Security audit skill with GOST and FSTEC
Security Audit Skill for Claude Code
A security audit skill for Claude Code: OWASP Top 10 plus GOST R 56939, FSTEC Order No. 21 and 152-FZ, parallel subagents and a compliance matrix
Low risk
We rate an entry low when it mostly gives the agent instructions and reference material.
Why this level
- It only reads project code via grep and subagents, writing just the final report to docs/
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add skills/security-audit-skill-for-claude-codeDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Run in a terminal in the project folder
npx skills add aguleykovn8n/security-audit-skill --skill security-audit -a claude-code -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add aguleykovn8n/security-audit-skill --skill security-audit -a cursor -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add aguleykovn8n/security-audit-skill --skill security-audit -a github-copilot -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add aguleykovn8n/security-audit-skill --skill security-audit -a codex -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add aguleykovn8n/security-audit-skill --skill security-audit -a gemini-cli -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add aguleykovn8n/security-audit-skill --skill security-audit -a cline -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add aguleykovn8n/security-audit-skill --skill security-audit -a roo -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
A fork of Roo Code, same .roo folders.
Run in a terminal in the project folder
npx skills add aguleykovn8n/security-audit-skill --skill security-audit -a opencode -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Clone the repository into ~/.claude/skills/security-audit, restart Claude Code (or run /restart), then in the project ask: run a security audit.
Other ways from the author
git clone https://github.com/aguleykovn8n/security-audit-skill ~/.claude/skills/security-auditA global skill, auto-discovered after a restart.
This is third-party code. Review the repository files before installing.
What it does
The skill runs a layered security check on a project: OWASP Top 10 (2021) with grep patterns for Node/TypeScript, Python, Go and Rust, a separate references/russian-security-standards.md file that maps typical Russian corporate security requirements to concrete code-level checks, password policy, RBAC, audit logging, CSRF, TLS, SDLC, based on GOST R 56939-2024, FSTEC Order No. 21 and 152-FZ, plus component checklists (auth, payments, admin panel, file upload) and STRIDE threat modeling. Before running, it asks four context questions about the stack, database, auth model and audit goal, then dispatches 3-5 parallel subagents each with a specific angle and consolidates the results into one report with CRITICAL/HIGH/MEDIUM severity and file:line references.
Who it is for. For developers and devops engineers who need a security audit before launch or are preparing for Russian corporate tenders with GOST and FSTEC requirements.
Good fit when
- A project is about to open to public traffic, especially with auth or payments
- You need to check against Russian security requirements for a corporate tender
- A scheduled quarterly-to-semiannual audit, or a post-incident review
Not a fit when
- A simple CRUD app with no auth or payments: an audit would be overkill
- A hackathon prototype where security through obscurity is fine
- A static site with no backend: only a secrets and SSL check is needed
Example request
Run a security audit before launch and produce a 152-FZ compliance matrixLimitations
Stack-specific grep patterns fully cover only Node/TypeScript, Python, Go and Rust; PHP, Java and Ruby only get generic OWASP checks with no specific patterns. Dispatching parallel subagents requires a subagent launch tool in the environment; integrations with the codex:rescue and superpowers:writing-plans plugins are optional extras, not requirements.
How to disable. Delete the ~/.claude/skills/security-audit folder.
Security check
- It only reads project code via grep and subagents, writing just the final report to docs/
README in short
The README lists the capabilities (OWASP Top 10, Russian standards, component checklists, STRIDE, common AI-generated-code gotchas), a three-step process (context questions, parallel subagents, a consolidated report), a supported-stack table, when to use and not use it, a sample report output, and a list of optional integrations with other plugins.
SKILL.md
--- name: security-audit description: Universal security audit skill for Claude Code, OWASP Top 10 (2021) + Russian security standards (GOST R 56939, FSTEC, 152-FZ) + best practices. Use before launching to production, when adding auth/payment/admin, preparing for corporate tenders, or regularly every 3-6 months. Triggers: security audit, проверка безопасности, аудит безопасности, OWASP, ГОСТ ИБ, перед запуском проверь дыры, найди уязвимости. --- # Security Audit - универсальный скилл Запускает многослойную проверку безопасности проекта. Подходит для любого web-проекта (Node.js / Python / Go / Rust / PHP / Java backend + React/Vue/Angular frontend). ## Что проверяет 3 слоя: 1. OWASP Top 10 (международный стандарт, edition 2021): A01 Broken Access Control, A02 Cryptographic Failures, A03 Injection, A04 Insecure Design, A05 Security Misconfiguration, A06 Vulnerable Components, A07 Auth Failures, A08 Software/Data Integrity, A09 Logging/Monitoring Failures, A10 SSRF 2. Российские стандарты ИБ: парольная политика, RBAC, регистрация событий, интеграции, шифрование TLS, SDLC. Основано на ГОСТ Р 56939-2024, Приказе ФСТЭК №21, OWASP ASVS 3. Project-specific gotchas для текущего стека.
FAQ
Do I need special documents for a corporate tender audit?
The skill builds a compliance matrix against GOST R 56939-2024, FSTEC Order No. 21 and 152-FZ sections, citing the file and line backing each point.
Does the skill cover PHP or Java?
Partly: generic OWASP checks apply, but there are no stack-specific grep patterns for them yet.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents