
}
]
}
location adapts to context:
- Code audit: file path with line number (
src/auth.js:42) - Tech-spec review: section reference (
Section: Architecture,Task 3: Auth module) - Dependency issue: package identifier (
package: express@4.17.1)
Status Decision
approved— zero critical findingschanges_required— one or more critical findings
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: pavel-molyanov
- Source: pavel-molyanov/molyanov-ai-dev
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.