🔐
QualityPython

Code Vulnerability Audit

by zebbern

Code Vulnerability Audit is a Quality skill for Claude Code, published by zebbern in claude-code-guide.

4.6K stars459 forkson zebbern/claude-code-guideAdded 2026/08/16Repository updated 2026/08/15
aiai-agentai-agent-toolsanthropic-claudeclaudeclaude-aiclaude-apiclaude-codeclaude-code-communicationclaude-code-guideclaude-code-skillsclaude-commandsclaude-desktopclaude-mcpclaude-sonnetcodemcpmcp-agentsmcp-toolsvscode-extension
Install in seconds
Install Code Vulnerability Audit
Copy Code Vulnerability Audit into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/zebbern/claude-code-guide/tree/main/skills/code-vuln-audit ~/.claude/skills/code-vuln-audit

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/zebbern/claude-code-guide.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
skills/code-vuln-audit/SKILL.md in zebbern/claude-code-guide
Installs to
~/.claude/skills/code-vuln-audit
Collection
One of 25 skills cataloged from this repository
Category
Quality1354 skills

What Code Vulnerability Audit does

Code Vulnerability Audit scans code for dependency vulnerabilities, hardcoded secrets, and OWASP security anti-patterns such as SQL injection and XSS. Use it when asked to run security scans, vulnerability detection, secret leak checks, or code security audits.

Code Vulnerability Audit is cataloged under Quality on DirSkills. Code Vulnerability Audit comes from a repository tagged ai, ai-agent, ai-agent-tools, anthropic-claude and claude.

Documentation

README

code-vuln-audit

A code security scanning tool with three core scanning capabilities:

  1. Dependency Vulnerability Scanning — Automatically detects known vulnerabilities in npm / pip dependencies
  2. Secret Leak Detection — Discovers hardcoded secrets, tokens, and passwords via regex matching + Shannon entropy analysis
  3. OWASP Pattern Detection — Identifies common security anti-patterns such as SQL injection, XSS, command injection, and insecure deserialization

Quick Start

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Code Vulnerability Audit

  • What else does zebbern publish alongside Code Vulnerability Audit?

    Code Vulnerability Audit is one of 25 skills that DirSkills catalogs from zebbern/claude-code-guide, the repository it ships in. Its siblings there include API Fuzzing for Bug Bounty, API Shape Explorer and AWS Penetration Testing. Each one is a separate skill with its own page in this directory, installs the same way Code Vulnerability Audit does, and is maintained by zebbern in that same repository. The rest of the collection is listed on the zebbern/claude-code-guide page.

  • How does Code Vulnerability Audit compare to other Quality skills?

    Code Vulnerability Audit ranks #320 by stars among the 1354 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Code Vulnerability Audit against them. Open each page to compare what they document and how they install.

More from zebbern/claude-code-guide

Code Vulnerability Audit is one of 25 skills cataloged on DirSkills from zebbern/claude-code-guide.

See all 25 skills
🛡️
2w ago

API Fuzzing for Bug Bounty

API Fuzzing for Bug Bounty provides techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing. Use it to discover vulnerabilities like IDOR, authentication bypass, SQL injection, SSRF, and GraphQL-specific issues.
Quality
4.6K459
🧩
2w ago

API Shape Explorer

API Shape Explorer generates multiple radically different interface designs for a module using parallel sub-agents, then compares them to help you choose the best API shape. Use it when designing APIs, exploring interface options, or comparing module shapes.
AI Engineering
4.6K459
🛡️
2w ago

AWS Penetration Testing

AWS Penetration Testing guides security assessment of Amazon Web Services environments, including IAM enumeration, privilege escalation, SSRF to metadata, S3 bucket exploitation, and Lambda attacks. Use it when asked to pentest AWS or test cloud infrastructure security.
Quality
4.6K459
🔍
2w ago

Academic Paper Reviewer

Academic Paper Reviewer simulates academic peer review across Originality, Methodology, Results, and Writing, providing Major and Minor Revision recommendations with actionable feedback. Use it when asked to review a paper or simulate peer review.
Quality
4.6K459
⚔️
2w ago

Active Directory Attacks

Active Directory Attacks provides techniques for attacking Microsoft Active Directory environments, covering reconnaissance, credential harvesting, Kerberos attacks, lateral movement, and privilege escalation for red team operations and penetration testing.
DevOps
4.6K459
🔍
2w ago

Audit Flow

Audit Flow traces system flows interactively across code, API, auth, data, and network layers with SQLite persistence and Mermaid export. Use it for security audits, compliance documentation, flow tracing, debugging, architecture reviews, or incident post-mortems.
Quality
4.6K459