khadinakbarlabs

Audit Scopes — Security skill for Claude Code

Security community

Audit and minimize API scopes for security, verify scope usage, and generate scope justification for App Store submission.

How to install Audit Scopes

Installs to ~/.claude/skills/khadinakbarlabs-shopify-app-builder-audit-scopes/SKILL.md

Terminal
mkdir -p ~/.claude/skills/khadinakbarlabs-shopify-app-builder-audit-scopes && curl -fsSL https://raw.githubusercontent.com/khadinakbarlabs/shopify-app-builder/HEAD/commands/audit-scopes.md -o ~/.claude/skills/khadinakbarlabs-shopify-app-builder-audit-scopes/SKILL.md

Restart Claude Code, or start a new session, for it to be picked up.

What Audit Scopes does


description: "Audit and minimize API scopes for security, verify scope usage, and generate scope justification for App Store submission" argument-hint: "current-scopes, target-resource"

Audit and Minimize API Scopes

You are reviewing and optimizing Shopify API scopes to follow least-privilege principle and prepare for App Store certification.

Scope Inventory and Assessment

  1. List current scopes
    • Extract scopes from shopify.app.toml SCOPES array
    • Common scopes: read_

Alternatives in Security

  • Maestro Knowledge — Intent-driven knowledge-store and Run knowledge lifecycle management — audit/prune, stage candidates (with sig 530 ★
  • Bountyforge — All-round bug bounty skill for Claude Code parallelized agents for smart contract audits (EVM, Move, Solana, T 399 ★
  • List All Global Skills Sorted By Provider Location — asm list --scope global --sort location asm search "code review" --json asm inspect my-skill asm audit --yes a 185 ★

Full documentation available on GitHub

View Source Repository