security-audit
Audits Rust projects for security vulnerabilities and dangerous code patterns.
Install
mkdir -p .claude/skills/security-audit-hiroshiyui && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/13334" && unzip -o skill.zip -d .claude/skills/security-audit-hiroshiyui && rm skill.zipInstalls to .claude/skills/security-audit-hiroshiyui
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Perform a project-wide security and safety audit of the 5thPlanet workspace.Key capabilities
- →Audit dependencies for known RustSec advisories
- →Flag duplicate transitive dependencies
- →Verify `unsafe_code = "forbid"` lint is intact
- →Review `Bus` trait implementations for address arithmetic issues
- →Check for integer underflow in addressing modes
- →Confirm no `build.rs` executes network requests or untrusted binaries
How it works
The skill performs a multi-step audit including dependency analysis, unsafe code lint verification, static review of trust boundaries, and build-time checks to identify security and safety risks.
Inputs & outputs
When to use security-audit
- →Security audit for rust projects
- →Check for dependency vulnerabilities
- →Verify safe code linting
About this skill
When performing a security audit, always follow these steps:
-
Audit dependencies — run
cargo audit(install withcargo install cargo-auditif missing) againstCargo.lockto check for known RustSec advisories. Then runcargo tree --workspace --duplicatesto flag duplicate transitive dependencies that could mask CVE fixes. Treat any unmaintained or yanked crate as a Medium finding even without a known vuln. -
Verify the unsafe-code lint is intact — the workspace
Cargo.tomlmust keep[workspace.lints.rust] unsafe_code = "forbid". Grep for any per-crate#![allow(unsafe_code)]overrides; any that exist must carry a justification comment and a soundness argument. Newunsafeblocks land as Critical findings until justified. -
Static review of trust boundaries — the only trust boundary in M1 is the
Bustrait. Audit eachBusimpl (notablysh2::harness::MemBusand any future Saturn bus) for:- Address arithmetic that could panic on hostile or out-of-range inputs (use
wrapping_*and explicit bounds, never rawVecindexing in production paths). - Integer underflow on pre-decrement / post-increment addressing modes.
- Mutable state shared across CPU instances without documented synchronization (relevant once the Saturn bus and the dual SH-2 land).
- Address arithmetic that could panic on hostile or out-of-range inputs (use
-
Static review of host-facing future code — for any code that will eventually touch the host (file I/O for CD images, save states, BIOS loading, SDL2 frontend), confirm:
- File paths are validated and canonicalized before opening.
- Image loaders bound their allocations (no
Vec::with_capacity(untrusted_u32 as usize)). - Save-state deserialization uses a versioned format and rejects unknown versions.
(Most of these don't exist yet — note the gap as a roadmap reminder rather than a finding.)
-
Build-time / supply-chain check — confirm no
build.rsin any workspace crate executes network requests or shells out to untrusted binaries. ConfirmCargo.lockis committed and matches the manifest. -
Report findings — document all identified risks grouped by category (Dependencies, Unsafe Code, Trust Boundaries, Host Boundary, Build/Supply Chain). Classify each by severity (Critical / High / Medium / Low) and provide concrete remediation steps. For each finding, cite the file path, line number, and the relevant audit advisory ID (when applicable).
When not to use it
- →When the request is for correctness bugs
- →When the request is for security holes
- →When the request is for performance issues
Prerequisites
Limitations
- →It does not apply the fixes, only lists them
- →It explicitly excludes correctness bugs, security holes, and performance from its scope
How it compares
This audit focuses specifically on over-engineering and complexity, providing a targeted review for simplification and reduction of code, unlike a general code review.
Compared to similar skills
security-audit side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| security-audit (this skill) | 0 | 2mo | No flags | Advanced |
| codebase-cleanup-deps-audit | 2 | 4mo | No flags | Intermediate |
| qa-security | 0 | 1mo | Review | Intermediate |
| dependency-audit | 0 | 4mo | Review | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
You might also like
codebase-cleanup-deps-audit
sickn33
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
qa-security
christopherlouet
Perform a security audit based on OWASP. Use when the user wants to verify security, look for vulnerabilities, or before a production deployment.
dependency-audit
hadsie
Audit Python dependencies for vulnerabilities, outdated
contrib-pr-review
homeassistant-ai
Review a contribution PR for safety, quality, and readiness. Checks for security concerns, test coverage, size appropriateness, and intent alignment. Use when reviewing external contributions.
verifier
oleyna80
Pre-merge quality gate. Use to verify code is ready to ship: route contracts (status, Content-Type, body), TypeScript, tests, CSP/CSRF headers, schema alignment, secret leak scan. Issues structured READY or BLOCKED verdict with file:line evidence. Read-only. Для верификации, проверки перед мержем, и
senior-security
davila7
Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.