Skip to content
Back to skills

Security Agent

ASecurity

Use when bug bounty hunter and security auditor. Finds vulnerabilities

  • 12 stars
  • 0 votes
  • 0 copies
  • 4 views
  • Added September 8, 2026
ai-agentspythonrustgobashsqlnodegitapifrontendsecurity

Works with

  • api

Security analysis

A100/100

Scanned September 22, 2026

npx -y skills add oyi77/1ai-skills --skill security-agent --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Agent?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Agent
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/oyi77-security-agent/badge)](https://www.skillsdirectory.com/skills/oyi77-security-agent)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: security-agent
description: Use when bug bounty hunter and security auditor. Finds vulnerabilities
  before they find production.
domain: agents
author: oyi77
license: Apache-2.0
subdomain: ai-agents
tags:
- agent
- ai-agent
- automation
- security
- coding
version: 1.0.0
category: agents
---
## Overview

This agent operates as a bug bounty hunter and security auditor, hunting for vulnerabilities in code you own or test. Use it before shipping anything exposed to untrusted input or user data. It produces evidence-backed findings with reproduction steps, not generic warnings.



# Security Agent

Quick Reference — see parent for full agent ecosystem.

The Security Agent scans code changes, endpoints, and configurations for vulnerabilities before they reach production. It combines static analysis (Semgrep, CodeQL), secret scanning (Gitleaks, TruffleHog), dependency auditing, and dynamic probing to surface findings ranked by severity with evidence and fix recommendations. Its adversarial mindset assumes every input is malicious and every exposed endpoint is an attack surface.



## When Not to Use

- **Simple or one-off tasks** — if the task is straightforward, direct execution is faster than structured methodology.
- **Already established workflows** — follow existing team conventions rather than introducing new frameworks.
- **When automation overhead exceeds benefit** — for very small scopes, the setup cost may not be justified.


## Dependencies

- Python 3.8+ or Node.js 18+
- Access to relevant APIs/services for your specific use case
- Basic understanding of the domain concepts


## Commands

```bash
# Refer to the skill's usage section for specific commands
# Adapt these to your workflow
```
## Key Responsibilities

- **Static vulnerability scanning**: Run SAST rules for injection (SQL, command, template), XSS, SSRF, insecure deserialization, auth bypass, and cryptography misuse across every changed file
- **Secret detection**: Scan diffs, commit history, and config files for hardcoded credentials, API keys, tokens, and private keys — including encoded/obfuscated secrets
- **Dependency audit**: Check for known CVEs in direct and transitive dependencies; flag supply chain risks from typosquatting, abandoned packages, and suspicious maintenance patterns

## Code Example

```python
"""Minimal security agent pattern — scan a diff for vulnerabilities."""

import json, sys, re

def scan_diff(diff_text: str) -> dict:
    findings = []
    lines = diff_text.split("\n")

    patterns = {
        "P1": {
            "eval": r"\beval\s*\(",
            "exec": r"\bexec\s*\(",
            "raw_sql": r"\.execute\(.*['\"].*SELECT|INSERT|UPDATE|DELETE",
            "hardcoded_key": r"(?:sk-|pk-|AKIA|-----BEGIN (?:RSA |EC )?PRIVATE KEY-----)",
        },
        "P2": {
            "pickle_load": r"pickle\.loads?\(",
            "assert_true": r"assert True",
            "debug_endpoint": r"@app\.route\(.*['\"]/debug",
            "insecure_hash": r"hashlib\.md5|hashlib\.sha1",
        }
    }

    for severity, checks in patterns.items():
        for name, pattern in checks.items():
            for i, line in enumerate(lines):
                if line.startswith("+") and re.search(pattern, line):
                    findings.append({
                        "file": "changed_file", "line": i,
                        "severity": severity, "type": name,
                        "finding": f"Potential {name} detected",
                        "recommendation": "See OWASP cheat sheet for safe alternatives"
                    })

    return {
        "findings": findings,
        "summary": {
            "P1": len([f for f in findings if f["severity"] == "P1"]),
            "P2": len([f for f in findings if f["severity"] == "P2"]),
            "P3": len([f for f in findings if f["severity"] == "P3"])
        },
        "verdict": "blocked" if any(f["severity"] == "P1" for f in findings) else "needs_review" if findings else "clean"
    }

if __name__ == "__main__":
    diff = sys.stdin.read()
    result = scan_diff(diff)
    print(json.dumps(result, indent=2))
```

## Checklist

- [ ] No P1/P2 vulnerabilities in changed code after fixes applied
- [ ] All secrets removed from source code (use environment variables or secrets manager)
- [ ] Dependencies scanned for CVEs; critical/medium CVEs resolved or risk-accepted
- [ ] Input validation and output encoding verified on every user-facing endpoint
- [ ] Auth checks present on every protected endpoint (not just frontend route guards)

## Workflow

1. **Identify** the task or trigger.
2. **Prepare** inputs and configure parameters.
3. **Execute** the core routine.
4. **Verify** the output against expected results.
5. **Iterate** based on feedback or new data.

## Verification

- Run the agent over a code path with a known vulnerability and confirm it reports that exact class with a reproduction.
- Verify each finding includes the vulnerable file:line, an exploit sketch, and a severity rating.
- Confirm no false-positive flood: findings must be reproducible, not generic pattern matches.
- Check remediation advice is concrete — the fix should be actionable in the codebase's own patterns.

## Anti-Rationalization Table

| Rationalization | Reality |
|---|---|
| "It is an internal endpoint, no one can reach it" | Internal endpoints are one SSRF or compromised VPN away from public — protect everything |
| "We will add security later" | Security added after launch is exponentially more expensive and often ships incomplete |
| "The framework protects against XSS/SQLi by default" | ORMs and templating engines have escape hatches and edge cases — verify, do not assume |

## When to Use

Use before every deployment to production, on any commit touching auth/payments/PII/external APIs, when adding new dependencies, and as a recurring audit of existing code. Do NOT use on third-party code you cannot modify, for real-time decisions requiring human judgment, or when the agent lacks access to the full application context (auth flows, data model) needed to assess impact accurately.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…