Security Actions — Security skill for Claude Code
GitHub Actions for AI agent and supply chain security checks: audit agent configs (Claude Code settings, MCP servers, Cursor rules, CLAUDE.md) for risky permissions and prompt injection, find secrets.
How to install Security Actions
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open basitalisandhu/security-actions and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Security Actions does
GitHub Actions for AI agent and supply chain security checks: audit agent configs (Claude Code settings, MCP servers, Cursor rules, CLAUDE.md) for risky permissions and prompt injection, find secrets in prompt files and notebooks, diff SBOMs in PR comments, audit licences, validate llms.txt, ping IndexNow. SARIF output, no dependencies.
Alternatives in Security
- Trail Of Bits Claude-code-config — Opinionated production defaults from a top security firm: sandboxing, permissions, hooks, skills, MCP server c 1.6k ★
- Agentseal — Security toolkit for AI agents 344 ★
- Claude Leaked Files — Mirrored snapshot of Claude Code's source (exposed 2026-03-31) preserved for educational purposes, defensive s 256 ★
README
security-actions
GitHub Actions for AI agent and supply chain security checks. Six small composite actions, each in its own directory with a dependency-free Python or Node script and a test suite, that teams drop into CI with one `uses:` line. The agent-side actions find risky agent configuration and leaked credentials in prompt files; the supply-chain actions diff SBOMs, audit licences, keep `llms.txt` valid and tell search engines about changed pages.
- uses: basitalisandhu/security-actions/agent-config-audit@v1
Actions
| Action | What it does | Output | Runtime |
|---|---|---|---|
| agent-config-audit | Audits .claude/settings.json permissions and hooks, .mcp.json servers (plain HTTP, literal credentials, unpinned packages), Cursor rules, and CLAUDE.md/AGENTS.md instruction files for prompt-injection patterns and secrets. |
SARIF, job summary, annotations, fail-on gate |
Python |
| prompt-secrets-scan | Finds provider API keys, private keys, bearer tokens, JWTs, webhooks and connection strings inside prompt files, system prompts, notebooks and agent instruction files, with an allowlist file. | SARIF, job summary, annotations | Python |
| llms-txt-check | Validates that a site directory or URL serves an llms.txt that follows the convention (H1, blockquote summary, H2 link sections, resolvable links), or generates one from a docs directory. |
Job summary, annotations, outputs | Python |
| indexnow-ping | Submits changed URLs (from a sitemap with a changed-since filter, or an explicit list) to IndexNow after a Pages deploy. |
Job summary, outputs | Node |
| sbom-diff-comment | Diffs two CycloneDX or SPDX SBOMs and posts or updates one pull request comment with added, removed and changed components and licence changes. | PR comment, job summary, Markdown file | Node |
| license-audit | Reads package-lock.json |
Related Skills
Agent Config Audit
Audit AI agent configuration files for security risks: risky permissions in .claude settings, secrets and unpi
MCP Skills Vault
Offline security check for MCP server configs (.mcp.json, VS Code, Cursor, Claude Code) — GitHub Action, pre-c
Aisecscan
Static security scanner for Claude Code configuration — settings, permissions, hooks, MCP servers, agents/suba
Claude Setup Audit
A Claude Code plugin that audits your whole setup — settings, permissions, hooks, MCP servers, skills, CLAUDE.
J Config Audit
Security audit of Claude, Codex, Gemini, and shared agent configuration for secrets, over-broad permissions, a
Permissions Audit
Review settings.json permissions — flag overly broad rules, identify likely-unused ones, suggest pruning.
Related Agents
Critic Security
Review code for OWASP-style security issues (injection, authn/authz, secrets, supply chain, LLM-specific) in p
Code Audit GitHub Workflows
Audits GitHub Actions workflow YAML and composite-action YAML for supply-chain, injection, permission, and sec
Claude Code Infra
Use PROACTIVELY and automatically — do not wait to be asked — to configure Claude Code itself: sub-agents, ski