| name | skill-security-auditor |
| description | Security audit and vulnerability scanner for AI agent skills before installation. Use when: (1) evaluating a skill from an untrusted source, (2) auditing a skill directory or git repo URL for malicious code, (3) pre-install security gate for Claude Code plugins, OpenClaw skills, or Codex skills, (4) scanning Python scripts for dangerous patterns like os.system, eval, subprocess, network exfiltration, (5) detecting prompt injection in SKILL.md files, (6) checking dependency supply chain risks, (7) verifying file system access stays within skill boundaries. Triggers: \"audit this skill\", \"is this skill safe\", \"scan skill for security\", \"check skill before install\", \"skill security check\", \"skill vulnerability scan\". |
| zh_description | 用于技能、安全、审计,支持安全扫描、审计、加固和风险治理。 |
| version | 1.0.4 |
| author | seaworld008 |
| source | github:alirezarezvani/claude-skills |
| source_url | |
| license | MIT |
| tags | ["auditor", "security", "skill"] |
| created_at | 2026-03-27 |
| updated_at | 2026-06-16 |
| quality | 4 |
| complexity | intermediate |
Skill Security Auditor
Scan and audit AI agent skills for security risks before installation. Produces a
clear PASS / WARN / FAIL verdict with findings and remediation guidance.
Quick Start
python3 scripts/skill_security_auditor.py /path/to/skill-name/
python3 scripts/skill_security_auditor.py https://github.com/user/repo --skill skill-name
python3 scripts/skill_security_auditor.py /path/to/skill-name/ --strict
python3 scripts/skill_security_auditor.py /path/to/skill-name/ --json
What Gets Scanned
1. Code Execution Risks (Python/Bash Scripts)
Scans all .py, .sh, .bash, .js, .ts files for:
| Category | Patterns Detected | Severity |
|---|
| Command injection | os.system(), os.popen(), subprocess.call(shell=True), backtick execution | 🔴 CRITICAL |
| Code execution | eval(), exec(), compile(), __import__() | 🔴 CRITICAL |
| Obfuscation | base64-encoded payloads, codecs.decode, hex-encoded strings, chr() chains | 🔴 CRITICAL |
| Network exfiltration | requests.post(), urllib.request, socket.connect(), httpx, aiohttp | 🔴 CRITICAL |
| Credential harvesting | reads from ~/.ssh, ~/.aws, ~/.config, env var extraction patterns | 🔴 CRITICAL |
| File system abuse | writes outside skill dir, /etc/, , , symlink creation |