Git Gud Security
Description
Security scanner for repos, apps, and things built with Claude (skills, plugins, MCP servers). Runs as a Claude Code skill. 332 checks, 4 scan modes.
Installation
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open the source below and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
README
Git Gud Security
Simple security for solo devs building with AI. Protect yourself and protect others.
A free security tool for solo AI devs: check the skills, MCP servers, agents, and apps you build before you ship them, without paying for a service. No account, no subscription. The fast scan runs entirely on your machine.
Most of what burns people isn't exotic: a service_role key pasted into the frontend, RLS left off "for dev," a committed `.env` with live keys, an MCP tool that runs `exec()` on model-supplied input, a SKILL.md trying to redirect your agent. It looks for those and reports them plainly, with the file and line.
Built for the AI tooling surface the free scanners ignore (MCP servers, Claude skills/plugins/hooks, coding-agent config files, prompt injection in instruction files), with coverage of the app behind it too (Supabase, Firebase, Cloudflare Workers, Next.js, Flutter, Expo). Runs as a Claude Code skill, or as a zero-dependency Python script for the fast `readme`/`quick` scan (`full` and `ultra` need Claude Code for the LLM).
Install
Clone into your skills directory. Pin to a release tag (recommended for a security tool, so you know exactly what's running):
git clone --branch v0.5.0 https://github.com/kidsmeal/git-gud-security ~/.claude/skills/git-gud-security
Or track the latest:
git clone https://github.com/kidsmeal/git-gud-security ~/.claude/skills/git-gud-security
Windows: `%USERPROFILE%\.claude\skills\git-gud-security`. Releases and changelog: [CHANGELOG.md](CHANGELOG.md).
Then ask Claude Code:
scan
Related Skills
Fastapi Review
Review a FastAPI application for architecture, async correctness, dependency injection, Pydantic schemas, secu
Security Defense in Depth
Implement multi-layered testing and security best practices.
Security SecLists Official Repository
[OWASP Testing Guide](https://owasp.org/www-project-web-security-testing-guide/)
Security Threat Hunting with Sigma Rules
Use Sigma detection rules to hunt for threats and analyze security events
Security Maintenance Walkthrough - 2026-03-29
- Re-triaged the full 2026-03-15 security finding set against current `main` and wrote a fresh current-head re
Security Google Workspace Model Armor
Filter user-generated content for safety
Security Related Agents
Django Reviewer
Expert Django code reviewer specializing in ORM correctness, DRF patterns, migration safety, security misconfi
Token Auditor
Scans ui/src/ for hardcoded visual values, duplicate components, and shadcn replacement candidates; produces d
Gitnexus Security Boundary Reviewer
GitNexus security and trust-boundary reviewer. Use for auth, permissions, secrets, injection, unsafe parsing,