Security Audit

ruvnet/ruflo/.agents/skills/security-audit

by ruvnet6051f6702b61No license74K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today

Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment processing, user data handling, API endpoint creation, file upload handling, database queries, external API integration. Skip when: read-only operations on public data, internal development tooling, static documentation, styling changes.

Includes scriptsSecurity
AI-generated overview

Scans codebases for vulnerabilities such as injection flaws, path traversal, hardcoded secrets and known CVEs.

What it does
This skill runs security scanning and vulnerability detection over a codebase, covering input validation, path traversal, SQL injection, XSS, hardcoded secrets and dependency CVEs. It also supports threat modeling analysis and generating a full security audit report, optionally as markdown. It ships two executable scripts, one for a full scan pipeline and one for auto-remediating known CVEs.
When to use it
Use it when implementing authentication, authorization, payment processing, user data handling, API endpoints, file uploads, database queries or external API integrations. It is intended to be skipped for read-only operations on public data, internal development tooling, static documentation and styling changes.
Requirements
Requires the npx command and the @claude-flow/cli package, which is fetched over the network. It ships two executable scripts, security-scan.sh and cve-remediate.sh, and references documentation files docs/security-checklist.md and docs/owasp-top10.md.

Security Audit Skill

Purpose

Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement.

When to Trigger

  • authentication implementation
  • authorization logic
  • payment processing
  • user data handling
  • API endpoint creation
  • file upload handling
  • database queries
  • external API integration

When to Skip

  • read-only operations on public data
  • internal development tooling
  • static documentation
  • styling changes

Commands

Full Security Scan

Run comprehensive security analysis on the codebase

bash
npx @claude-flow/cli security scan --depth full

Example:

bash
npx @claude-flow/cli security scan --depth full --output security-report.json

Input Validation Check

Check for input validation issues

bash
npx @claude-flow/cli security scan --check input-validation

Example:

bash
npx @claude-flow/cli security scan --check input-validation --path ./src/api

Path Traversal Check

Check for path traversal vulnerabilities

bash
npx @claude-flow/cli security scan --check path-traversal

SQL Injection Check

Check for SQL injection vulnerabilities

bash
npx @claude-flow/cli security scan --check sql-injection

XSS Check

Check for cross-site scripting vulnerabilities

bash
npx @claude-flow/cli security scan --check xss

CVE Scan

Scan dependencies for known CVEs

bash
npx @claude-flow/cli security cve --scan

Example:

bash
npx @claude-flow/cli security cve --scan --severity high

Security Audit Report

Generate full security audit report

bash
npx @claude-flow/cli security audit --report

Example:

bash
npx @claude-flow/cli security audit --report --format markdown --output SECURITY.md

Threat Modeling

Run threat modeling analysis

bash
npx @claude-flow/cli security threats --analyze

Validate Secrets

Check for hardcoded secrets

bash
npx @claude-flow/cli security validate --check secrets

Scripts

ScriptPathDescription
security-scan.agents/scripts/security-scan.shRun full security scan pipeline
cve-remediate.agents/scripts/cve-remediate.shAuto-remediate known CVEs

References

DocumentPathDescription
Security Checklistdocs/security-checklist.mdSecurity review checklist
OWASP Guidedocs/owasp-top10.mdOWASP Top 10 mitigation guide

Best Practices

  1. Check memory for existing patterns before starting
  2. Use hierarchical topology for coordination
  3. Store successful patterns after completion
  4. Document any new learnings

Source and attribution

Source:ruvnet/rufloin.agents/skills/security-auditat commit6051f67

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

Security Audit · .agents/skills/security-audit Agent Skill | SourceWeft