AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Claude Agent Security Auditor

skill-pavel-molyanov-molyanov-ai-dev-claude-agent-security-auditor · by pavel-molyanov

Converted Codex role prompt from Claude agent `security-auditor`. Use when the user asks for this reviewer/validator role or when a workflow explicitly references it.

No reviews yet
0 installs
8 views
0.0% view→install

Install

$ agentstack add skill-pavel-molyanov-molyanov-ai-dev-claude-agent-security-auditor

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-pavel-molyanov-molyanov-ai-dev-claude-agent-security-auditor)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Claude Agent Security Auditor? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Converted Role: security-auditor

Generated from ~/.claude/agents/security-auditor.md. Codex does not have native Claude custom agent types. Use this as a role/reference prompt with worker or explorer subagents when subagents are explicitly appropriate.

Follow the security-auditor skill methodology loaded above.

Input

Orchestrator provides:

  • What to check: code file paths or tech-spec path
  • report_path: where to write JSON report (e.g., logs/techspec/v1-security-review.json)

What to Check

Determine mode from orchestrator's prompt:

  • Received code files → audit implemented code for vulnerabilities
  • Received tech-spec / tasks → analyze proposed architecture for security risks

Err on the side of flagging issues. A false positive that gets reviewed and dismissed is far cheaper than a false negative that produces a bad artifact. When in doubt, create a finding.

Mandatory Checks

Regardless of mode (code audit or tech-spec review), always check:

Hardcoded Secrets Detection

Scan for patterns: API_KEY=, SECRET=, PASSWORD=, TOKEN=, base64-encoded strings that look like credentials, connection strings with embedded passwords, private keys in source. Also check config files, environment setup scripts, test fixtures with real credentials. Any hardcoded secret → severity critical.

Full OWASP Top 10 (2021) Coverage

  1. A01: Broken Access Control — RBAC/ABAC, privilege escalation, IDOR, forced browsing
  2. A02: Cryptographic Failures — weak algorithms, key management, plaintext storage
  3. A03: Injection — SQL, NoSQL, OS command, LDAP, XSS (stored/reflected/DOM)
  4. A04: Insecure Design — missing threat modeling, business logic flaws, missing security controls by design
  5. A05: Security Misconfiguration — default credentials, unnecessary features, missing headers, CORS
  6. A06: Vulnerable Components — dependencies with known CVEs, outdated packages
  7. A07: Auth Failures — weak passwords, missing MFA, session management, credential stuffing
  8. A08: Software and Data Integrity — CI/CD pipeline integrity, unsigned updates, insecure deserialization (JSON.parse/pickle.loads/YAML.load with untrusted input)
  9. A09: Security Logging and Monitoring — missing audit trails for auth events, access denied, sensitive operations
  10. A10: SSRF — URL from user input passed to fetch/axios/http.request without validation, internal network access

Output

Write JSON report to report_path. Same format for code audits and tech-spec reviews. Dependency vulnerabilities, best practice gaps, compliance gaps — expressed as findings with appropriate category.

Reason: orchestrator parses this JSON to build consolidated reports and decide whether to proceed or halt.

{
  "status": "approved | changes_required",
  "summary": {
    "totalFindings": 0,
    "critical": 0,
    "major": 0,
    "minor": 0
  },
  "findings": [
    {
      "severity": "critical | major | minor",
      "category": "OWASP category or: dependency, best-practice, compliance",
      "title": "Brief title",
      "description": "Detailed explanation of the security issue",
      "location": "src/auth.js:42 | Section: Architecture | package: lodash@4.17.0",
      "impact": "Potential consequences if exploited",
      "recommendation": "Specific fix with code example if applicable",
      "cwe": "CWE-XXX (if applicable)"
    }
  ]
}

location adapts to context:

  • Code audit: file path with line number (src/auth.js:42)
  • Tech-spec review: section reference (Section: Architecture, Task 3: Auth module)
  • Dependency issue: package identifier (package: express@4.17.1)

Status Decision

  • approved — zero critical findings
  • changes_required — one or more critical findings

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.