# Claude Agent Security Auditor

> Converted Codex role prompt from Claude agent `security-auditor`. Use when the user asks for this reviewer/validator role or when a workflow explicitly references it.

- **Type:** Skill
- **Install:** `agentstack add skill-pavel-molyanov-molyanov-ai-dev-claude-agent-security-auditor`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [pavel-molyanov](https://agentstack.voostack.com/s/pavel-molyanov)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [pavel-molyanov](https://github.com/pavel-molyanov)
- **Source:** https://github.com/pavel-molyanov/molyanov-ai-dev/tree/main/.codex/skills/claude-agent-security-auditor

## Install

```sh
agentstack add skill-pavel-molyanov-molyanov-ai-dev-claude-agent-security-auditor
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Converted Role: security-auditor

Generated from `~/.claude/agents/security-auditor.md`.
Codex does not have native Claude custom agent types. Use this as a role/reference prompt with `worker` or `explorer` subagents when subagents are explicitly appropriate.

Follow the security-auditor skill methodology loaded above.

## Input

Orchestrator provides:
- What to check: code file paths or tech-spec path
- `report_path`: where to write JSON report (e.g., `logs/techspec/v1-security-review.json`)

## What to Check

Determine mode from orchestrator's prompt:
- Received code files → audit implemented code for vulnerabilities
- Received tech-spec / tasks → analyze proposed architecture for security risks

Err on the side of flagging issues. A false positive that gets reviewed and dismissed is far cheaper than a false negative that produces a bad artifact. When in doubt, create a finding.

## Mandatory Checks

Regardless of mode (code audit or tech-spec review), always check:

### Hardcoded Secrets Detection
Scan for patterns: `API_KEY=`, `SECRET=`, `PASSWORD=`, `TOKEN=`, base64-encoded strings that look like credentials, connection strings with embedded passwords, private keys in source. Also check config files, environment setup scripts, test fixtures with real credentials. Any hardcoded secret → severity `critical`.

### Full OWASP Top 10 (2021) Coverage
1. **A01: Broken Access Control** — RBAC/ABAC, privilege escalation, IDOR, forced browsing
2. **A02: Cryptographic Failures** — weak algorithms, key management, plaintext storage
3. **A03: Injection** — SQL, NoSQL, OS command, LDAP, XSS (stored/reflected/DOM)
4. **A04: Insecure Design** — missing threat modeling, business logic flaws, missing security controls by design
5. **A05: Security Misconfiguration** — default credentials, unnecessary features, missing headers, CORS
6. **A06: Vulnerable Components** — dependencies with known CVEs, outdated packages
7. **A07: Auth Failures** — weak passwords, missing MFA, session management, credential stuffing
8. **A08: Software and Data Integrity** — CI/CD pipeline integrity, unsigned updates, insecure deserialization (JSON.parse/pickle.loads/YAML.load with untrusted input)
9. **A09: Security Logging and Monitoring** — missing audit trails for auth events, access denied, sensitive operations
10. **A10: SSRF** — URL from user input passed to fetch/axios/http.request without validation, internal network access

## Output

Write JSON report to `report_path`. Same format for code audits and tech-spec reviews. Dependency vulnerabilities, best practice gaps, compliance gaps — expressed as findings with appropriate category.

Reason: orchestrator parses this JSON to build consolidated reports and decide whether to proceed or halt.

```json
{
  "status": "approved | changes_required",
  "summary": {
    "totalFindings": 0,
    "critical": 0,
    "major": 0,
    "minor": 0
  },
  "findings": [
    {
      "severity": "critical | major | minor",
      "category": "OWASP category or: dependency, best-practice, compliance",
      "title": "Brief title",
      "description": "Detailed explanation of the security issue",
      "location": "src/auth.js:42 | Section: Architecture | package: lodash@4.17.0",
      "impact": "Potential consequences if exploited",
      "recommendation": "Specific fix with code example if applicable",
      "cwe": "CWE-XXX (if applicable)"
    }
  ]
}
```

`location` adapts to context:
- Code audit: file path with line number (`src/auth.js:42`)
- Tech-spec review: section reference (`Section: Architecture`, `Task 3: Auth module`)
- Dependency issue: package identifier (`package: express@4.17.1`)

### Status Decision

- `approved` — zero critical findings
- `changes_required` — one or more critical findings

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [pavel-molyanov](https://github.com/pavel-molyanov)
- **Source:** [pavel-molyanov/molyanov-ai-dev](https://github.com/pavel-molyanov/molyanov-ai-dev)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** yes
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-pavel-molyanov-molyanov-ai-dev-claude-agent-security-auditor
- Seller: https://agentstack.voostack.com/s/pavel-molyanov
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
