🛡️
QualityShell

Security Audit

by garagon

Security Audit is a Quality skill for Claude Code, published by garagon in nanostack.

204 stars15 forkson garagon/nanostackAdded 2026/09/05Repository updated 2026/06/15
ai-agentsai-codingclaude-codecode-reviewcodexdeveloper-toolsengineering-workflowgstackharnessharness-engineeringsecurity-audit
Install in seconds
Install Security Audit
Copy Security Audit into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/garagon/nanostack/tree/main/security ~/.claude/skills/security

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/garagon/nanostack.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
security/SKILL.md in garagon/nanostack
Installs to
~/.claude/skills/security
Collection
One of 18 skills cataloged from this repository
Category
Quality1662 skills

What Security Audit does

Security Audit performs OWASP Top 10 checks and STRIDE threat modeling against a codebase before shipping. Use it to review code, dependencies, secrets, CI, and other likely attack surfaces.

Security Audit is cataloged under Quality on DirSkills. Security Audit comes from a repository tagged ai-agents, ai-coding, claude-code, code-review and codex.

Documentation

README

/security — Security Audit

You think like an attacker but report like a defender. The real attack surface is rarely the code you wrote. It is the secrets in git history, the dependency you forgot to update, the CI pipeline that leaks tokens, and the AI endpoint without rate limiting. Start there, not at the application logic.

Telemetry preamble

Defensive telemetry init. No-op if telemetry is disabled via NANOSTACK_NO_TELEMETRY=1, ~/.nanostack/.telemetry-disabled, or if the helpers are removed.

_P="$HOME/.claude/skills/nanostack/bin/lib/skill-preamble.sh"
[ -f "$_P" ] && . "$_P" security
unset _P

This is the opening of the README. Read the full README on GitHub.

Commands Security Audit provides

Slash commands named in this skill’s SKILL.md, listed in the order they first appear.

  • /security
  • /review
  • /qa

Frequently asked about Security Audit

  • What else does garagon publish alongside Security Audit?

    Security Audit is one of 18 skills that DirSkills catalogs from garagon/nanostack, the repository it ships in. Its siblings there include Compound, Conductor and Feature. Each one is a separate skill with its own page in this directory, installs the same way Security Audit does, and is maintained by garagon in that same repository. The rest of the collection is listed on the garagon/nanostack page.

  • How does Security Audit compare to other Quality skills?

    Security Audit ranks #1497 by stars among the 1662 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Security Audit against them. Open each page to compare what they document and how they install.

More from garagon/nanostack

Security Audit is one of 18 skills cataloged on DirSkills from garagon/nanostack.

See all 18 skills