Borrowing it
Nothing to install: this file belongs to afiqiqmal/claude-security-audit. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/afiqiqmal/claude-security-audit/main/CLAUDE.mdgit clone --depth 1 https://github.com/afiqiqmal/claude-security-auditWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/afiqiqmal/claude-security-audit/claude-md)<a href="https://agentmods.dev/instructions/afiqiqmal/claude-security-audit/claude-md"><img src="https://agentmods.dev/badge/instructions/afiqiqmal/claude-security-audit/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00828 | $0.00828 |
| Opus 5 | $0.00414 | $0.00414 |
| Sonnet 5 | $0.00166 | $0.00166 |
| Haiku 4.5 | $0.00083 | $0.00083 |
Grade A, and why
claude-security-audit CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 48 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CLAUDE.md
Project
Claude Code slash command for white-box and gray-box security auditing. Maps findings to OWASP Top 10:2025, CWE, NIST CSF 2.0, SANS/CWE Top 25, OWASP ASVS 5.0, PCI DSS 4.0.1, MITRE ATT&CK, SOC 2 and ISO 27001:2022. Includes security hotspots, code smells and framework-specific checks.
Conventions
- No em-dashes. Use
-(space-hyphen-space) instead - No comma before "and" (no Oxford comma)
- No AI jargon: avoid "leverage", "utilize", "cutting-edge"
- Every finding must have OWASP, CWE ID and NIST CSF 2.0 mapping (other compliance frameworks where applicable, skip extras with
--lite) - Every finding must include exact file path, line number and vulnerable code
- Code fixes are only included when user passes
--fixflag - Severity indicators: 🔴 CRITICAL, 🟠 HIGH, 🟡 MEDIUM, 🟢 LOW, 🔵 INFO
- Reports save to
./security-audit-report.md(and.pdfif a converter is installed)
Modes
full(default) - All phases (1-5)quick- CRITICAL and HIGH only (phases 1-2)gray- Gray-box testing only (phases 1, 3)focus:auth/focus:api/focus:config- Deep dives (phases 1, 2, 4)diff/diff:BRANCH- Git-changed files only (phases 0, 1, 2, 4)recheck:PATH- Re-audit specific files/directories (phases 1, 2, 4)triage- Interactive triage of existing reportphase:1throughphase:5- Single phase execution--fix- Include remediation code blocks--lite- OWASP + CWE + NIST only (reduces token usage)--fail-on critical|high|medium- CI gating with exit summary--format sarif|json- Structured output (SARIF v2.1.0 or JSON)--update-baseline- Write finding fingerprints for future comparison--diff-report path- Compare with previous report--pack name- Load compliance packs (hipaa, gdpr, fintech, saas-multi-tenant, soc2, education)
Structure
.claude/commands/security-audit.md- The slash command (entry point)references/attack-vectors.md- Detailed checklists per attack categoryreferences/nist-csf-mapping.md- NIST CSF 2.0 mapping tablesreferences/compliance-mapping.md- CWE, SANS Top 25, ASVS, PCI DSS, ATT&CK, SOC 2, ISO 27001 mappingreferences/custom-template.md- Template for custom security checksreferences/frameworks/- Framework-specific checklists (Laravel, Next.js, FastAPI, Express, Django, Rails, Spring Boot, ASP.NET Core, Go, Flask, Nuxt.js, SvelteKit)references/features-extended.md- Baseline, SARIF/JSON, report diff and triage specsreferences/packs/- Compliance packs (HIPAA, GDPR, fintech, SaaS multi-tenant, SOC 2, Education)security-audit-guidelines.md- Severity ratings, modes and conventionsinstall.sh- Installs command and references to~/.claude/
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 48 lines · 828 tokens per session scan A ab3acd42a71b
claude-security-audit CLAUDE.md is an instructions file published in the GitHub repository afiqiqmal/claude-security-audit (22 stars, last pushed 6mo ago), licensed MIT. It adds 828 tokens to every session, about $0.0041 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.