security-analysis

security-analysis is a skill for Claude Code from shennawardana23/skillme. It costs 87 tokens per session (1,383 once invoked), scanned A, original, Apache-2.0.

A two-step security scan for a code snippet, file, or code change: first it looks for known risky patterns, then it reasons about business-logic and timing flaws.

In plain words
What is it for?
Use it to produce a severity-ranked list of possible vulnerabilities in existing code or a proposed change.
Why use it?
It finds both obvious problems, such as unsafe database queries, and harder issues that simple pattern matching may miss.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the skillme plugin — 137 skills, 2 commands shipped together

Good fit Use it to produce a severity-ranked list of possible vulnerabilities in existing code or a proposed change.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/shennawardana23/skillme/security-analysis
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add shennawardana23/skillme --skill security-analysis
Clone the repo
git clone --depth 1 https://github.com/shennawardana23/skillme

Made for: Claude Code.

Or install skillme, the plugin that ships this one along with the rest of its 137 skills, 2 commands.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for security-analysis

README.md
[![agentmods](https://agentmods.dev/badge/skills/shennawardana23/skillme/security-analysis/github.svg)](https://agentmods.dev/skills/shennawardana23/skillme/security-analysis)
Your own site
<a href="https://agentmods.dev/skills/shennawardana23/skillme/security-analysis"><img src="https://agentmods.dev/badge/skills/shennawardana23/skillme/security-analysis/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for security-analysis

Your own site · 80×15
<a href="https://agentmods.dev/skills/shennawardana23/skillme/security-analysis"><img src="https://agentmods.dev/badge/skills/shennawardana23/skillme/security-analysis.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 87 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,383 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00087 $0.01383
Opus 5 $0.00044 $0.00691
Sonnet 5 $0.00017 $0.00277
Haiku 4.5 $0.00009 $0.00138

Measured 6d ago against content hash ff624cab820e, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

security-analysis scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Runs shell commandslowCapability

Expected in a hook, worth knowing in a rule or an instructions file.

- Command: `exec.Command`/`os/exec`/`subprocess`/`child_process.exec` where any argument traces back to external input
skills/security-analysis/SKILL.md · 101 lines

How it starts

The opening of the file, as written. The whole thing — 101 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Security Analysis

Two passes, run in order. The static pass is mechanical and exhaustive — report every match, even ones that turn out to be false positives on inspection, and only discard a match after confirming why it's safe. The reasoning pass catches what patterns structurally cannot: this is not a re-run of security-review's priority checklist or security-and-hardening's proactive threat-modeling — it's a scan workflow that ends in a severity-counted findings report.

Pass 1: static pattern scan

Check every category below against the target. Treat this like a grep sweep — you're looking for shapes, not judging exploitability yet.

Injection

  • SQL: string concatenation or fmt.Sprintf/+ building a query with an external value; raw input placed directly in a WHERE/ORDER BY clause
  • Command: exec.Command/os/exec/subprocess/child_process.exec where any argument traces back to external input
  • Template: untrusted input rendered through a non-escaping template engine (Go text/template instead of html/template)
  • LDAP: unsanitized input interpolated into an LDAP filter string

Credential and secret exposure

  • Hardcoded passwords, API keys, tokens, connection strings in source
  • Secrets appearing in log statements, even at DEBUG level
  • Secrets or internal detail echoed back in error responses
  • Environment variables logged directly instead of redacted

Authentication and authorization

  • Endpoints reachable with no authentication check at all
  • Authentication present but no check that the caller is authorized for this resource (ownership/role check)
  • JWT validation skipped, or alg: none/unverified-signature acceptance
  • Session tokens with low entropy or no expiry

Cryptographic weaknesses

  • MD5 or SHA1 for anything security-sensitive (password hashing, MACs)
  • ECB mode block ciphers
  • Hardcoded IV/nonce (reused nonce breaks stream-cipher and GCM confidentiality)
  • math/rand (or language equivalent) used for tokens, session IDs, or anything security-sensitive

Read the full file on GitHub · 101 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 101 lines · 87 tokens per session scan A ff624cab820e

Subscribe to this mod's changes

security-analysis is a skill published in the GitHub repository shennawardana23/skillme (2 stars, last pushed 11d ago), licensed Apache-2.0. It adds 87 tokens to every session and 1,383 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 1 finding (runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

systematic-debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.

obra/superpowers · 21 tokens

coding-protocol

Risk-scaled repo execution and code-evidence protocol. Skip architecture-only work, explanation, contract-preserving prose, and status. Use for contract changes, debugging, code review, implementation plans, and Git mutation; mixed tasks: only those parts.

lencx/skills · 54 tokens

fix-bug

Resolves a single bug from any starting evidence — Dash0 telemetry (span / log / web event / RUM error link), raw stack trace, error message, code pointer (file:line), screen recording, Linear ticket URL, or free-text symptom. Classifies the input, triages complexity (Phase 0.5) to pick between a fast lane and a full…

mthines/agent-skills · 343 tokens

holistic-analysis

Forces a full holistic re-analysis when a fix or refactor isn't working. Instead of continuing to patch in isolation, this skill triggers a structured step-back analysis that traces the entire execution path end-to-end — from entry point to exit — analyzing each block, every contract boundary, and the full data flow.…

mthines/agent-skills · 224 tokens

ci-auto-fix

Diagnoses a failed CI check, classifies it with an explicit verdict (code-bug | workflow-bug | dep-bug | env-bug | flaky | unsure), confidence-gates the fix (>=90 auto, 80-89 ask, <80 escalate), applies it, pushes, and iteratively verifies until CI passes — reverting the last commit if a brand-new failure appears.…

mthines/agent-skills · 154 tokens

playwright-trace-analyzer

Analyzes Playwright E2E trace.zip archives (and bare trace JSONL when unpacked). Extracts the action timeline, network waterfall, console errors, and DOM-snapshot anchors, then identifies the highest-impact problems (flaky waits, slow selectors, network bottlenecks, hung actions, unhandled console errors, navigation…

mthines/agent-skills · 232 tokens