maddhruv/absolute-audit
> Triggers on "absolute audit", "security audit", "are we vulnerable", "scan for CVEs", "check for secrets/injection", "harden this".
npx skills add https://github.com/maddhruv/absolute --skill absolute-audit
> Start your first response with the 🔒 emoji.
Find and triage security problems across the repo — vulnerable dependencies (CVEs) and
risky code patterns — then fix the ones worth fixing, safely. Output is a severity-ranked
findings table with a remediation per item, not a raw scanner dump.
Runs the shared engine in references/health-engine.md — read it for the
DETECT → SCAN → TRIAGE → FIX → VERIFY → REPORT loop and the safety contract. This file
covers only what's specific to security auditing.
> Authorized defensive use. This command audits the user's *own* repository to find
> and fix weaknesses. It is for hardening, not for attacking systems or evading detection.
main.Distinct from the built-in /security-review (reviews the *pending diff* on your
branch) — audit scans the whole committed repo, deps included. They complement.
1. Dependency vulnerabilities (CVEs) — primary:
| Ecosystem | Scanner |
|---|---|
| npm / pnpm / yarn | npm audit --json / pnpm audit --json / yarn npm audit --json |
| Python | pip-audit (preferred) or safety check |
| Go | govulncheck ./... |
| Cross-language | osv-scanner against the lockfile if available |
2. Code-level patterns — read-only grep/static pass for high-signal issues only:
hardcoded secrets/keys/tokens, eval/dynamic exec on input, SQL built by string
concatenation, missing authz checks on sensitive routes, disabled TLS verification, unsafe
deserialization, overly-broad CORS. Prefer the project's existing SAST/linter security
rules (eslint-plugin-security, bandit, gosec) if configured.
Report suspected leaked secrets but never print the secret value — reference
path:line and the kind.
Rank by severity × exploitability × reachability, not raw CVSS:
| Severity | Default |
|---|---|
| Critical / High, reachable, fix available | fix now (wave 1) |
| Moderate, reachable | fix this pass |
| Low / not reachable from app code | report, usually defer |
| Transitive-only, no direct upgrade path | flag, note the blocking parent |
Mark each: is it reachable from the app's actual code paths? A CVE in an unused transitive
branch is lower priority than a Moderate one on a hot path. State the fixed version or the
mitigation for each.
bump mechanics to the upgrade flow's per-ecosystem steps). Prefer patched minors;
escalate to a major only when that's the only fix, and gate it.
+ flag the leaked one for rotation, add the authz check). Each fix is its own small wave.
stay green. Never resolve by suppressing/allowlisting the alert.
/absolute upgrade — does the actual version moves for vulnerable deps./security-review (built-in) — pair with this to also cover your pending diff./absolute work — if remediation is a real refactor (e.g. replacing an auth flow), hand off.Take maddhruv/absolute-audit from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.