Security and 152-FZ audit skill with rouble risk pricing
axioma-security
A skill for a deep website security and 152-FZ compliance audit: every finding is mapped to a law article and priced in roubles
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Active testing can affect a live site and requires the owner's written authorization
- Fine and risk estimates do not replace a legal opinion before filing with Roskomnadzor
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add skills/axioma-securityDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Run in a terminal in the project folder
npx skills add tkachev-ai/axioma-security --skill axioma-security -a claude-code -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 16958d0
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/tkachev-ai/axioma-security.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/axioma-security/
git -C "$tmp" checkout 16958d075b6644ed0e218e8d7e44cf8c8cbc0453
mkdir -p .claude/skills
cp -R "$tmp/skills/axioma-security" .claude/skills/axioma-securityCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add tkachev-ai/axioma-security --skill axioma-security -a cursor -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 16958d0
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/tkachev-ai/axioma-security.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/axioma-security/
git -C "$tmp" checkout 16958d075b6644ed0e218e8d7e44cf8c8cbc0453
mkdir -p .agents/skills
cp -R "$tmp/skills/axioma-security" .agents/skills/axioma-securityCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add tkachev-ai/axioma-security --skill axioma-security -a github-copilot -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 16958d0
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/tkachev-ai/axioma-security.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/axioma-security/
git -C "$tmp" checkout 16958d075b6644ed0e218e8d7e44cf8c8cbc0453
mkdir -p .github/skills
cp -R "$tmp/skills/axioma-security" .github/skills/axioma-securityCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add tkachev-ai/axioma-security --skill axioma-security -a codex -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 16958d0
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/tkachev-ai/axioma-security.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/axioma-security/
git -C "$tmp" checkout 16958d075b6644ed0e218e8d7e44cf8c8cbc0453
mkdir -p .agents/skills
cp -R "$tmp/skills/axioma-security" .agents/skills/axioma-securityCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add tkachev-ai/axioma-security --skill axioma-security -a gemini-cli -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 16958d0
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/tkachev-ai/axioma-security.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/axioma-security/
git -C "$tmp" checkout 16958d075b6644ed0e218e8d7e44cf8c8cbc0453
mkdir -p .agents/skills
cp -R "$tmp/skills/axioma-security" .agents/skills/axioma-securityCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/tkachev-ai/axioma-security.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/axioma-security/
git -C "$tmp" checkout 16958d075b6644ed0e218e8d7e44cf8c8cbc0453
mkdir -p .devin/skills
cp -R "$tmp/skills/axioma-security" .devin/skills/axioma-securityCommands for macOS and Linux, on Windows run them in Git Bash.
Formerly Windsurf.
Run in a terminal in the project folder
npx skills add tkachev-ai/axioma-security --skill axioma-security -a cline -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 16958d0
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/tkachev-ai/axioma-security.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/axioma-security/
git -C "$tmp" checkout 16958d075b6644ed0e218e8d7e44cf8c8cbc0453
mkdir -p .cline/skills
cp -R "$tmp/skills/axioma-security" .cline/skills/axioma-securityCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
npx skills add tkachev-ai/axioma-security --skill axioma-security -a roo -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 16958d0
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/tkachev-ai/axioma-security.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/axioma-security/
git -C "$tmp" checkout 16958d075b6644ed0e218e8d7e44cf8c8cbc0453
mkdir -p .roo/skills
cp -R "$tmp/skills/axioma-security" .roo/skills/axioma-securityCommands for macOS and Linux, on Windows run them in Git Bash.
A fork of Roo Code, same .roo folders.
