From claude-code-toolkit
Performs security audit of codebase for dependency vulnerabilities, secrets, OWASP Top 10, input validation, auth issues, and misconfigs. Outputs findings report by severity with fixes and references.
npx claudepluginhub rohitg00/awesome-claude-code-toolkitsecurity/Perform a security audit of the codebase covering common vulnerability categories. ## Steps ### 1. Dependency Vulnerabilities - Run the package manager's audit: `npm audit`, `pip audit`, `cargo audit`, `govulncheck ./...`. - List critical and high severity vulnerabilities. - For each, determine if the vulnerable code path is actually reachable in this project. - Recommend specific version upgrades or patches. ### 2. Secrets Scan - Search for hardcoded secrets, API keys, tokens, and passwords: - Patterns: `password\s*=`, `api[_-]?key`, `secret`, `token`, `Bearer `, base64-encoded string...
/auditLogs agent interactions (prompts, responses, tool calls) to append-only .beads/interactions.jsonl. Also supports labeling prior entries via record|label args.
/auditAudits UI code against design system for spacing, depth, color, and pattern violations. Reports file-specific issues and suggestions. Supports path argument or defaults to common UI paths.
/auditRuns Rust security audits (default) with cargo audit and geiger, or safety/concurrency/full modes using miri, rudra, lockbud. Outputs prioritized vulnerability reports and fix recommendations.
/auditAnalyzes iOS/Swift projects to suggest relevant audits or runs specified ones (e.g., memory, concurrency, accessibility, SwiftUI performance, security).
/auditPerforms security audit on codebase or specified target, checking dependency vulnerabilities, auth, input validation, data exposure, configs, and secrets. Outputs prioritized findings with remediation steps.
/auditPerforms security audit on codebase or specified target, checking dependency vulnerabilities, auth, input validation, data exposure, configs, and secrets. Outputs prioritized findings with remediation steps.
Perform a security audit of the codebase covering common vulnerability categories.
npm audit, pip audit, cargo audit, govulncheck ./....password\s*=, api[_-]?key, secret, token, Bearer , base64-encoded strings..env files committed to git, config files, source code..gitignore for proper exclusion of sensitive files.eval(), innerHTML.Produce a findings report organized by severity (Critical, High, Medium, Low, Info) with: