Skip to content
appsgit

Security Audit

Security Audit is an agent skill (a SKILL.md file) from staruhub/ClaudeSkills. 全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描. It works with Claude Code and has 727 GitHub stars. Install it by copying the skill folder into your agent's skills directory.

github.com/staruhub/ClaudeSkills/skills/Geek-skills-security-audit (opens in a new tab)

Add this skill

Claude

Claude Code loads skills from ~/.claude/skills/ (all projects) or .claude/skills/ (one project):

git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git
cp -r ClaudeSkills/skills/Geek-skills-security-audit ~/.claude/skills/security-audit   # personal, or .claude/skills in a project

In the Claude apps, zip the security-audit folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

ChatGPT / Codex

Codex reads skills from .agents/skills/ in a repo or ~/.agents/skills/ for every project:

git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git
cp -r ClaudeSkills/skills/Geek-skills-security-audit .agents/skills/security-audit   # repo; ~/.agents/skills for all projects

Standalone skills also load in the ChatGPT desktop app.

Cursor

Cursor loads skills from .cursor/skills/ (or ~/.cursor/skills/) and also reads .claude/skills/:

git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git
cp -r ClaudeSkills/skills/Geek-skills-security-audit .cursor/skills/security-audit   # project; ~/.cursor/skills for all projects

Source (checked Oct 7, 2026): code.claude.com/docs/en/skills (opens in a new tab), support.claude.com/en/articles/12512180-using-skills-in-claude (opens in a new tab), learn.chatgpt.com/docs/build-skills (opens in a new tab), cursor.com/docs/context/skills (opens in a new tab)

What this skill does

全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 - Docker镜像和Kubernetes配置审计,(6) CI/CD安全检查。触发关键词:"安全检查"、"漏洞扫描"、"代码审计"、"security audit"、"vulnerability scan"、"SAST"、"dependency check"、"CVE检测"等。不用于:修复单个已定位的bug、编写新的安全功能代码、对无授权的第三方系统做扫描或渗透测试。 本文件不维护具体CVE清单。凡涉及"某版本是否有漏洞"的结论,必须现场查询: 用 web search 查 [框架/库名] CVE advisory [当前年份],或查官方 security advisory 页面。 正文中出现的具体CVE(如…

When it triggers

  • "安全检查"
  • "漏洞扫描"
  • "代码审计"
  • "security audit"
  • "vulnerability scan"
  • "SAST"
  • "dependency check"
  • "CVE检测"

FAQ

Security Audit FAQ

Still curious? Email info@appsgit.com.

What is the Security Audit skill?

Security Audit is an agent skill (a SKILL.md file) from staruhub/ClaudeSkills. 全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描. It works with Claude Code and has 727 GitHub stars. Install it by copying the skill folder into your agent's skills directory. Its SKILL.md lives at github.com/staruhub/ClaudeSkills/skills/Geek-skills-security-audit.

How do I install the Security Audit skill?

Copy the security-audit folder (the one containing SKILL.md) into ~/.claude/skills/ for Claude Code, .agents/skills/ for Codex or .cursor/skills/ for Cursor. The agent picks it up automatically when a task matches its description.

Is the Security Audit skill free?

Yes. The repository is open source under the MIT license.

Is Security Audit maintained?

The repository's most recent commit was on Aug 12, 2026. Its latest release is 1.0.1. appsgit only lists skills from repositories with a commit in the last six months.