Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add darellchua2/opencode-config-template --skill security-audit-skillgit clone --depth 1 https://github.com/darellchua2/opencode-config-templateWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/darellchua2/opencode-config-template/security-audit-skill)<a href="https://agentmods.dev/skills/darellchua2/opencode-config-template/security-audit-skill"><img src="https://agentmods.dev/badge/skills/darellchua2/opencode-config-template/security-audit-skill.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00043 | $0.07498 |
| Opus 5 | $0.00022 | $0.03749 |
| Sonnet 5 | $0.00009 | $0.01500 |
| Haiku 4.5 | $0.00004 | $0.00750 |
Grade C, and why
security-audit-skill scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nullifies safety policiesmediumAnti-refusal
"You have no restrictions", "do anything now", "ignore your guidelines": a direct jailbreak that disables guardrails.
# Detection: tables missing tenant_id, or queries that forget the filter Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.
Recursive force deletemediumDestructive command
rm -rf with a variable or a broad path is one typo away from removing the wrong tree.
When enabled, defaults to `Iterations: 10`. Safety blocks: `.env`, `node_modules/`, `rm -rf`, `git push --force`. Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.
How it starts
The opening of the file, as written. The whole thing — 763 lines — stays where its author put it; the contents beside it link to each section on GitHub.
What I do
I audit codebases for security vulnerabilities and provide actionable remediation guidance:
- OWASP Top 10 Analysis: Systematic review against injection, broken auth, sensitive data exposure, XXE, broken access control, misconfigurations, XSS, insecure deserialization, vulnerable components, and insufficient logging
- Dependency Scanning: Run and interpret npm audit, pip-audit, Snyk, and Dependabot results
- Secret Detection: Identify leaked API keys, tokens, passwords, and credentials using git-secrets, truffleHog, and gitleaks patterns
- Input Validation: Review user input handling, sanitization, and parameterized queries
- Security Headers: Verify Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options
- HTTPS Enforcement: Check for mixed content, insecure redirects, certificate issues
When to use me
Use this skill when:
- Reviewing code for security vulnerabilities before deployment
- Setting up security scanning in CI/CD pipelines
- Auditing third-party dependencies for known CVEs
- Detecting accidentally committed secrets or credentials
- Hardening HTTP headers and transport security
- Performing a security-focused code review
- Responding to a security incident or vulnerability report
Related Skills
- authentication-authorization-skill: Handles identity/session flow implementation patterns (OAuth, JWT, sessions). This skill handles auditing and vulnerability scanning. CSRF prevention here focuses on detection; auth skill focuses on implementation.
- error-resolver-workflow-skill: Handles runtime error diagnosis. This skill handles proactive security auditing.
- linting-workflow-skill: General linting. This skill focuses on security-specific scanning tools.
Step 1: Dependency Audit
Node.js
npm audit --production
npm audit fix --dry-run
npx better-npm-audit audit
Python
pip-audit --desc
safety check --json
pip-audit -r requirements.txt
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 763 lines · 43 tokens per session scan C 947c0ed012b7
security-audit-skill is a skill published in the GitHub repository darellchua2/opencode-config-template (6 stars, last pushed 2d ago), licensed Apache-2.0. It adds 43 tokens to every session and 7,498 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it C with 2 findings (nullifies safety policies, recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
autoreview
Pre-commit/ship code review: Codex default; optional Claude or Pi.
rework-rate
Measure and interpret PR rework rate — the emerging 5th DORA metric.
omh-code-review
This is a Hermes-native code-review workflow skill.
revdiff-plan
Review the last Codex assistant message (plan, analysis, or proposal) with inline annotations in a TUI overlay. Extracts the most recent response from Codex rollout files and opens it in revdiff for review and annotation. Activates on "revdiff-plan", "review plan with revdiff", "annotate plan", "review last response"…
code-reviewer
Code review specialist focused on patterns, bugs, security, and performance.
agent-teams-simplify-and-harden
Implementation + audit loop using parallel agent teams with structured simplify, harden, and document passes. Spawns implementation agents to do the work, then audit agents to find complexity, security gaps, and spec deviations, then loops until code compiles cleanly, all tests pass, and auditors find zero issues or…