Security audit skill with GOST and FSTEC

Security Audit Skill for Claude Code

A security audit skill for Claude Code: OWASP Top 10 plus GOST R 56939, FSTEC Order No. 21 and 152-FZ, parallel subagents and a compliance matrix

Skill

Low risk

We rate an entry low when it mostly gives the agent instructions and reference material.

Why this level

  • It only reads project code via grep and subagents, writing just the final report to docs/
All reasons and checks
Russian stack

aguleykovn8n/security-audit-skill

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add skills/security-audit-skill-for-claude-code

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Run in a terminal in the project folder

npx skills add aguleykovn8n/security-audit-skill --skill security-audit -a claude-code -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add aguleykovn8n/security-audit-skill --skill security-audit -a cursor -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add aguleykovn8n/security-audit-skill --skill security-audit -a github-copilot -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add aguleykovn8n/security-audit-skill --skill security-audit -a codex -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add aguleykovn8n/security-audit-skill --skill security-audit -a gemini-cli -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add aguleykovn8n/security-audit-skill --skill security-audit -a cline -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

Run in a terminal in the project folder

npx skills add aguleykovn8n/security-audit-skill --skill security-audit -a roo -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

A fork of Roo Code, same .roo folders.

Run in a terminal in the project folder

npx skills add aguleykovn8n/security-audit-skill --skill security-audit -a opencode -y

The skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.

You will need: Node.js

Checked against the repository on Sep 25, 2026, commit 3f42b89.

Text for your agent

Clone the repository into ~/.claude/skills/security-audit, restart Claude Code (or run /restart), then in the project ask: run a security audit.

Other ways from the author
git clone https://github.com/aguleykovn8n/security-audit-skill ~/.claude/skills/security-audit

A global skill, auto-discovered after a restart.

This is third-party code. Review the repository files before installing.

What it does

The skill runs a layered security check on a project: OWASP Top 10 (2021) with grep patterns for Node/TypeScript, Python, Go and Rust, a separate references/russian-security-standards.md file that maps typical Russian corporate security requirements to concrete code-level checks, password policy, RBAC, audit logging, CSRF, TLS, SDLC, based on GOST R 56939-2024, FSTEC Order No. 21 and 152-FZ, plus component checklists (auth, payments, admin panel, file upload) and STRIDE threat modeling. Before running, it asks four context questions about the stack, database, auth model and audit goal, then dispatches 3-5 parallel subagents each with a specific angle and consolidates the results into one report with CRITICAL/HIGH/MEDIUM severity and file:line references.

Who it is for. For developers and devops engineers who need a security audit before launch or are preparing for Russian corporate tenders with GOST and FSTEC requirements.

Good fit when

  • A project is about to open to public traffic, especially with auth or payments
  • You need to check against Russian security requirements for a corporate tender
  • A scheduled quarterly-to-semiannual audit, or a post-incident review

Not a fit when

  • A simple CRUD app with no auth or payments: an audit would be overkill
  • A hackathon prototype where security through obscurity is fine
  • A static site with no backend: only a secrets and SSL check is needed

Example request

Run a security audit before launch and produce a 152-FZ compliance matrix

Limitations

Stack-specific grep patterns fully cover only Node/TypeScript, Python, Go and Rust; PHP, Java and Ruby only get generic OWASP checks with no specific patterns. Dispatching parallel subagents requires a subagent launch tool in the environment; integrations with the codex:rescue and superpowers:writing-plans plugins are optional extras, not requirements.

How to disable. Delete the ~/.claude/skills/security-audit folder.

Security check

  • It only reads project code via grep and subagents, writing just the final report to docs/

README in short

The README lists the capabilities (OWASP Top 10, Russian standards, component checklists, STRIDE, common AI-generated-code gotchas), a three-step process (context questions, parallel subagents, a consolidated report), a supported-stack table, when to use and not use it, a sample report output, and a list of optional integrations with other plugins.

SKILL.md

---
name: security-audit
description: Universal security audit skill for Claude Code, OWASP Top 10 (2021) + Russian security standards (GOST R 56939, FSTEC, 152-FZ) + best practices. Use before launching to production, when adding auth/payment/admin, preparing for corporate tenders, or regularly every 3-6 months. Triggers: security audit, проверка безопасности, аудит безопасности, OWASP, ГОСТ ИБ, перед запуском проверь дыры, найди уязвимости.
---

# Security Audit - универсальный скилл

Запускает многослойную проверку безопасности проекта. Подходит для любого web-проекта (Node.js / Python / Go / Rust / PHP / Java backend + React/Vue/Angular frontend).

## Что проверяет

3 слоя:

1. OWASP Top 10 (международный стандарт, edition 2021): A01 Broken Access Control, A02 Cryptographic Failures, A03 Injection, A04 Insecure Design, A05 Security Misconfiguration, A06 Vulnerable Components, A07 Auth Failures, A08 Software/Data Integrity, A09 Logging/Monitoring Failures, A10 SSRF
2. Российские стандарты ИБ: парольная политика, RBAC, регистрация событий, интеграции, шифрование TLS, SDLC. Основано на ГОСТ Р 56939-2024, Приказе ФСТЭК №21, OWASP ASVS
3. Project-specific gotchas для текущего стека.

FAQ

Do I need special documents for a corporate tender audit?

The skill builds a compliance matrix against GOST R 56939-2024, FSTEC Order No. 21 and 152-FZ sections, citing the file and line backing each point.

Does the skill cover PHP or Java?

Partly: generic OWASP checks apply, but there are no stack-specific grep patterns for them yet.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AISecurity audit skill with GOST and FSTEC

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.