hoangnguyen0403/common-security-audit
Probe for hardcoded secrets, injection surfaces, unguarded routes, business logic flaws, and platform-specific weaknesses across backend (Node, Go, Java, Python, Rust), frontend (React, Angular, Vue), and mobile (iOS, Android, Flutter) codebases. Use when performing security audits, vulnerability scans, secrets detection, or penetration testing.
npx skills add https://github.com/HoangNguyen0403/agent-skills-standard --skill common-security-audit
See implementation examples for secrets scanning commands.
Covers: Backend source, frontend bundles (REACT_APP_, NEXT_PUBLIC_, VITE_), mobile configs (BuildConfig, iOS configurations, strings.xml).
See implementation examples for log leakage scanning commands across Node, Go, Dart, Java, Swift.
See implementation examples for injection detection and auth coverage measurement.
npm audit --audit-level=high | pip-audit | cargo auditgo list -m -u all | dart pub outdated --jsonmvn dependency:list / ./gradlew dependencies | pod audit / Gradle scanSee implementation examples for RCE/SSRF/Path Traversal and infrastructure hardening (Docker/K8s).
grep -rE "(REACT_APP_|NEXT_PUBLIC_|VITE_)" . --include="*.ts*" --include="*.env*"dangerouslySetInnerHTML, innerHTML, eval, and .map files in prod builds.See mobile audit commands for insecure storage (credential stores/Keystore), cert pinning, debug flags, and deep links.
findById without an owner filter is a P0 IDOR vulnerability).exp, weak keys, and uncontrolled property spread (...req.body).| Finding | Threshold | Severity | Deduction |
| --- | --- | --- | --- |
| Hardcoded Secrets | Any match | P0 | -25 |
| Plain-text PII in Logs | Any match | P0 | -20 |
| Unguarded Routes > 20% | > 0.2 | P0 | -15 |
| Raw SQL Concatenation | Any match | P1 | -10 |
| Response Leakage (Stack) | > 0 | P1 | -10 |
| Insecure Mobile Storage | Token in plaintext | P1 | -15 |
| Missing Cert Pinning | No pinning detected | P2 | -8 |
| DOM XSS Sinks | Any match | P1 | -10 |
> CAUTION: P0 finding immediately caps Security score at 40/100. Immediate actions for leaked secrets: rotate the credential NOW and purge from history.
When this skill applies, preserve the following domain terminology or equivalent concrete examples in the answer when relevant:
Take hoangnguyen0403/common-security-audit from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.