security-audit

security-audit is a skill for Claude Code, Codex from adolfousier/opencrabs. It costs 22 tokens per session (4,332 once invoked), scanned B, original, MIT.

A security review of a codebase that checks for known vulnerabilities, including CVEs, across different programming languages. A CVE is a publicly recorded security weakness in software.

In plain words
What is it for?
Use it to detect the project’s languages and run the matching dependency or vulnerability audit, such as npm audit, pip-audit, cargo audit, or govulncheck. It is intended for findings that a security engineer could raise during code review.
Why use it?
It gives one review process for projects using different technology stacks and reports findings with a severity score. It also makes clear which security checks the available project files support.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/adolfousier/opencrabs/security-audit
Any agent
npx skills add adolfousier/opencrabs --skill security-audit
Clone the repo
git clone --depth 1 https://github.com/adolfousier/opencrabs

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for security-audit

README.md
[![agentmods](https://agentmods.dev/badge/skills/adolfousier/opencrabs/security-audit.svg)](https://agentmods.dev/skills/adolfousier/opencrabs/security-audit)
Your own site
<a href="https://agentmods.dev/skills/adolfousier/opencrabs/security-audit"><img src="https://agentmods.dev/badge/skills/adolfousier/opencrabs/security-audit.svg" alt="Measured on agentmods" height="20"></a>
Per session 22 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 4,332 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 3 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00022 $0.04332
Opus 5 $0.00011 $0.02166
Sonnet 5 $0.00004 $0.00866
Haiku 4.5 $0.00002 $0.00433

Measured 5d ago against content hash 51eac04064fc, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

security-audit scanned grade B with 3 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Cloud metadata endpointmediumServer-side request forgery

One request to 169.254.169.254 can return temporary IAM credentials.

- File-fetcher tools (image proxy, OG-tag fetcher) that don't allowlist hosts and don't block link-local / metadata IPs (`169.254.169.254`, `127.0.0.0/8`, `10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16`)

Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

- Python: `requests.get(url, verify=False)`, `ssl._create_unverified_context()`, `ctx.verify_mode = ssl.CERT_NONE`

Runs shell commandslowCapability

Expected in a hook, worth knowing in a rule or an instructions file.

- `subprocess.run(..., shell=True)` (Python), `subprocess.call(`...`, shell=True)`
src/docs/reference/templates/skills/security-audit/SKILL.md · 281 lines

How it starts

The opening of the file, as written. The whole thing — 281 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are a senior security engineer performing a comprehensive security audit of the codebase in the current working directory. The audit must be language-agnostic — detect the project type and dispatch to the appropriate tooling.

Be honest about what you cannot examine. Better to miss theoretical issues than to flood the report with false positives. Each finding must be something a security engineer would confidently raise in a PR review.

Stage 1 — Project detection

Inspect the working directory for manifest files. Multiple manifests = monorepo / polyglot — audit each language stack.

Manifest detected Language Audit dispatch
Cargo.toml Rust cargo audit
package.json + package-lock.json Node (npm) npm audit --json
package.json + pnpm-lock.yaml Node (pnpm) pnpm audit --json
package.json + yarn.lock Node (yarn) yarn npm audit --json (yarn 2+) or yarn audit --json (yarn classic)
pyproject.toml / poetry.lock / requirements*.txt / Pipfile.lock Python pip-audit (preferred) or safety check --json
go.mod Go govulncheck ./...
Gemfile.lock Ruby bundle audit check --update
composer.json / composer.lock PHP composer audit --format=json
pom.xml / build.gradle / build.gradle.kts Java/JVM osv-scanner -r . (preferred — dependency-check-maven is heavyweight and slow)
pubspec.yaml / pubspec.lock Dart/Flutter osv-scanner -r .
*.csproj / packages.lock.json .NET dotnet list package --vulnerable --include-transitive
Package.swift / Podfile.lock Swift / iOS osv-scanner -r .
mix.exs Elixir mix deps.audit (if installed) or osv-scanner -r .
.terraform.lock.hcl / *.tf Terraform tfsec . and/or checkov -d .
Dockerfile OCI image trivy fs . or grype dir:.

Universal fallback when no native scanner is available, or to cross-check: osv-scanner -r . (covers most ecosystems via SBOM-style detection).

If the relevant scanner is not installed, report which scanner would run and continue with the static-analysis stages. Do not fail the whole audit.

Read the full file on GitHub · 281 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 281 lines · 22 tokens per session scan B 51eac04064fc

Subscribe to this mod's changes

security-audit is a skill published in the GitHub repository adolfousier/opencrabs (920 stars, last pushed yesterday), licensed MIT. It adds 22 tokens to every session and 4,332 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it B with 3 findings (cloud metadata endpoint, makes network calls, runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

compare-harnesses

Diff two scaffolded harnesses (ADR-031). Reports manifest meta drift + host list + per-file fingerprint changes (added/removed/changed). Exits 0 IDENTICAL, 1 DRIFT, 2 missing manifest. Use --bundle for the ADR-031 schema-1 JSON envelope.

ruvnet/metaharness · 66 tokens

create-harness

Scaffold your own focused AI agent harness — pick host (Claude Code, Codex, pi.dev, Hermes), template, agents, skills, and ship a npm-publishable harness with its own npx CLI. Use when a user asks to "create my own agent harness", "scaffold a harness", "make a custom Claude Code plugin like ruflo", or "build a…

ruvnet/metaharness · 89 tokens

diag-harness

Kernel-version skew check (ADR-027). Reports manifest surface + manifest kernel + installed kernel + verdict (match/patch-diff/minor-diff/major-diff). Exits 1 on minor/major skew with a copy-pasteable npm install @metaharness/[email protected] next step. Exits 2 if no .harness/manifest.json at path.

ruvnet/metaharness · 85 tokens

example-harness

Scaffold a ready-made AI agent harness in one command from the 19 published @metaharness/ example packages — 9 host integrations (Claude Code, Codex, Hermes, pi.dev, OpenClaw, RVM, Copilot, OpenCode, GitHub Actions) + 10 vertical pods (devops, research, trading, support, legal, coding, education, sales, gaming…

ruvnet/metaharness · 90 tokens

oia-manifest

Emit .harness/oia-manifest.json declaring layer alignment with the OIA v0.1 9-layer reference architecture. Self-describes the harness's MCP wiring, witness signing, audit log, identity posture (always 'none' at v0.1). --check verifies an existing manifest, --dry-run prints without writing, --json emits to stdout.

ruvnet/metaharness · 79 tokens

repo-genome

7-section readiness scorecard for a LOCAL repo. Reports repo type + agent topology + MCP risk + test confidence + release readiness + recommended harness plan + scorecard. Exit 0 ready, 1 needs-work, 2 blocked. --json for the 6-field scorecard, --bundle for the ADR-031 schema-1 envelope.

ruvnet/metaharness · 73 tokens