🛡️
QualityPython

Security Auditor

by Observal

Security Auditor is a Quality skill for Claude Code, published by Observal in Observal.

2.4K stars472 forkson Observal/ObservalAdded 2026/08/18Repository updated 2026/08/16
agentsanalyticsantigravityclaude-codecli-toolcodexcursorcursor-aiinsightskirolarge-language-modelsmcpopen-sourcepiplaygroundregistryself-hostedskills
Install in seconds
Install Security Auditor
Copy Security Auditor into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/Observal/Observal/tree/main/tests/fixtures/skills/security-auditor ~/.claude/skills/security-auditor

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/Observal/Observal.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
tests/fixtures/skills/security-auditor/SKILL.md in Observal/Observal
Installs to
~/.claude/skills/security-auditor
Collection
One of 10 skills cataloged from this repository
Category
Quality1354 skills

What Security Auditor does

Security Auditor scans provided code for OWASP Top 10 vulnerabilities including SQL injection, XSS, SSRF, and broken authentication. It provides severity ratings and remediation steps with corrected code to use during code review.

Security Auditor is cataloged under Quality on DirSkills. Security Auditor comes from a repository tagged agents, analytics, antigravity, claude-code and cli-tool.

Documentation

README


name: security-auditor description: Audits code for OWASP Top 10 vulnerabilities version: 1.0.0 owner: example task_type: code-review

Security Auditor

When activated, scan provided code for OWASP Top 10 vulnerabilities:

  1. SQL Injection
  2. Cross-Site Scripting (XSS)
  3. Server-Side Request Forgery (SSRF)
  4. Broken Authentication
  5. Sensitive Data Exposure
  6. Insecure Deserialization
  7. Security Misconfiguration

Provide severity ratings (critical/high/medium/low) and remediation steps with corrected code.

Frequently asked about Security Auditor

  • What else does Observal publish alongside Security Auditor?

    Security Auditor is one of 10 skills that DirSkills catalogs from Observal/Observal, the repository it ships in. Its siblings there include Observal, Observal Admin and Observal Agents. Each one is a separate skill with its own page in this directory, installs the same way Security Auditor does, and is maintained by Observal in that same repository. The rest of the collection is listed on the Observal/Observal page.

  • How does Security Auditor compare to other Quality skills?

    Security Auditor ranks #512 by stars among the 1354 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Security Auditor against them. Open each page to compare what they document and how they install.

More from Observal/Observal

Security Auditor is one of 10 skills cataloged on DirSkills from Observal/Observal.

See all 10 skills
🛠️
2w ago

Observal

Observal operates the Observal CLI for login, configuration, setup checks, inbox processing, teamspace management, and authenticated API access. Use it when you need to inspect local setup or run core account and inventory workflows.
Automation
2.4K472
⚙️
2w ago

Observal Admin

Observal Admin administers Observal users, settings, diagnostics, review queues, security events, audit logs, SAML, SCIM, local server services, upgrades, rollback, and database migrations. Use it for privileged governance, submission decisions, identity configuration, security investigation, or server operations.
DevOps
2.4K472
🤖
2w ago

Observal Agents

Observal Agents creates, validates, publishes, versions, and manages Observal Agents from the command line, including pulling, archiving, restoring, and transferring ownership. Use it when building, installing, or changing an Agent definition or managing its lifecycle.
AI Engineering
2.4K472
🔍
2w ago

Observal Ops

Observal Ops inspects Observal traces, sessions, rankings, feedback, telemetry health, logs, and Agent insight reports. Use it when you need operational evidence, telemetry diagnosis, ratings, report generation, regression analysis, or recommendations grounded in Agent usage.
Data
2.4K472
🔧
2w ago

Observal Recovery

Observal Recovery recovers Observal session ingestion, manages CLI upgrades, downgrades and rollback, and performs explicit local Agent fallback when the server is unavailable. Use when the user asks to reconcile missed sessions, repair CLI version state, or continue locally after a confirmed connection or configuration failure.
DevOps
2.4K472
📦
2w ago

Observal Registry

Observal Registry searches, recommends, submits, installs, and manages Observal MCP servers, skills, hooks, prompts, and sandboxes. Use it to find components, publish them, install them into a harness, or manage their lifecycle.
Automation
2.4K472