Skip to content
Back to skills

Security Audit

ASecurity

Audit code and dependencies for concrete exploitable weaknesses while preserving MaskShift’s intentionally permissive local execution philosophy.

  • 2 stars
  • 0 votes
  • 0 copies
  • 6 views
  • Added September 19, 2026
ai-agentsapisecurity

Works with

  • api

Security analysis

A100/100

Scanned October 4, 2026

npx -y skills add nafeeur/MaskShift --skill security-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Audit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/nafeeur-security-audit/badge)](https://www.skillsdirectory.com/skills/nafeeur-security-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: security-audit
description: Audit code and dependencies for concrete exploitable weaknesses while preserving MaskShift’s intentionally permissive local execution philosophy.
---

# Pragmatic Security Audit

- Treat MaskShift as an owner-operated local harness with permissive execution; do not redesign it into an approval-heavy sandbox.
- Focus on accidental remote exposure, credential leakage, path traversal in HTTP routes, command injection in non-agent input, unsafe archive extraction, dependency compromise, and unauthenticated network binding.
- Preserve the autonomous default while making scope and activity visible through audit logs and an emergency stop.
- Verify that secrets are redacted from UI/API/log output and passed to child processes only when needed.
- Report concrete exploit paths and minimal fixes; avoid generic hardening checklists.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…