# Security Audit (agent skill)

> Security Audit is an agent skill (a SKILL.md file) from staruhub/ClaudeSkills. 全面的代码安全检查和服务器安全审计skill。适用于：(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞，(2) 依赖安全检查 - 识别过时或有漏洞的第三方库，结合实时搜索确认最新CVE，(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置，(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测，(5) 容器安全扫描. It works with Claude Code and has 727 GitHub stars. Install it by copying the skill folder into your agent's skills directory.

全面的代码安全检查和服务器安全审计skill。适用于：(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞，(2) 依赖安全检查 - 识别过时或有漏洞的第三方库，结合实时搜索确认最新CVE，(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置，(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测，(5) 容器安全扫描 - Docker镜像和Kubernetes配置审计，(6) CI/CD安全检查。触发关键词："安全检查"、"漏洞扫描"、"代码审计"、"security audit"、"vulnerability scan"、"SAST"、"dependency check"、"CVE检测"等。不用于：修复单个已定位的bug、编写新的安全功能代码、对无授权的第三方系统做扫描或渗透测试。 本文件不维护具体CVE清单。凡涉及"某版本是否有漏洞"的结论，必须现场查询： 用 web search 查 [框架/库名] CVE advisory [当前年份]，或查官方 security advisory 页面。 正文中出现的具体CVE（如…

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/staruhub/ClaudeSkills |
| Skill path | skills/Geek-skills-security-audit/SKILL.md |
| Skill name | security-audit |
| GitHub stars | 727 |
| Installs on skills.sh | not listed |
| License | MIT |
| Skills in repo | 1 |
| Plugin marketplace | no |
| Official | no |
| Works with | Claude Code |
| Category | Security |
| Last commit | Aug 12, 2026 |

## When it triggers

- "安全检查"
- "漏洞扫描"
- "代码审计"
- "security audit"
- "vulnerability scan"
- "SAST"
- "dependency check"
- "CVE检测"

## Add this skill

### Claude Code

```sh
git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git
cp -r ClaudeSkills/skills/Geek-skills-security-audit ~/.claude/skills/security-audit   # personal, or .claude/skills in a project
```

In the Claude apps, zip the skill folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

### ChatGPT / Codex

```sh
git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git
cp -r ClaudeSkills/skills/Geek-skills-security-audit .agents/skills/security-audit   # repo; ~/.agents/skills for all projects
```

### Cursor

```sh
git clone --depth 1 https://github.com/staruhub/ClaudeSkills.git
cp -r ClaudeSkills/skills/Geek-skills-security-audit .cursor/skills/security-audit   # project; ~/.cursor/skills for all projects
```

Sources (checked 2026-10-07): https://code.claude.com/docs/en/skills, https://support.claude.com/en/articles/12512180-using-skills-in-claude, https://learn.chatgpt.com/docs/build-skills, https://cursor.com/docs/context/skills

---

Canonical page: https://appsgit.com/skills/staruhub-security-audit
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
