claude-security-audit
Run a multi-phase code security audit and produce reports, SARIF, and an SBOM.
Run a multi-phase code security audit and produce reports, SARIF, and an SBOM.
The skill maps a repository’s technologies and attack surfaces, runs a bundled set of SAST, dependency, secret, container, and infrastructure scanners, then performs parallel deep dives into areas such as authorization, injection, supply chain, and agentic risks. It emits Markdown, SARIF, CycloneDX, and a reusable baseline, supports Claude Code only, and is best run inside an isolated container.
Resource types
Use cases
Platforms
Runtime
Audit suspension risks in a Claude Code working environment.
Check whether a specific CVE actually applies to your environment.
Capabilities
Public GitHub facts last synced Jul 10, 2026.
Store and inject development secrets through 1Password from Claude Code.
Audit a deployed public app for production gaps missed during coding.