Skill Security Auditor v2
Run a hybrid security audit before installing a skill or deploying code. Return a clear PASS / WARN / FAIL verdict with concrete findings and remediation.
Use
Audit a local path
python3 scripts/security_auditor_v2.py /path/to/target
Audit a git repo
python3 scripts/security_auditor_v2.py https://github.com/org/repo
JSON output
python3 scripts/security_auditor_v2.py /path/to/target --json
Strict mode
python3 scripts/security_auditor_v2.py /path/to/target --strict
What it checks
Command execution risk
- shell execution
- eval/exec
- dynamic imports
child_process/ subprocess misuse
Prompt injection risk
- instruction override attempts
- role hijacking
- safety bypass language
- hidden directives
Data exfiltration risk
- outbound network writes
- credential harvesting patterns
- suspicious file access
Privilege and persistence risk
sudo- cron modification
- shell/profile tampering
- dangerous permissions
Filesystem safety
- writes outside expected scope
- destructive deletes
- symlinks
- hidden sensitive files
Dependency and secret risk
- suspicious install-at-runtime behavior
- unpinned deps
- likely secrets/tokens in repo
Optional deep scanners if installed
- Semgrep
- Bandit
- Gitleaks
- Trivy
Output contract
Always return:
- PASS: no meaningful issues found
- WARN: review required, but likely safe after inspection
- FAIL: unsafe to install/use as-is
For each finding include:
- severity
- category
- file and line when possible
- why it matters
- how to fix it
Hard rules
- Treat third-party skills as untrusted until scanned
- Never auto-approve a FAIL result
- For WARN, explain why it is likely safe or why manual review is needed
- Distinguish live executable risk from documentation/examples
- Prefer fewer high-confidence findings over noisy output
Optional deeper tools
If available on the machine, the script will automatically use:
semgrepbanditgitleakstrivy
If missing, the script still works with the native scanner only.
References
- Read
references/risk-model.mdwhen tuning findings or reviewing gray-area cases.