
Security
- 509 installs
- 3.9k repo stars
- Updated January 26, 2026
- parcadei/continuous-claude-v3
security is an agent skill that runs a two-agent vulnerability scan and fix-verification workflow for developers who audit authentication, injection, and sensitive code before merge.
About
security is a parcadei/continuous-claude-v3 skill implementing a dedicated /security audit workflow for sensitive code paths. The pipeline chains two agents: aegis performs the security audit identifying vulnerabilities, then arbiter verifies proposed fixes. Developers reach for security when prompted by security audit, vulnerability check, authentication review, or injection attack concerns—especially before handling auth, payments, or user data and after adding security-sensitive features. The workflow diagram shows scan-then-verify sequencing rather than single-pass linting. It complements general code review by focusing on exploit classes like injection and broken authentication rather than style or performance. Trigger phrases include is this secure, check for vulnerabilities, and review authentication code, making it a ship-gate skill for teams using continuous-claude-v3 agent sequences on high-risk modules.
- Runs automated security checks on every Claude-generated edit
- Catches OWASP Top 10, secret leaks, and dependency vulnerabilities in real time
- Blocks high-severity issues with hard gates before code reaches main
- Works alongside your existing agent workflow without extra steps
- 458 builders currently use it across production agent projects
Security by the numbers
- 509 all-time installs (skills.sh)
- +2 installs in the week ending Aug 4, 2026 (Skillselion tracking)
- Ranked #503 of 2,203 Security skills by installs in the Skillselion catalog
- Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/parcadei/continuous-claude-v3 --skill securityAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 509 |
|---|---|
| repo stars | ★ 3.9k |
| Last updated | January 26, 2026 |
| Repository | parcadei/continuous-claude-v3 ↗ |
How do you audit code for security vulnerabilities?
Let Claude continuously scan every code change for security issues before merging.
Who is it for?
Developers shipping auth, payment, or PII-handling code who need a two-step agent security audit before merge.
Skip if: Non-sensitive UI tweaks or projects without authentication, payments, or user data exposure.
When should I use this skill?
User requests security audit, vulnerability scan, injection check, or authentication code review before merge.
What you get
Security audit findings from aegis plus arbiter-verified fix recommendations for sensitive code.
- Vulnerability audit report
- Verified security fix recommendations
By the numbers
- Uses a 2-agent sequence: aegis audit followed by arbiter verification
Files
/security - Security Audit Workflow
Dedicated security analysis for sensitive code.
When to Use
- "Security audit"
- "Check for vulnerabilities"
- "Is this secure?"
- "Review authentication code"
- "Check for injection attacks"
- Before handling auth, payments, user data
- After adding security-sensitive features
Workflow Overview
┌─────────┐ ┌───────────┐
│ aegis │───▶│ arbiter │
│ │ │ │
└─────────┘ └───────────┘
Security Verify
audit fixesAgent Sequence
| # | Agent | Role | Output |
|---|---|---|---|
| 1 | aegis | Comprehensive security scan | Vulnerability report |
| 2 | arbiter | Verify fixes, run security tests | Verification report |
Why Dedicated Security?
