Yotta Security Audit — Security skill for Claude Code
元安是一个零依赖的跨智能体安全扫描引擎.
How to install Yotta Security Audit
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open YottaMeta/yotta-security-audit and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Yotta Security Audit does
元安是一个零依赖的跨智能体安全扫描引擎。它内置 13 类规则,专门检测 AI 技能中的恶意模式——供应链投毒、提示注入、危险命令、越权访问等,并提供 Windows / Linux 双平台系统安全基线检查(纯只读,绝不执行修复)。它能自动发现技能目录,生成文本 / JSON / Markdown 三种报告(默认脱敏)。它只检测与报告,绝不擅自删除、修复或查杀——让「把第三方技能装进任何智能体」这件事,变成一道可审计的安检门。
Alternatives in Security
- Pal — Multi-model AI integration — chat, debugging, code review, planning, security audit 11.3k ★
- Skills — Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows 4k ★
- /web3 Audit — Smart contract security audit using the 10-bug-class methodology 927 ★
README
Language: English · 中文
yotta-security-audit · 元安 (Yuan'an)
YottaMeta's AI-skill supply-chain & system security scan engine: detects malicious skill patterns · scans system security baselines, purely read-only, zero-dependency and disciplined. Use it before installing a new skill, for periodic audits of installed skills, or to check system security baselines — wherever correctness and safety matter.
Activates when the user mentions security audit / skill security check / malicious detection / supply-chain security / system security baseline / scan skills / supply chain / malicious skill, or asks to scan a skill; running it before installing any new skill is recommended — judged by the target, not keyword luck.
Python 3.8+ standard library, zero external dependencies; Windows + Linux; read-only detection, reports masked by default, with authorization & legal boundaries declared.
Safely audit and quarantine Orca-installed agent skills, hooks, and CLI residue on Windows, macOS, and Linux. Per-project Claude Code cost from local transcripts (token usage x API list prices). Read-only; cross-platform YuanCe (元测) — disciplined authorization-first security-testing methodology for AI agents: four-stage web secur Compile findings into markdown security assessment report Open-source security for AI agents: kernel-enforced egress control on macOS and Linux, keys only the operator Read-only audit of a local developer machine for AI-agent-related security risks (Linux + macOS). Ten modules Defensive security and hardening specialist. Creates detection rules, hardens Linux/Windows systems, writes Si BYOK (Bring-Your-Own-Key) and OAuth token security expert. Deep on cross-platform OS keychain integration (mac Use this agent when packaging fails or needs changes — yarn build:package:windows mac linux, PyInstaller error
Related Skills
Orca Agent Cleanup
Security community
Cost Audit
Security community
Yotta Security Testing
Security community
Report
Security community
Sanctuary Framework
Security community
AI Agent Audit
Security community
Related Agents
Blue Team
Security community
Byok Token Security Expert
Security community
Packager Troubleshooter
Development community