security-audit-skill — security grade SAFE, quality 72/100

Security audit verdict: SAFE · quality 72/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by cloudflare · Agent Tool · ★ 10.2k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is security-audit-skill safe to install? View the security audit →

About security-audit-skill

security-audit A coding-agent skill that turns your agent into a security auditor. It orchestrates isolated agents through reconnaissance, coverage-led hunting, candidate validation, structured output, independent record verification, and target-neutral reporting. This is the skill that seeded Cloudflare's vulnerability discovery harness, described in Build your own vulnerability harness. The harness grew into a multi-stage, fleet-wide system; this skill is the single-repo starting point it evolved from. What it does The skill runs a structured audit in six phases: Reconnaissance -- map architecture, trust boundaries, input surfaces, prior evidence, and deterministic coverage in and . Coverage-led hunting -- assign isolated hunters from ledger units, record their checks, and use coverage critics to find gaps. Candidate validation -- give every unique candidate to a fresh verifier that tries to disprove it. Structured output -- write , , and records to and validate them against . Independent record verification -- fresh agents verify final source claims. Material replacements receive another independent verifier.

Quick Facts

Stars10,187
Forks549
LanguageJavaScript
CategoryAgent Tool
LicenseMIT
Quality Score72.4870956637667/100
Open Issues30
Last Updated2026-09-14
Created2026-06-18
Platformsnode
Est. Tokens~11k

Compatible Skills

These tools work well together with security-audit-skill for enhanced workflows:

  • website-rebuild-skill — semantic(0.17)+complementary+same_lang+similar_pop+shared_platform (56%)
  • autoprompt-skill — semantic(0.16)+complementary+same_lang+similar_pop+shared_platform (55%)

security-audit-skill alternative? Top 6 similar tools

Looking for a security-audit-skill alternative? If you're comparing security-audit-skill with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • open-saas by wasp-lang · ⭐ 15.8k

    A 100% free modern JS SaaS boilerplate (React, NodeJS, Prisma). Full-featured: Auth (email, google, github, sl

  • notebooklm-skill by PleasePrompto · ⭐ 7.8k

    Use this skill to enable Claude Code to communicate directly with your Google NotebookLM notebooks. Query your

  • agent-skills by tech-leads-club · ⭐ 6.5k

    The secure, validated skill registry for professional AI coding agents. Extend Antigravity, Claude Code, Curso

  • excalidraw-diagram-skill by coleam00 · ⭐ 4.8k

    Skill to give Claude Code (and any coding agent) the ability to generate beautiful and practical Excalidraw di

  • raptor by gadievron · ⭐ 3.8k

    Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and

  • playwright-skill by lackeyjb · ⭐ 3.0k

    General-purpose Playwright automation for coding agents

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular JavaScript Agent Tools

Frequently Asked Questions

What is security-audit-skill?

security-audit-skill is A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings. It is categorized as a Agent Tool with 10.2k GitHub stars.

What programming language is security-audit-skill written in?

security-audit-skill is primarily written in JavaScript.

How do I install or use security-audit-skill?

You can find installation instructions and usage details in the security-audit-skill GitHub repository at github.com/cloudflare/security-audit-skill. The project has 10.2k stars and 549 forks, indicating an active community.

What license does security-audit-skill use?

security-audit-skill is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to security-audit-skill?

The top alternatives to security-audit-skill on Agent Skills Hub include open-saas, notebooklm-skill, agent-skills. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools