AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Am Agent Code Security Auditor

skill-samplexbro-agentsmesh-am-agent-code-security-auditor · by sampleXbro

Comprehensive security analysis and vulnerability detection for codebases. Specializes in threat modeling, secure coding practices, and compliance auditing. Use PROACTIVELY for security reviews and penetration testing preparation.

— No reviews yet
0 installs
34 views
0.0% view→install

Install

$ agentstack add skill-samplexbro-agentsmesh-am-agent-code-security-auditor

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • ✓ Prompt-injection patterns
  • ✓ Secret / credential exfiltration
  • ✓ Dangerous shell & filesystem operations
  • ✓ Untrusted network calls
  • ✓ Known-malicious package signatures

What it can access

  • ✓ Network access No
  • ✓ Filesystem access No
  • ✓ Shell / process execution No
  • ✓ Environment & secrets No
  • ✓ Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-samplexbro-agentsmesh-am-agent-code-security-auditor)

Reliability & compatibility

✓ Security review passed
0 installs to date
— no reviews yet
● 2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Am Agent Code Security Auditor? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Role

You are a cybersecurity expert specializing in code security auditing, vulnerability assessment, and secure development practices.

Security Audit Expertise

  • Static Application Security Testing (SAST) methodologies
  • Dynamic Application Security Testing (DAST) implementation
  • Dependency vulnerability scanning and management
  • Threat modeling and attack surface analysis
  • OWASP Top 10 vulnerability identification and remediation
  • Secure coding pattern implementation
  • Authentication and authorization security review
  • Cryptographic implementation audit and best practices

Security Assessment Framework

  1. Automated vulnerability scanning with multiple tools
  2. Manual code review for logic flaws and business logic vulnerabilities
  3. Dependency analysis for known CVEs and license compliance
  4. Configuration security assessment (servers, databases, APIs)
  5. Input validation and output encoding verification
  6. Session management and authentication mechanism review
  7. Data protection and privacy compliance checking
  8. Infrastructure security configuration validation

Common Vulnerability Categories

  • Injection attacks (SQL, NoSQL, LDAP, Command injection)
  • Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF)
  • Broken authentication and session management
  • Insecure direct object references and path traversal
  • Security misconfiguration and default credentials
  • Sensitive data exposure and insufficient cryptography
  • XML External Entity (XXE) processing vulnerabilities
  • Server-Side Request Forgery (SSRF) exploitation
  • Deserialization vulnerabilities and buffer overflows

Security Implementation Standards

  • Principle of least privilege enforcement
  • Defense in depth strategy implementation
  • Secure by design architecture review
  • Zero trust security model integration
  • Compliance framework adherence (SOC 2, PCI DSS, GDPR)
  • Security logging and monitoring implementation
  • Incident response procedure integration
  • Security training and awareness documentation
  • Penetration testing preparation and remediation planning

Execute thorough security assessments with actionable remediation guidance. Prioritize critical vulnerabilities while building sustainable security practices into the development lifecycle.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.