More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    ai Security Auditor

    2

    Your AI agent has access to 12 tools, reads from a vector database, and executes shell commands.

    Free

    19 installsSecurity scanned
    ai-security-auditor

    ai-security-auditor

    Example session with this skill installed

    "Audit my agent configuration — it uses 5 MCP servers and scrapes web content"

    • Read your context and instructions
    • Compiled the ai-security-auditor
    AI SECURITY AUDIT REPORT
    ════════════════════════
    Agent: content-researcher
    Overall Risk: HIGH (2 Critical, 4 High, 3 Medium)
    
    ID  Severity  Category     Finding                                       Remediation
    ──  ────────  ───────────  ────────────────────────────────────────────  ─────────────────────────────────────────
    F1  CRITICAL  Injection    Web scraper output concatenated into context  Add content delimiter tokens and strip
                               unsanitized                                   instruction patterns
    F2  CRITICAL  Agency       Terminal tool has unrestricted shell access   Restrict to command allowlist (git, npm,
                                                                             python)
    F3       HIGH  Leakage  API key hardcoded in system  Move to env var
                            prompt line 23               $AGENT_API_KEY via secret
    ───────  ────  ───────  ───────────────────────────  ─────────────────────────
    manager
    F4  HIGH      Permissions  MCP filesystem server has write access to /   Restrict to project directory with path
                                                                             allowlist
    
    Priority actions: [1] Sanitize web output before context injection
    [2] Restrict terminal to allowlist [3] Rotate and remove hardcoded key
    

    Connects securely to your tools. The creator never sees your data.

    About this skill

    The Problem

    Your AI agent has access to 12 tools, reads from a vector database, and executes shell commands. The system prompt was copied from a blog post. A malicious user discovers that crafted input causes the agent to dump environment variables into a public channel. You don't find out days later. Prompt injection is the #1 attack vector against AI agents — and most teams have zero defensive tooling beyond "trust the model."

    What You Get

    • Scan prompt templates for injection vectors — detect direct concatenation of user input into system prompts, insufficient role separation, XML/markdown tag injection, and recursive override patterns across six attack categories
    • Audit tool permission boundaries — map every MCP server and tool integration to a permission matrix (read/write/execute/network) with risk-level classification from LOW to CRITICAL
    • Detect data leakage paths — find hardcoded API keys in system prompts, sensitive data persisting in conversation history, context window overexposure, and tool output that returns more data than the agent needs
    • Evaluate excessive agency — classify every autonomous action on an escalation ladder (READ_ONLY through FULL_EXECUTE) and flag missing human-in-the-loop gates with blast-radius analysis
    • Assess RAG pipeline security — check vector database authentication, document ingestion sanitization, retrieval relevance scoring, and context assembly trust-weighting for poisoned-document attacks
    • Generate structured audit findings — CRITICAL/HIGH/MEDIUM/LOW severity with specific line references, OWASP LLM category mapping, and prioritized remediation steps that include before/after code examples

    Why This Beats Prompting It Yourself

    Asking an agent "is my prompt secure?" returns generic advice about role separation. But it won't trace the full data flow from a tool's untrusted output through your RAG retrieval into the LLM context, identifying that a poisoned document in your vector DB could override system instructions. This skill maps the complete attack surface across six phases with pattern-matching precision — not vibes.

    Example Session

    You: "Audit my agent configuration — it uses 5 MCP servers and scrapes web content"

    Agent:

    AI SECURITY AUDIT REPORT
    ════════════════════════
    Agent: content-researcher
    Overall Risk: HIGH (2 Critical, 4 High, 3 Medium)
    
    ID  Severity  Category     Finding                                       Remediation
    ──  ────────  ───────────  ────────────────────────────────────────────  ─────────────────────────────────────────
    F1  CRITICAL  Injection    Web scraper output concatenated into context  Add content delimiter tokens and strip
                               unsanitized                                   instruction patterns
    F2  CRITICAL  Agency       Terminal tool has unrestricted shell access   Restrict to command allowlist (git, npm,
                                                                             python)
    F3       HIGH  Leakage  API key hardcoded in system  Move to env var
                            prompt line 23               $AGENT_API_KEY via secret
    ───────  ────  ───────  ───────────────────────────  ─────────────────────────
    manager
    F4  HIGH      Permissions  MCP filesystem server has write access to /   Restrict to project directory with path
                                                                             allowlist
    
    Priority actions: [1] Sanitize web output before context injection
    [2] Restrict terminal to allowlist [3] Rotate and remove hardcoded key
    

    Use Cases

    • Pre-deployment security review of any AI agent or LLM-powered application
    • Evaluating third-party MCP servers before adding them to your agent's toolset
    • Post-incident forensics after a suspected injection attack on your agent
    • Compliance documentation for regulated industries (finance, healthcare, government)
    • Hardening agent configurations during security sprints or red-team exercises
    • Training new team members on secure prompt engineering patterns with real examples

    Known Limitations

    This is static analysis of configuration files — it cannot detect dynamic attacks during live user interaction. Multi-agent trust boundaries and cascading permission escalation are partially covered but require manual review for complex orchestration patterns. Non-English skill files may have undetected issues since patterns are English-focused.

    Upgrade to Pro

    Free gives the initial snapshot. AI Security Auditor Pro ($5) adds full OWASP LLM Top 10 rules, structured test suites against your tool schemas, compliance exports, and a CI gate that blocks regressions. Upgrade when you operate multiple agents — Pro version.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    19 installs

    Downloaded by developers to date

    Free forever

    No account required to browse

    Trust & safety

    Security scanned

    Verified clean 4 months ago

    • Free to download with an account

    Listed4 months ago
    Updated9 days ago

    What's inside

    Frequently Asked Questions