security-audit

security-audit is a skill for Claude Code, Codex from joris887/exosuit. It costs 71 tokens per session (1,726 once invoked), scanned A, original, MIT.

A security-review workflow for code involving login, credentials, files, user data, networks, databases, or cryptography. It checks for common weaknesses such as leaked secrets, injection attacks, unsafe input, and risky dependencies.

In plain words
What is it for?
Use it to inspect authentication changes, API endpoints, database queries, file operations, dependency updates, and other security-sensitive code without modifying files.
Why use it?
Security problems in these areas can expose accounts or data, and they are easy to miss during an ordinary code review.

Skill for Claude CodeCodex

Part of the exosuit plugin — 44 skills, 1 command, 9 agents, 10 hooks shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/joris887/exosuit/security-audit
Any agent
npx skills add joris887/exosuit --skill security-audit
Clone the repo
git clone --depth 1 https://github.com/joris887/exosuit

Made for: Claude Code, Codex.

Or install exosuit, the plugin that ships this one along with the rest of its 44 skills, 1 command, 9 agents, 10 hooks.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for security-audit

README.md
[![agentmods](https://agentmods.dev/badge/skills/joris887/exosuit/security-audit.svg)](https://agentmods.dev/skills/joris887/exosuit/security-audit)
Your own site
<a href="https://agentmods.dev/skills/joris887/exosuit/security-audit"><img src="https://agentmods.dev/badge/skills/joris887/exosuit/security-audit.svg" alt="Measured on agentmods" height="20"></a>
Per session 71 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,726 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00071 $0.01726
Opus 5 $0.00036 $0.00863
Sonnet 5 $0.00014 $0.00345
Haiku 4.5 $0.00007 $0.00173

Measured 5d ago against content hash 0f4ea0506a69, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

security-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/skills/security-audit/SKILL.md · 163 lines

How it starts

The opening of the file, as written. The whole thing — 163 lines — stays where its author put it; the contents beside it link to each section on GitHub.


security-audit

Run security audit on authentication changes Check for hardcoded secrets in the codebase Verify input validation on user-facing endpoints

You are a security engineer. This skill MUST be invoked for any code touching authentication, credentials, file access, or user data.

Tool restriction: This agent MUST only use Read, Glob, Grep, and Bash (for running security scanning tools like gitleaks, npm audit, pip-audit, cargo audit). Do NOT use Edit or Write. This is a read-only analysis agent.

Mandatory for

  • Authentication/authorization code
  • Credential and secret handling
  • File system operations with user data
  • Network communications and API endpoints
  • Database queries with user input
  • Cryptographic operations
  • CORS, CSP, or security header configuration
  • Dependency additions or updates

CWE Checklist (Top 15 in AI-Generated Code — Ranked by Frequency × Severity)

Priority CWE Vulnerability What to Check
CRITICAL CWE-798/259 Hardcoded credentials No passwords, keys, tokens, connection strings in source
CRITICAL CWE-89 SQL injection ALL queries parameterized — no string concat with user input
CRITICAL CWE-79 XSS User content escaped before rendering; framework auto-escape enabled
CRITICAL CWE-78 OS command injection No user input in shell commands; use library APIs instead
CRITICAL CWE-94 Code injection No eval(), exec(), Function() with user-controlled input
HIGH CWE-22 Path traversal File paths validated; no ../ exploitation; use path.resolve + check
HIGH CWE-287 Improper authentication Auth checks on ALL protected endpoints; no auth bypass paths
HIGH CWE-306 Missing auth for critical function Admin/destructive/data-export endpoints explicitly protected
HIGH CWE-862 Missing authorization Business-logic authorization enforced, not just authentication
HIGH CWE-327 Broken cryptography No MD5/SHA1 for security; no DES/RC4; adequate key lengths
HIGH CWE-918 SSRF URLs validated before server-side requests; allowlist where possible
HIGH CWE-502 Insecure deserialization Untrusted data not deserialized without schema validation
MEDIUM CWE-200 Information exposure Error messages don't leak stack traces, paths, or config
MEDIUM CWE-20 Input validation Server-side validation on ALL user inputs, not just client-side
MEDIUM CWE-352 CSRF State-changing endpoints have CSRF protection

Read the full file on GitHub · 163 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 163 lines · 71 tokens per session scan A 0f4ea0506a69

Subscribe to this mod's changes

security-audit is a skill published in the GitHub repository joris887/exosuit (4 stars, last pushed 15d ago), licensed MIT. It adds 71 tokens to every session and 1,726 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

issue-triage

Issue triage: audit open issues, categorize, detect duplicates, cross-ref PRs, risk assessment, post comments. Args: "all" for deep analysis of all, issue numbers to focus (e.g. "42 57"), "en"/"fr" for language, no arg = audit only in French.

rtk-ai/rtk · 70 tokens

build-teaql-app

Build or change a TeaQL application in Java, Rust, Go, Swift, Python, C#/.NET, or TypeScript, including Kotlin/JVM applications that consume Java-generated libraries. Mandatory order: first draft and save a complete KSML model, then verify the client and evaluate that saved model, repair it through repeated evaluation…

teaql/teaql-agent-kit · 112 tokens

moai-workflow-worktree

Git worktree management for parallel SPEC development with isolated workspaces, automatic branch registration, and seamless MoAI-ADK integration. Use when setting up parallel development environments.

modu-ai/moai-adk · 41 tokens

moai-kanban-foreman

One unattended kanban foreman iteration: watch the backlog queue, dispatch the next operator-picked card to an isolated worker, collect completion evidence on read (not on claims), and report. This is the body the project's loop.md driver invokes each iteration of a bare /loop; it can also be invoked directly to test…

modu-ai/moai-adk · 76 tokens

moai-workflow-thinking

Sequential Thinking MCP for structured step-by-step analysis via --deepthink flag. Separate from UltraThink which is Claude's native extended reasoning mode. Use for multi-step analysis or architecture decisions.

modu-ai/moai-adk · 43 tokens

moai-domain-uiux

UI/UX design systems specialist covering accessibility, icons, theming, design tokens, and user experience patterns. Use when working on design systems, WCAG compliance, ARIA patterns, or dark mode theming.

modu-ai/moai-adk · 49 tokens