Claude Skill Security Check — Security skill for Claude Code
Claude Code skill: security audit on pending branch changes — anti-vibe-coding checklist + OWASP practices.
How to install Claude Skill Security Check
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open rioscthiago/claude-skill-security-check and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Claude Skill Security Check does
Claude Code skill: security audit on pending branch changes — anti-vibe-coding checklist + OWASP practices.
Alternatives in Security
- MCP Security Checklist (SlowMist) — Comprehensive checklist: input validation, rate limiting, RBAC, credential management, container hardening 819 ★
- Vibeship Scanner — a free vulnerability and security scanner for vibe coders, with 2000+ rulesets, and copy pasteable Master AI F 120 ★
- Audit Infra — Infrastructure-first security audit — secrets, supply chain, CI/CD, LLM/skill security, OWASP, STRIDE 98 ★
README
/security-check — Skill para Claude Code
Auditoria de segurança das mudanças pendentes na branch atual, em uma única invocação.
Combina o foco do `/security-review` (built-in do Claude Code) com:
- Checklist anti-vibe-coding — padrões recorrentes de exploração em apps modernos
- Práticas validadas do OWASP (Cheat Sheets + Secure Headers Project)
Cobre 15+ categorias: Access Control (IDOR, privilege escalation), Business Logic (OWASP A04), Auth & Secrets (anti-enumeração, MFA), Input Validation (SQL/NoSQL/XSS), SSRF (com image proxy), Race Conditions, Secrets & Misconfig (A05), Security Headers, File Upload, Webhooks & Supply Chain (SLSA/SBOM), Exception Handling (A10), AI/LLM Security, Logging Estruturado (OWASP vocab), Privacidade LGPD/GDPR, Honey pots.
**Importante:** a skill **só audita e relata**. Não modifica código, configuração nem infra automaticamente. O relatório é desenhado como **insumo para o planejamento nativo do agente** (Claude Code / Codex) — após você definir escopo, o agente executa com seu próprio planner.
🇧🇷 Português
Como instalar
git clone https://github.com/rioscthiago/claude-skill-security-check.git ~/.claude/skills/security-check
Pronto. A skill aparece na próxima invocação do Claude Code. Pra atualizar: `git -C ~/.claude/skills/security-check pull`.
**Chave da NVD (opcional, recomendada):** a Fase 0 consulta a API da NVD. Sem chave funciona, só que 10x mais devagar. Peça uma chave gratuita em https://nvd.nist.gov/developers/request-an-api-key e guarde em `$NVD_API_KEY` ou em `~/.nvd.key` (nunca dentro do repositório).
Como usar
Dentro do Claude Code, na raiz de qualquer repo Git:
/security-check
A skill vai: 0. **Sincronizar as falhas publicadas** (Fase 0) — NVD, catálogo KEV da CISA (as que já estão sendo exploradas) e GitHub Advisory Database, desde a última verificação, cruzando com as dependências do projeto (`scripts/nvd_check.py` e `scripts/gh_advisories.py`, só std
Related Skills
Vibe Code Security Audit
Audit web apps and AI-generated code for common security flaws with a Claude Code skill focused on OWASP issue
Vibe Code Explainer
Non-developers using Claude Code accept AI-generated code changes blindly. They can’t read diffs, spot unrelat
Multipov Security
Run a multi-agent security-focused code review on $ARGUMENTS (default: current branch changes) via the multipo
Security Audit Stride
Chạy checklist bảo mật OWASP Top 10 + STRIDE trước bước review cuối của Tech Lead trong WF-REVIEW-CRIT (luôn c
Vibe Security Check Skill
Claude skill for automated security audit for vibe-coded apps. One command, 15 checks, auto-fix. Works with No
Stark Audit
Audit existing UI/UX code, flows, or screenshots against UX heuristics plus the matching platform's anti-slop
Related Agents
Deploy Check
Pre-deploy validation that checks branch, uncommitted changes, CI status, and pending PRs
Sdlc Security
Runs a full OWASP Top 10 (2025) audit, plus OWASP LLM Top 10 (2025) when AI/LLM components are present, agains
Security Review
This agent should be invoked when the user asks to review code for security vulnerabilities, check for secrets