
from claude-code280
Run on-demand security, dependency and code-quality audits to find vulnerabilities, exposed secrets, and maintainability issues.
The Audit skill performs comprehensive on-demand security and code-quality scans across a codebase. It combines static analysis, dependency checks, secret scanning, and simple metrics (complexity, duplication, LOC) to produce a prioritized report of Critical/High/Medium/Low findings and remediation guidance.
Use before deployments, during security reviews, or as a CI check: run a full audit (OWASP-focused), dependency-only scans, secret-only scans, or targeted audits for specific directories or files. Ideal for pre-release checks and triaging technical debt.
This skill is authoring-agnostic but maps well to developer-focused agents and code-analysis plugins (Claude Code, Codex-style assistants, GitHub Actions integrations).
This skill has not been reviewed by our automated audit pipeline yet.