Home / eigent-ai / eigent · resources/example-skills/skill-security-auditor/SKILL.md · GitHub

skill-security-auditor skillA

skill-security-auditor is agent-read markdown (skill) from eigent-ai/eigent: Security auditing for code, configs, and infrastructure. Use when the user wants to audit or improve security: scan for vulnerabilities (SQL injection, XSS, command injection, path traversal), detect hardcoded secrets and credentials, review auth and authorization, check dependencies for known CVEs, audit config files for insecure defaults, or generate security reports. Trigger on "security audit", "vulnerability scan", "code review for security", "find secrets", "check for vulnerabilities", "OW.

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

# Security Auditor Guide

## Overview

This guide covers security auditing workflows for source code, dependencies, and configurations. For detailed vulnerability patterns and detection rules, see references/vulnerability-patterns.md. For secrets detection patterns, see references/secrets-patterns.md.

## Quick Start

Run the bundled scan script against a project directory:

```bash
python scripts/scan_project.py /path/to/project
```

This performs a lightweight scan for common issues: hardcoded secrets, dangerous function calls, and insecure patterns. For deeper analysis, follow the workflows below.

### Testing the scripts

```bash
python scripts/scan_project.py /path/to/some/project --format text
python scripts/scan_secrets.py /path/to/some/project --format text
```

## Audit Workflow

### 1. Reconnaissance

Before auditing, understand the project:

```bash
# Identify languages, frameworks, and entry points
find . -type f -name "*.py" -o -name "*.js" -o -name "*.ts" -o -name "*.go" -o -name "*.java" | head -20
cat package.json pyproject.toml requirements.txt go.mod pom.xml 2>/dev/null
```

Key questions:
- What frameworks are used? (Express, Django, Flask, Spring, etc.)
…

Read the whole file at its exact version.

How to install

Latest version
mdr add eigent-ai/eigent/skill-security-auditor@git:20260318.31828e6
Exact content
mdr add eigent-ai/eigent/skill-security-auditor@sha256:8fb34b36db5e52c1

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_whtty7sraqvitejj.svg)](https://markdownregistry.com/a/art_whtty7sraqvitejj)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260318.31828e6 latest2026-03-18 31828e6 7,215 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (7215 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

eigent-ai/eigent · 15,412 stars · license Apache-2.0 · pushed 2026-09-24 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_whtty7sraqvitejj
GET https://markdownregistry.com/api/v1/resolve?ref=eigent-ai/eigent/skill-security-auditor
GET https://markdownregistry.com/api/v1/blob/8fb34b36db5e52c1973b019c652bfb85d8aaaa7b73ae09e352e636cc6619115f

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from eigent-ai/eigent

AGENTS.md agents
eigent-ai/eigent · AGENTS.md
git:20260828.59f43af · audit A · 15,412 stars
docx skill
eigent-ai/eigent · resources/example-skills/docx/SKILL.md · Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files). Triggers…
git:20260226.343050b · audit A · 15,412 stars
pdf skill
eigent-ai/eigent · resources/example-skills/pdf/SKILL.md · Use this skill whenever the user wants to do anything with PDF files. This includes reading or extracting text/tables…
git:20260226.343050b · audit A · 15,412 stars
pptx skill
eigent-ai/eigent · resources/example-skills/pptx/SKILL.md · Use this skill any time a .pptx file is involved in any way — as input, output, or both. This includes: creating slide…
git:20260318.14139d7 · audit A · 15,412 stars
skill-creator skill
eigent-ai/eigent · resources/example-skills/skill-creator/SKILL.md · Guide for creating effective skills. Use when creating a new skill or updating an existing skill that extends agent…
git:20260318.14139d7 · audit A · 15,412 stars
xlsx skill
eigent-ai/eigent · resources/example-skills/xlsx/SKILL.md · Use this skill any time a spreadsheet file is the primary input or output. This means any task where the user wants to…
git:20260226.343050b · audit A · 15,412 stars

Every file in eigent-ai/eigent

Other files named skill-security-auditor

skill-security-auditor skill
borghei/claude-skills · engineering/skill-security-auditor/SKILL.md · Security audit and vulnerability scanning for AI agent skills before install. Detects prompt injection, dangerous code…
v1.1.0 · audit A · 821 stars

Browse by kind, by grade A, or by owner.