Questions? hello@viberation.devGet supportBlogDocsChangelog
Get started

Security Audit

Find, verify and prioritise vulnerabilities in your code.

Cloudflare's security audit skill. Your agent finds vulnerabilities grounded in the source code, validates and prioritises them, and describes the fixes, for web apps, APIs, services and libraries.

Install this skill

npx skills add https://github.com/cloudflare/security-audit-skill --skill security-audit

Runs the open-source skills CLI in your own terminal. It asks which agents to add the skill to. Read what it tells your agent to do before you install it.

Install for your agent

  • Claude Code

    Run this in your project

    npx skills add https://github.com/cloudflare/security-audit-skill --skill security-audit -a claude-code

    Add -g to install it for every project instead.

    Or ask Claude Code to do it

    Install the "security-audit" skill from https://github.com/cloudflare/security-audit-skill for Claude Code.
    Copy the skill folder (the one containing SKILL.md, with any scripts or reference files next to it) into .claude/skills/ in this project.
    Before copying, show me the SKILL.md and list any scripts it includes, and wait for me to confirm.

    Or copy the folder yourself

    Unzip the download into .claude/skills/ for this project, or ~/.claude/skills/ for all your projects.

    Picked up in the current session, no restart needed.

    Claude Code skills docs
  • Claude.ai

    Upload the ZIP

    1. In Settings > Capabilities, turn on Code execution and file creation.
    2. Go to Customize > Skills, press +, then Create skill.
    3. Choose Upload a skill and pick the ZIP you downloaded.

    Free, Pro and Max plans. On Team and Enterprise, an owner turns skills on in Organization settings first.

    Claude.ai skills docs
  • ChatGPT

    Upload the ZIP

    1. Open Skills in ChatGPT and select Create.
    2. Select Upload from your computer and pick the ZIP you downloaded.
    3. Wait for ChatGPT's safety scan. A skill marked Needs Review asks you to check it before use.

    Skills that rely on scripts or a terminal may not work unchanged in ChatGPT.

    ChatGPT skills docs
  • Codex

    Run this in your project

    npx skills add https://github.com/cloudflare/security-audit-skill --skill security-audit -a codex

    Add -g to install it for every project instead.

    Or ask Codex to do it

    Install the "security-audit" skill from https://github.com/cloudflare/security-audit-skill for Codex.
    Copy the skill folder (the one containing SKILL.md, with any scripts or reference files next to it) into .agents/skills/ in this project.
    Before copying, show me the SKILL.md and list any scripts it includes, and wait for me to confirm.

    Or copy the folder yourself

    Unzip the download into .agents/skills/ for this project, or ~/.agents/skills/ for all your projects.

    Restart Codex if the skill does not show up.

    Codex skills docs
  • Cursor

    Run this in your project

    npx skills add https://github.com/cloudflare/security-audit-skill --skill security-audit -a cursor

    Add -g to install it for every project instead.

    Or ask Cursor to do it

    Install the "security-audit" skill from https://github.com/cloudflare/security-audit-skill for Cursor.
    Copy the skill folder (the one containing SKILL.md, with any scripts or reference files next to it) into .cursor/skills/ in this project.
    Before copying, show me the SKILL.md and list any scripts it includes, and wait for me to confirm.

    Or copy the folder yourself

    Unzip the download into .cursor/skills/ for this project, or ~/.cursor/skills/ for all your projects.

    Run it by typing / and the skill name in chat.

    Cursor skills docs
  • GitHub Copilot

    Run this in your project

    npx skills add https://github.com/cloudflare/security-audit-skill --skill security-audit -a github-copilot

    Add -g to install it for every project instead.

    Or ask GitHub Copilot to do it

    Install the "security-audit" skill from https://github.com/cloudflare/security-audit-skill for GitHub Copilot.
    Copy the skill folder (the one containing SKILL.md, with any scripts or reference files next to it) into .github/skills/ in this project.
    Before copying, show me the SKILL.md and list any scripts it includes, and wait for me to confirm.

    Or copy the folder yourself

    Unzip the download into .github/skills/ for this project, or ~/.copilot/skills/ for all your projects.

    Works in Copilot CLI, the cloud agent and agent mode in VS Code and JetBrains.

    GitHub Copilot skills docs
  • Antigravity

    Run this in your project

    npx skills add https://github.com/cloudflare/security-audit-skill --skill security-audit -a antigravity

    Add -g to install it for every project instead.

    Or ask Antigravity to do it

    Install the "security-audit" skill from https://github.com/cloudflare/security-audit-skill for Antigravity.
    Copy the skill folder (the one containing SKILL.md, with any scripts or reference files next to it) into .agents/skills/ in this project.
    Before copying, show me the SKILL.md and list any scripts it includes, and wait for me to confirm.

    Or copy the folder yourself

    Unzip the download into .agents/skills/ for this project, or ~/.gemini/config/skills/ for all your projects.

    Antigravity skills docs
  • Gemini CLI

    Run this in your project

    npx skills add https://github.com/cloudflare/security-audit-skill --skill security-audit -a gemini-cli

    Add -g to install it for every project instead.

    Or ask Gemini CLI to do it

    Install the "security-audit" skill from https://github.com/cloudflare/security-audit-skill for Gemini CLI.
    Copy the skill folder (the one containing SKILL.md, with any scripts or reference files next to it) into .gemini/skills/ in this project.
    Before copying, show me the SKILL.md and list any scripts it includes, and wait for me to confirm.

    Or copy the folder yourself

    Unzip the download into .gemini/skills/ for this project, or ~/.gemini/skills/ for all your projects.

    Run /skills to check it was found.

