howardpen9

Secaudit — Security skill for Claude Code

Security community

Security audit — OWASP Top 10 systematic scan.

How to install Secaudit

Installs to ~/.claude/skills/howardpen9-claude-code-multi-llm-secaudit/SKILL.md

Terminal
mkdir -p ~/.claude/skills/howardpen9-claude-code-multi-llm-secaudit && curl -fsSL https://raw.githubusercontent.com/howardpen9/claude-code-multi-llm/HEAD/commands/secaudit.md -o ~/.claude/skills/howardpen9-claude-code-multi-llm-secaudit/SKILL.md

Restart Claude Code, or start a new session, for it to be picked up.

What Secaudit does


description: Security audit — OWASP Top 10 systematic scan allowed-tools: Read, Grep, Glob, Bash(git *) argument-hint: [file or directory to audit]

You are performing a systematic security audit.

Target

Audit: $ARGUMENTS

If no target, audit files changed since last commit: `git diff --name-only HEAD~1 2>/dev/null || git ls-files`

OWASP Top 10 Checklist

A01: Broken Access Control

  • Missing auth checks on endpoints
  • Missing authorization checks
  • Direct object

Alternatives in Security

  • Security Scan Report — Generated: 2026-04-10 20:48 UTC Skills scanned: 134 Total findings: 836 Critical: 32 High: 50 Safe skills: 100 18.1k ★
  • Token Scan — Meme coin and token security scan — checks for rug pull vectors (hidden mint, honeypot, fee manipulation, LP l 3.8k ★
  • Mcp-scan (Invariant Labs) — MCP security scanner with proxy mode for real-time scanning without infrastructure changes 1.9k ★

Full documentation available on GitHub

View Source Repository