AI Agent Hub
Back to skills
Code Security Audit icon

Code Security Audit

Development Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please follow https://skillhub.cn/install/skillhub.md and install @user_4bfc9f62/code-security-audit-v2.

About this skill

Security Review for Static Code

The hard part of code review is rarely syntax. It is missing SQL injection, XSS, hard-coded secrets, path traversal, unsafe deserialization, and command execution patterns across multiple languages. Manual review can miss repeated dangerous APIs, especially in multi-file projects. This skill treats security checking as a static scanning workflow: submit code, detect the language, scan it against built-in rules, and return risks with side-by-side fixes.

How It Works

The main input is one or more source files. The skill first infers the language, then runs 111 detection rules across 20 vulnerability categories, including SQL injection, XSS, hard-coded credentials, command execution, deserialization, SSRF, IDOR, weak crypto, and buffer overflow issues. For each finding, it labels the vulnerability type, severity, and code location, then produces a dangerous code -> safe code remediation example. The final report is ordered by CRITICAL, HIGH, MEDIUM, and LOW.

Limits: this is SAST, not dynamic testing, so it cannot replace runtime vulnerability checks. Some findings may be false positives and need business context. Remediation guidance is for source code and should still be reviewed by a security team before production use. It does not support closed-source or compiled binaries, and detection precision is limited for obfuscated code.

Use Cases

  • Check a Flask query snippet before commit to locate SQL injection risk and see parameterized-query fixes.
  • Review an Express endpoint to flag XSS risks such as innerHTML and output a safer pattern.
  • Audit Go service code for command construction patterns and evaluate command-execution vulnerabilities.
  • Scan multiple project files for hard-coded secrets, SSRF, and IDOR, then aggregate findings by severity.

Best For

  • Backend engineers who review business code and want to catch injection, XSS, and hard-coded secret risks before merge.
  • Full-stack engineers maintaining web endpoints need to locate common risks such as innerHTML, unsafe redirects, and CSRF.
  • Application security reviewers need to aggregate multi-file scan results into an actionable, severity-ranked report.
  • Engineers writing Python or Go service security logic need side-by-side examples of dangerous and safer code.