    Gemini CLI skills docs
Installs
8.5K via skills.sh
Last updated
14 Sept 2026
Licence
MIT

Security checks

Run by independent scanners and published on skills.sh. Their results, not a Viberation review.

  • Gen Agent Trust Hub Pass

    This skill provides a comprehensive and rigorous framework for conducting security audits on codebases. It includes detailed modules for various attack classes and uses local validation scripts to ensure findings meet specific criteria. While it performs local command execution for validation and processes untrusted source code, these actions are performed within an intended security research workflow with emphasized isolation controls.

    15 Sept 2026
  • Socket Pass

    No alerts

    15 Sept 2026
  • Snyk Warning

    Risk: MEDIUM · 1 issue

    15 Sept 2026
What's inside (20 files)
  • AI-AND-LLM.md10.6K chars
  • ATTACK-CLASSES.md15.7K chars
  • CLIENT-SIDE.md8.6K chars
  • CLOUD-AND-DEPLOYMENT.md8.3K chars
  • DATA-ISOLATION-AND-LIFECYCLE.md7.8K chars
  • DESKTOP-MOBILE-AND-LOCAL-IPC.md8.7K chars
  • HUNTING.md22.4K chars
  • MEMORY-SAFETY-AND-BINARY.md10.5K chars
  • PROTOCOLS-RPC-AND-MESSAGING.md7.5K chars
  • RECONNAISSANCE.md15.9K chars
  • report-schema.json14.5K chars
  • RESOURCE-EXHAUSTION-AND-AVAILABILITY.md7.5K chars
  • SKILL.md22K chars
  • SUPPLY-CHAIN-AND-RELEASE.md7.3K chars
  • validate-coverage-ledger.cjs33.5K chars
  • validate-coverage-ledger.test.cjs28.5K chars
  • validate-findings.cjs28.8K chars
  • validate-findings.test.cjs26.4K chars
  • VALIDATION-AND-REPORTING.md17.8K chars
  • WEB-PROTOCOL-AND-AUTH.md12.3K chars

SKILL.md, first part. Shown as plain text.

---
name: security-audit
description: Security guidance and vulnerability review for codebases, APIs, services, CLI tools, libraries, and daemons. Use for security questions, focused reviews, vulnerability research, security audits, or pen tests. Run the complete workflow only for explicit codebase audit or pen-test requests, full/comprehensive/end-to-end reviews, or requested report artifacts.
---

# Security Audit

Find vulnerabilities that violate a real trust boundary, then give owners the source evidence, safe reproduction, priority, and smallest effective fix. This is a defensive, source-first workflow. A candidate without a concrete affected principal, resource, or security outcome is not a confirmed finding.

## Operating modes

This skill is guidance by default. Loading it does not authorize the complete audit workflow or file creation.

- **Guidance mode**: For security questions, focused reviews, methodology, triage, or investigation of specific findings, use only the relevant parts of this skill. Do not automatically run all six phases, create an output directory, or write audit artifacts. You may launch focused agents when useful; they return results to the current task.
- **Full audit mode**: Use the complete workflow when the user explicitly asks to audit or pen-test a codebase, asks for a full, comprehensive, or end-to-end security review, or requests report artifacts. Run all six phases and write the files defined below.

If the request could mean either mode, ask one focused question before creating files or starting the complete workflow.

## Platform terminology

This skill is agent-neutral:

- **Parent** is the agent that coordinates the run and owns shared state.
- **Task tool** is the platform's delegation or sub-agent mechanism.
- **`research` agent** is a delegated agent for focused source exploration and factual verification.
- **`general` agent** is a delegated agent for broad investigation and bounded local execution.
- **`subagent_type:`** in a heading names which of these two delegated agent roles runs that work.

Use equivalent platform capabilities while preserving role, write-isolation, prompt, and independence boundaries.

## Universal execution safety

These rules apply in both operating modes. Source inspection is read-only. Run target-controlled builds, tests, processes, browsers, emulators, fuzzers, and fixture processing only inside an OS-enforced sandbox that provides all of these controls:

- no external network; use only an isolated loopback namespace when the check needs local client/server traffic;
- an empty environment populated from an explicit allowlist with safe values, with scratch-local `HOME`, temporary directories, and caches;
- a read-only target and toolchain, with the target-controlled process able to write only inside its assigned `scratch/` directory; and
- explicit low CPU, memory, process, file-size, disk, and wall-clock limits.

The agent, outside the target-controlled process, may make a disposable source copy in an assigned `scratch/` directory when a build must write beside source. In guidance mode, do not retain target-controlled files. In full audit mode, only trusted parent-side code may promote the minimum non-secret result to retained `artifacts/` using the procedure under Write isolation. Never expose a retained output directory (other than the agent's own assigned `scratch/`), another agent's directory, the host home directory, credentials, sockets, or shared services to target code. Do not install dependencies or let builds fetch them. Use only tools and dependencies already available locally. If every control cannot be enforced, do not execute target code: report the missing sandbox capability as a needs-validation blocker and give a safe validation plan.

Use dummy principals, fixtures, and secrets. Do not probe deployed endpoints, external services, shared infrastructure, production identities, other users' data, or live control planes. Do not test avai

Key info

Pricing
Open source
Category
Skills
Skill category
Security
Works in
Every agent listed here, including Claude.ai and ChatGPT
Best for
Intermediate
Made by
Cloudflare
Use it when
You want your code checked for security holes before launch

Related reading

  • Fundamentals

    Reviewing code you did not write

    You are going to merge a lot of code you did not type. Reviewing it is a different skill from writing it, and it is the one that actually keeps a vibe-coded…

    Intermediate

More in Skills