Claude Skill Security Auditor — Security skill for Claude Code
Claude Code skill for running structured security audits with actionable remediation plans.
How to install Claude Skill Security Auditor
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open wrsmith108/claude-skill-security-auditor and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Claude Skill Security Auditor does
Claude Code skill for running structured security audits with actionable remediation plans.
Alternatives in Security
- Anthropic Cybersecurity Skills — 734+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Work 3.8k ★
- Clawsec — Security skill suite with drift detection, automated audits, and skill integrity verification 798 ★
- Bountyforge — All-round bug bounty skill for Claude Code parallelized agents for smart contract audits (EVM, Move, Solana, T 399 ★
README
Security Auditor
A Claude Code skill for running structured security audits with actionable remediation plans.
Installation
As a Claude Code Skill
# Clone to your Claude skills directory
git clone https://github.com/wrsmith108/claude-skill-security-auditor.git ~/.claude/skills/security-auditor
Standalone Usage
npx tsx scripts/index.ts [options]
Trigger Phrases
This skill activates when you mention:
- "npm audit"
- "security vulnerability"
- "dependency vulnerability"
- "CVE"
- "security check"
- "audit dependencies"
- "check vulnerabilities"
Capabilities
- Execute
npm audit --jsonand parse structured output - Classify vulnerabilities by severity (critical, high, medium, low)
- Extract CVE identifiers, affected versions, and fix versions
- Distinguish direct vs transitive dependencies
- Generate markdown reports with remediation commands
- Support risk acceptance via
security-exceptions.json - Provide CI-friendly exit codes
Usage
Basic Audit
npx tsx scripts/index.ts
JSON Output
npx tsx scripts/index.ts --json
Fail on High+ Severity (for CI)
npx tsx scripts/index.ts --fail-on high
Fail on Critical Only
npx tsx scripts/index.ts --fail-on critical
Audit a Specific Project
npx tsx scripts/index.ts --cwd /path/to/project
Risk Acceptance
Create a `security-exceptions.json` file in your project root to accept known risks:
{
"exceptions": [
{
"id": "GHSA-xxxx-xxxx-xxxx",
"reason": "Not exploitable in our usage context",
"expires": "2025-06-01",
"approvedBy": "security-team"
}
]
}
Accepted vulnerabilities are tracked separately in the report.
Output Format
The skill generates a markdown report with:
- Summary table by severity
- Detailed breakdown of high+ severity issues
- Transitive dependency analysis
- Copy-paste remediation commands
- List of accepted risks (if a
Related Skills
GPT Pro Audit
Agent skill that audits code and plans with connected GitHub context and a strong ChatGPT model using Effort P
Security Auditor
Audits code for OWASP-class vulnerabilities — injection, auth flaws, secret leaks, unsafe deserialization.
Website Audit Skill
A Claude skill for comprehensive website content and UX audits. Content, copy, UX structure, conversion, creat
Self Audit
Run Black Heron on its own source. Recursive validation — auditor that audits itself. Result is shipped with t
Audit Agent Sessions
Analyze all agent sessions from the last 3 days across Claude, Codex, and Gemini. Produce actionable optimizat
Audit Ddd
DDD architecture audit with pattern recommendations. Analyzes layer separation, domain model richness, and arc
Related Agents
Backlog Auditor
Audits the backlog for label hygiene, body shape, dependency integrity, and milestone coherence. Returns a str
07 Security Auditor
Security specialist that performs security audits, identifies vulnerabilities, and provides remediation guidan
Sourcery Triager
Read-only Sourcery findings triage. Use to summarize security findings, prioritize what to fix first, and prep