code-vuln-audit
Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection
Install / Use
npx skills add zebbern/claude-code-guide --skill code-vuln-auditInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of code-vuln-audit
code-vuln-audit scores 89/100 on our quality scale, 434th of 775 Security skills we index.
Its SKILL.md is 5.2 KB long, well organised into 18 sections with 3 code examples: a solid amount of guidance for an agent.
With 4,638 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 2 days ago, so code-vuln-audit is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
code-vuln-audit compared with similar skills
All 4 of these similar skills score higher than code-vuln-audit; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| code-vuln-audit (this skill)by zebbern | 89 | 4.6k | 2d ago | SKILL.md |
| claude-memby thedotmack | 100 | 94.8k | today | CLAUDE.md |
| Agent-Reachby Panniantong | 100 | 85.9k | 13d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.0k | 1d ago | CLAUDE.md |
| crawl4aiby unclecode | 100 | 84.4k | 3d ago | MCP Server |
Frequently asked questions
- How do I install code-vuln-audit?
- Run
npx skills add zebbern/claude-code-guide --skill code-vuln-audit. The install tabs above show the steps for each supported agent. - Which AI agents does code-vuln-audit work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is code-vuln-audit safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is code-vuln-audit still maintained?
- The repository was last updated 2 days ago, so code-vuln-audit is actively maintained.
Skill content
View source on GitHubname: code-vuln-audit description: "Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection. Use when the user mentions security scans, vulnerability detection, secret leaks, API keys, OWASP, npm audit, pip-audit, hardcoded passwords, or code security checks." license: MIT
code-vuln-audit
A code security scanning tool with three core scanning capabilities:
- Dependency Vulnerability Scanning — Automatically detects known vulnerabilities in npm / pip dependencies
- Secret Leak Detection — Discovers hardcoded secrets, tokens, and passwords via regex matching + Shannon entropy analysis
- OWASP Pattern Detection — Identifies common security anti-patterns such as SQL injection, XSS, command injection, and insecure deserialization
Quick Start
# Scan the current directory (all checks)
python3 scripts/security_scan.py .
# Scan dependencies only
python3 scripts/security_scan.py --mode deps .
# Detect secret leaks only
python3 scripts/security_scan.py --mode secrets /path/to/project
# Detect OWASP security patterns only
python3 scripts/security_scan.py --mode owasp .
# Output report in JSON format
python3 scripts/security_scan.py --format json --output report.json .
# Only show findings at high severity and above
python3 scripts/security_scan.py --severity high .
Scan Module Details
1. Dependency Vulnerability Scanning (deps)
Automatically detects the project type and invokes the appropriate tool:
| Project Type | Detection File | Tool Used |
|---|---|---|
| Node.js | package.json + package-lock.json | npm audit |
| Python | requirements.txt / pyproject.toml / Pipfile | pip-audit |
If the corresponding audit tool is not installed, a helpful message is displayed instead of an error.
2. Secret Leak Detection (secrets)
Detection is performed in two ways:
Regex Matching: Covers common secret formats
| Secret Type | Example Pattern |
|---|---|
| AWS Access Key | 20-character string starting with AKIA |
| GitHub Token | Starts with ghp_ or github_pat_ |
| Slack Token | Starts with xoxb- or xoxp- |
| Stripe Key | Starts with sk_live_ or pk_live_ |
| Private Key File | -----BEGIN PRIVATE KEY----- |
| Generic API Key | Format like api_key = "..." |
| Credentials in URL | https://user:pass@host |
| JWT Token | eyJ... format |
Shannon Entropy Analysis: Computes information entropy for string constants in code (threshold > 4.5 and length >= 20) to discover secrets in non-standard formats.
3. OWASP Pattern Detection (owasp)
Covers statically detectable security patterns from the OWASP Top 10:
| OWASP Category | Detection Patterns | |---|---| | A02: Cryptographic Failures | Weak hashes (MD5/SHA1), weak ciphers (DES/RC4) | | A03: Injection | SQL injection, command injection (os.system / subprocess shell / eval / exec), XSS (innerHTML / document.write / dangerouslySetInnerHTML / v-html) | | A04: Insecure Design | Path traversal | | A05: Security Misconfiguration | Debug mode enabled, CORS wildcard, binding to 0.0.0.0 | | A08: Integrity Failures | Insecure deserialization (pickle / yaml.load / marshal / unserialize) | | A10: SSRF | User input passed directly to HTTP requests |
Supported languages: Python, JavaScript/TypeScript, Java, PHP, Ruby, Go, and more.
Parameters
| Parameter | Description | Default |
|---|---|---|
| TARGET | Directory to scan | Current directory |
| --mode MODE | Scan mode: all, deps, secrets, owasp | all |
| --format FORMAT | Output format: text, json | text |
| --output FILE | Output file path | stdout |
| --severity LEVEL | Minimum reporting level: low, medium, high, critical | low |
| --exclude-dir DIR | Additional directories to exclude (repeatable) | - |
| --max-file-kb SIZE | Maximum file size to scan in KB | 512 |
| -h, --help | Show help | - |
Output Format
Text Output (default)
=== Security Scan Report ===
Target: /path/to/project
Modules: deps, secrets, owasp
[CRITICAL] AWS Access Key ID
File: src/config.py:15
Code: AWS_KEY = "AKIA…[redacted]"
[HIGH] SQL Injection (f-string)
File: src/db.py:42
Code: cursor.execute(f"SELECT * FROM users WHERE id={user_id}")
--- Summary ---
Critical: 1 | High: 1 | Medium: 0 | Low: 0
Total findings: 2
JSON Output
{
"target": "/path/to/project",
"scan_time": "2026-04-14T10:30:00",
"findings": [
{
"scanner": "secrets",
"name": "AWS Access Key ID",
"severity": "critical",
"file": "src/config.py",
"line": 15,
"snippet": "AWS_KEY = \"AKIA…[redacted]\"",
"category": "secret-pattern"
}
],
"summary": {"critical": 1, "high": 0, "medium": 0, "low": 0, "total": 1}
}
Exit Codes
| Exit Code | Meaning |
|---|---|
| 0 | No findings |
| 1 | Findings present (at least one security issue) |
| 2 | Scanner internal error |
Prerequisites
- Python 3.7+ (uses standard library only)
- Dependency scanning requires the corresponding tools:
npm(for Node.js projects),pip-audit(for Python projects) - If an audit tool is missing, that module will be skipped with a notice — other modules continue to run normally
Related Skills
claude-mem
94.8kPersistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Agent-Reach
85.9kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.0kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
crawl4ai
84.4kOpen-source web crawler and scraper for LLMs and AI agents: any website into clean, LLM-ready Markdown. Run it yourself, or use Crawl4AI Cloud with one key.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
