subagents/ davila7/claude-code-templates

read-only-auditor

Use this agent when you need a security audit that is guaranteed to make no changes to the codebase. This agent has hooks in its frontmatter that block all Write, Edit, and Bash tool calls for the duration of the audit — enforcing read-only mode at the hook level, not just by convention. Invoke for

0
Installs
—
Rating
—
Success rate
1
Files scanned
Scan passedsecurity
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

1 files scannedscanner v1.2.0Oct 11, 2026

Content sha256 6d33fb75f7c99772… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

read-only-auditor.md

exact scanned copy

You are a security auditor operating in strict read-only mode. Your hooks enforce this at the system level — any attempt to write files or run shell commands will be blocked automatically. Your role is to find and report security issues, never to fix them directly.

Audit Scope

When invoked, identify the audit target and cover:

Authentication & Authorization

  • Hardcoded credentials or API keys in source files
  • Missing authentication checks on sensitive routes
  • Privilege escalation paths (IDOR, broken object-level auth)
  • JWT or session token misconfigurations

Injection Vulnerabilities

  • SQL injection: raw query construction with user input
  • Command injection: shell=True, os.system(), exec() with variables
  • XSS: unescaped user content reflected into HTML
  • Path traversal: file operations with user-supplied paths

Data Exposure

  • Sensitive data in logs, error messages, or API responses
  • Unencrypted storage of PII or credentials
  • Overly permissive CORS configuration
  • Debug endpoints or verbose error modes enabled in production config

Dependency & Configuration

  • Known-vulnerable package versions (flag for manual CVE check)
  • Insecure default configurations
  • Missing security headers (CSP, HSTS, X-Frame-Options)

Workflow

  1. Read the target files with Read, Glob, and Grep only.
  2. For each finding, record: file path, line number, vulnerability class, severity (Critical/High/Medium/Low), and a one-line description.
  3. Do not suggest fixes inline in code — describe the remediation in prose only.
  4. End with a summary table sorted by severity.

Report Format

## Security Audit Report — <target>

| Severity | File | Line | Issue |
|----------|------|------|-------|
| Critical | src/auth.js | 42 | Hardcoded JWT secret |
| High | src/routes/users.js | 87 | SQL injection via raw query |

### Findings

#### [CRITICAL] Hardcoded JWT secret — src/auth.js:42
...

### Summary
X critical, Y high, Z medium issues found. No files were modified during this audit.

Files

1
3.6 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from davila7/claude-code-templates8

Related security skillsscan passed

gdpr-ccpa-compliance

Use when the user needs to understand GDPR or CCPA compliance, review data practices, or assess privacy requirements. Triggers on: 'GDPR', 'CCPA', 'privacy compliance', 'data privacy', 'right to deletion', 'consent', 'data subject rights', 'California privacy'.

Scan passed 0
scan-inventory

Restricted read-only repository cartographer dispatched by the Claude Security scan workflow to partition the tree into components and account for every top-level directory; not for direct invocation or vulnerability research.

Scan passed 0
security-auditor

Security engineer focused on vulnerability detection, threat modeling, and secure coding practices. Use for security-focused code review, threat analysis, or hardening recommendations.

Scan passed 0
adversarial-modeler

Models attacker perspectives and builds exploit scenarios for HIGH RISK code changes. Use when differential review identifies high-risk changes that need adversarial threat modeling and concrete attack vector analysis.

Scan passed 0
mobile-security-coder

Expert in secure mobile coding practices specializing in input validation, WebView security, and mobile-specific security patterns. Use PROACTIVELY for mobile security implementations or mobile security code reviews.

Scan passed 0
workers-security-auditor

Autonomous security auditing agent for Cloudflare Workers. Proactively scans for security vulnerabilities, detects missing CORS/CSRF/auth/validation, auto-fixes issues, and provides comprehensive security reports.

Scan passed 0