The /review workflow focuses on code quality. Security needs:
- Specialized vulnerability patterns
- Dependency scanning
- Secret detection
- OWASP Top 10 checks
- Authentication/authorization review
Execution
Phase 1: Security Audit
Task(
subagent_type="aegis",
prompt="""
Security audit: [SCOPE]
Scan for:
**Injection Attacks:**
- SQL injection
- Command injection
- XSS (Cross-Site Scripting)
- LDAP injection
**Authentication/Authorization:**
- Broken authentication
- Session management issues
- Privilege escalation
- Insecure direct object references
**Data Protection:**
- Sensitive data exposure
- Hardcoded secrets/credentials
- Insecure cryptography
- Missing encryption
**Configuration:**
- Security misconfigurations
- Default credentials
- Verbose error messages
- Missing security headers
**Dependencies:**
- Known vulnerable packages
- Outdated dependencies
- Supply chain risks
Output: Detailed report with:
- Severity (CRITICAL/HIGH/MEDIUM/LOW)
- Location (file:line)
- Description
- Remediation steps
"""
)Phase 2: Verification (After Fixes)
Task(
subagent_type="arbiter",
prompt="""
Verify security fixes: [SCOPE]
Run:
- Security-focused tests
- Dependency audit (npm audit, pip audit)
- Re-check reported vulnerabilities
- Verify fixes don't introduce regressions
Output: Verification report
"""
)Security Scopes
Full Codebase
User: /security
→ Scan entire codebaseSpecific Area
User: /security authentication
→ Focus on auth-related codeSingle File
User: /security src/api/auth.py
→ Deep dive on one fileDependencies Only
User: /security --deps
→ Only dependency vulnerabilitiesExample
User: /security the payment processing code
Claude: Starting /security audit for payment code...
Phase 1: Security audit...
[Spawns aegis]
┌─────────────────────────────────────────────────────────────┐
│ Security Audit Report │
├─────────────────────────────────────────────────────────────┤
│ Scope: src/services/payment/ │
│ Files scanned: 12 │
│ Lines analyzed: 2,847 │
├─────────────────────────────────────────────────────────────┤
│ CRITICAL (1) │
│ ────────── │
│ [C1] SQL Injection in payment.py:89 │
│ query = f"SELECT * FROM orders WHERE id = {order_id}" │
│ Fix: Use parameterized queries │
│ │
│ HIGH (2) │
│ ──────── │
│ [H1] Hardcoded API key in stripe_client.py:12 │
│ STRIPE_KEY = "sk_live_..." │
│ Fix: Move to environment variable │
│ │
│ [H2] Missing input validation in refund.py:45 │
│ amount = request.json['amount'] # No validation │
│ Fix: Validate amount is positive number │
│ │
│ MEDIUM (1) │
│ ────────── │
│ [M1] Verbose error messages in error_handler.py:23 │
│ return {"error": str(e)} # Leaks internal details │
│ Fix: Return generic message, log details internally │
│ │
│ LOW (0) │
│ ─────── │
│ None │
├─────────────────────────────────────────────────────────────┤
│ Summary: 1 critical, 2 high, 1 medium, 0 low │
│ Status: BLOCKING - Fix critical issues before release │
└─────────────────────────────────────────────────────────────┘
Fix the critical and high issues, then run:
/security --verifyAfter Fixes
User: /security --verify
Claude: Phase 2: Verifying fixes...
[Spawns arbiter]
✅ C1: SQL injection fixed - using parameterized queries
✅ H1: API key moved to environment variable
✅ H2: Input validation added
✅ M1: Error messages sanitized
All security tests passing.
Security audit: PASSEDOWASP Top 10 Coverage
| Risk | Checked |
|---|---|
| A01 Broken Access Control | ✅ |
| A02 Cryptographic Failures | ✅ |
| A03 Injection | ✅ |
| A04 Insecure Design | ✅ |
| A05 Security Misconfiguration | ✅ |
| A06 Vulnerable Components | ✅ |
| A07 Auth Failures | ✅ |
| A08 Data Integrity Failures | ✅ |
| A09 Logging Failures | ✅ |
| A10 SSRF | ✅ |
Flags
--deps: Dependencies only--verify: Re-run after fixes--owasp: Explicit OWASP Top 10 report--secrets: Focus on secret detection
Related skills
FAQ
What agents does the security skill use?
The security skill chains aegis for the initial vulnerability security audit and arbiter to verify fixes, forming a two-step scan-then-verify workflow for sensitive code changes.
When should developers invoke security?
security fits before merging auth, payment, or user-data features, after adding security-sensitive code, or when asked to check vulnerabilities, injection attacks, or authentication implementations.