Run in a terminal in the project folder
npx skills add tkachev-ai/axioma-security --skill axioma-security -a opencode -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Without third-party tools, from commit 16958d0
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/tkachev-ai/axioma-security.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/axioma-security/
git -C "$tmp" checkout 16958d075b6644ed0e218e8d7e44cf8c8cbc0453
mkdir -p .agents/skills
cp -R "$tmp/skills/axioma-security" .agents/skills/axioma-securityCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/tkachev-ai/axioma-security.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/axioma-security/
git -C "$tmp" checkout 16958d075b6644ed0e218e8d7e44cf8c8cbc0453
mkdir -p .agents/skills
cp -R "$tmp/skills/axioma-security" .agents/skills/axioma-securityCommands for macOS and Linux, on Windows run them in Git Bash.
Run in a terminal in the project folder
tmp=$(mktemp -d)
git clone --filter=blob:none --no-checkout https://github.com/tkachev-ai/axioma-security.git "$tmp"
git -C "$tmp" sparse-checkout set --no-cone /skills/axioma-security/
git -C "$tmp" checkout 16958d075b6644ed0e218e8d7e44cf8c8cbc0453
mkdir -p .agents/skills
cp -R "$tmp/skills/axioma-security" .agents/skills/axioma-securityCommands for macOS and Linux, on Windows run them in Git Bash.
Copy the skills/axioma-security folder into ~/.claude/skills with cp -R skills/axioma-security ~/.claude/skills/, then invoke it with /axioma-security or Skill(skill="axioma-security").
Other ways from the author
cp -R skills/axioma-security ~/.claude/skills/After cloning the repository, copy the skill folder.
This is third-party code. Review the repository files before installing.
What it does
The skill walks the agent through eight audit phases, each closed with an artifact: prep and written test authorization (without it, the skill switches to a passive, documentary-only audit), passive recon (OSINT, DNS, subdomains, subdomain takeover, SPF/DKIM/DMARC, leaked data), transport and headers (TLS, CORS, cookies), an OWASP application check (injections, XSS, IDOR, JWT/OAuth, SSRF), personal-data handling review, 152-FZ compliance (consents, localization, cross-border transfer, FSTEC and FSB threat modeling), deterministic risk pricing (a likelihood multiplier times the midpoint of the fine range plus other damage, P0-P2 priority), and a final report with a findings registry and remediation plan. The sanctions reference under the Administrative Code, Criminal Code and 152-FZ lives in a separate file and is checked against the report date.
Who it is for. For security specialists and site owners who need a report that reads clearly for an engineer, a lawyer, and a business owner alike.
Good fit when
- You need a security audit that maps every finding to a specific law article and fine amount
- You have written authorization from the resource owner for active testing
- You need a rouble risk estimate to prioritize fixes (P0-P2)
Not a fit when
- You have no written owner authorization for active testing: the skill will limit itself to a passive audit, and active pentesting without authorization is illegal (Criminal Code art. 272)
- You need a legal opinion for a court or Roskomnadzor: the sanctions reference needs verification against the current law before operational use
Example request
Run a security and 152-FZ audit of example.ru, I have written owner authorizationLimitations
Active testing requires written authorization from the resource owner, otherwise the skill falls back to a passive audit. The sanctions reference is current as of the date in the file (September 2026) and needs verification before an operational report. Risk pricing is a deterministic formula, not an individualized legal assessment.
How to disable. Delete the skills/axioma-security folder from ~/.claude/skills.
Security check
- Active testing can affect a live site and requires the owner's written authorization
- Fine and risk estimates do not replace a legal opinion before filing with Roskomnadzor
README in short
The bilingual README explains why a merged security and 152-FZ report is needed: a normal pentest does not state cost or the law, a normal compliance audit does not check whether data can actually leak. It describes the eight phases with artifacts, the risk-pricing formula, the skill's three files (operational guide, a 17-section methodology, a sanctions reference), and an explicit boundary on authorization for active testing.
FAQ
Can the skill be used without the site owner's permission?
Active testing only happens with written authorization (Criminal Code art. 272); without it, the skill switches to a passive, documentary-only audit.
How is the risk cost calculated?
A likelihood multiplier (0.7 / 0.4 / 0.1) is multiplied by the midpoint of the fine range and added to other damage, and the result drives the P0-P2 priority.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents