Secaudit — Security skill for Claude Code
Security audit — OWASP Top 10 systematic scan.
How to install Secaudit
Installs to ~/.claude/skills/howardpen9-claude-code-multi-llm-secaudit/SKILL.md
mkdir -p ~/.claude/skills/howardpen9-claude-code-multi-llm-secaudit && curl -fsSL https://raw.githubusercontent.com/howardpen9/claude-code-multi-llm/HEAD/commands/secaudit.md -o ~/.claude/skills/howardpen9-claude-code-multi-llm-secaudit/SKILL.md Restart Claude Code, or start a new session, for it to be picked up.
What Secaudit does
description: Security audit — OWASP Top 10 systematic scan allowed-tools: Read, Grep, Glob, Bash(git *) argument-hint: [file or directory to audit]
You are performing a systematic security audit.
Target
Audit: $ARGUMENTS
If no target, audit files changed since last commit: `git diff --name-only HEAD~1 2>/dev/null || git ls-files`
OWASP Top 10 Checklist
A01: Broken Access Control
- Missing auth checks on endpoints
- Missing authorization checks
- Direct object
Alternatives in Security
- Security Scan Report — Generated: 2026-04-10 20:48 UTC Skills scanned: 134 Total findings: 836 Critical: 32 High: 50 Safe skills: 100 18.1k ★
- Token Scan — Meme coin and token security scan — checks for rug pull vectors (hidden mint, honeypot, fee manipulation, LP l 3.8k ★
- Mcp-scan (Invariant Labs) — MCP security scanner with proxy mode for real-time scanning without infrastructure changes 1.9k ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Security Audit Stride
Chạy checklist bảo mật OWASP Top 10 + STRIDE trước bước review cuối của Tech Lead trong WF-REVIEW-CRIT (luôn c
Security Audit
Audit de securite complet d'une web app (OWASP Top 10, CWE/CVE, headers, auth, paywall, infra). Genere un rapp
Audit Security
Security audit (OWASP Top 10, PHP-specific vulnerabilities). Analyzes input validation, injection, authenticat
Web Security Audit Skill
Skill de auditoria de seguridad web completa (pentest black-box). 70+ tests automatizados, OWASP Top 10, CVEs,
API Security
API security audit (OWASP API Security Top 10 2023): BOLA/IDOR, broken authentication, broken object-property-
LLM Security
AI/LLM agent security audit (OWASP GenAI/LLM Top 10 2026): prompt injection (direct + indirect/RAG), jailbreak
Related Agents
Security Audit Agent
자바 코드 보안 취약점 검증 전문. Refactor 작업 직후 또는 git commit 직전 호출. OWASP Top 10 + Secret Scan (trufflehog/ggshield) + Pro
Security Audit Analyzer
Комплексный анализ безопасности веб-приложений с JavaScript frontend и PHP backend. Проверка уязвимостей OWASP
Dnp Security Auditor
🔐 .NET security audit — OWASP Top 10 for APIs, secrets exposure, auth configuration, dependency vulnerabiliti