By shaxbozaka
Use when auditing a web app for security vulnerabilities. Handles both internal audits (sitting in your own codebase, filesystem access) and external audits (only URL + written authorization). Context-detects which mode and applies the right checklist. Contains a source-code audit checklist (auth bugs, IDOR, SSRF, injection, crypto misuse, file handling, rate-limits, Docker config), a black-box probing checklist (subdomain enum, port scan, TLS/DNS, admin-panel leakage, error-shape oracles, version fingerprint), a server/infra sweep (management ports, cloud metadata, CDN bypass, backup files, container image CVEs), a rate-limit deep-dive (distributed-counter vs in-memory, XFF trust, cost-inflation DoS), and — after you have findings — advisory writing via gh api and patch delivery when the temporary private fork is gated.
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
A Claude Code skill + plugin marketplace for auditing web apps for security vulnerabilities — whether on your own codebase (defensive audit before you ship) or on a project you have written authorization to audit (GHSA collaborator, bug-bounty scope, CTF engagement).
What Claude does with it:
/health).express-rate-limit's in-memory default, Better-Auth's "memory" storage default, Django's LocMemCache, XFF trust).gh api advisory workflow, patch delivery when the GHSA temporary private fork is gated to the maintainer./plugin marketplace add shaxbozaka/security-audit
/plugin install security-audit@security-audit
After install the skill appears in the registry and activates automatically when a prompt matches the trigger description.
mkdir -p ~/.claude/skills
git clone https://github.com/shaxbozaka/security-audit ~/.claude/skills/security-audit
Restart Claude Code. The skill now lives at ~/.claude/skills/security-audit/SKILL.md and Claude picks it up at session start.
The description frontmatter triggers on any of:
It's also invokable by name — just ask Claude to "use the security-audit skill."
.claude-plugin/marketplace.json # plugin metadata
SKILL.md # core runbook
references/
poc-templates.md # 14 reusable probe snippets:
# 1 auth bootstrap
# 2 snapshot probe (living-target)
# 3 rate-limit posture measurement
# 3b distributed-counter smoke test
# 3c X-Forwarded-For bypass test
# 3d cost-inflation probe
# 4 SSRF error-shape oracle +
# version fingerprint via SSRF
# 5 sanitiser-bypass harness (JSDOM strict)
# 6 security-headers audit
# 7 advisory edit loop (gh api)
# 8 patch-set export for advisory inlining
# 9 cleanup rituals
# 10 server port sweep
# 11 TLS configuration audit
# 12 DNS / subdomain takeover
# 13 origin IP discovery (CDN bypass)
# 14 cloud metadata via SSRF
source-audit-patterns.md # deep ripgrep recipes for INSIDE mode:
# auth, IDOR, SSRF, injection, XSS,
# file handling, crypto, races,
# rate-limit framework specifics,
# CORS/CSRF, Docker/CI, secrets,
# logic bugs grep can't find
README.md
LICENSE # MIT
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimnpx claudepluginhub shaxbozaka/security-audit --plugin security-auditAI-native recruiting platform. Search jobs, manage applications, check AI interview assessments, schedule meetings, rate employers, post jobs, search candidates, and get hiring market insights.
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
A growing collection of Claude-compatible academic workflow bundles. Covers scientific figures, manuscript writing and polishing, reviewer assessment, citation retrieval, data availability, paper reading, literature search, response letters, paper-to-PPTX conversion, and evidence-grounded Chinese invention patent drafting. Rules are organized as reusable skill folders with explicit workflows and quality checks.
v9.44.1 — Patch release for Gemini environment/version detection and qwen auth gating. Run /octo:setup.
Harness-native ECC operator layer - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses
UI/UX design intelligence. 67 styles, 161 palettes, 57 font pairings, 25 charts, 15 stacks (React, Next.js, Vue, Svelte, Astro, SwiftUI, React Native, Flutter, Tailwind, shadcn/ui, Nuxt, Jetpack Compose). Actions: plan, build, create, design, implement, review, fix, improve, optimize, enhance, refactor, check UI/UX code. Projects: website, landing page, dashboard, admin panel, e-commerce, SaaS, portfolio, blog, mobile app. Elements: button, modal, navbar, sidebar, card, table, form, chart. Styles: glassmorphism, claymorphism, minimalism, brutalism, neumorphism, bento grid, dark mode, responsive, skeuomorphism, flat design. Topics: color palette, accessibility, animation, layout, typography, font pairing, spacing, hover, shadow, gradient.
This skill should be used when users need to generate ideas, explore creative solutions, or systematically brainstorm approaches to problems. Use when users request help with ideation, content planning, product features, marketing campaigns, strategic planning, creative writing, or any task requiring structured idea generation. The skill provides 30+ research-validated prompt patterns across 14 categories with exact templates, success metrics, and domain-specific applications.