Security Audit
Perform comprehensive security assessment and vulnerability analysis
$ npx claude-code-templates@latest --command="security/security-audit" --yesRequires Claude Code. The command adds this command to your project's .claudedirectory — nothing runs on ToolZip's servers.
What's inside this command
Component source
Security Audit
Perform comprehensive security assessment: $ARGUMENTS
Current Environment
- Dependency scan: !
npm audit --audit-level=moderate 2>/dev/null || pip check 2>/dev/null || echo "No package manager detected" - Environment files: @.env* (if exists)
- Security config: @.github/workflows/security.yml or @security/ (if exists)
- Recent commits: !
git log --oneline --grep="security\|fix" -10
Task
Perform systematic security audit following these steps:
- Environment Setup
- Check for existing security tools and configurations
- Review deployment and infrastructure setup
- Dependency Security
- Check for outdated packages with security issues
- Review dependency sources and integrity
- Use appropriate tools: npm audit, pip check, cargo audit, etc.
- Authentication & Authorization
- Check for proper session management
- Verify authorization controls and access restrictions
- Examine password policies and storage
- Input Validation & Sanitization
- Look for SQL injection vulnerabilities
- Identify potential XSS (Cross-Site Scripting) issues
- Review file upload security and validation
- Data Protection
- Check encryption implementation for data at rest and in transit
- Review data masking and anonymization practices
- Verify secure communication protocols (HTTPS, TLS)
- Secrets Management
- Check for proper secrets management practices
- Review environment variable security
- Identify exposed configuration files
- Error Handling & Logging
- Check logging practices for security events
- Verify sensitive data is not logged
- Assess error handling robustness
- Infrastructure Security
- Check CI/CD pipeline security
- Examine cloud configuration and permissions
- Assess network security configurations
- Security Headers & CORS
- Review CORS configuration
- Verify CSP (Content Security Policy) settings
- Examine cookie security attributes
- Reporting
- Provide specific remediation steps for each issue
- Include code examples and file references
- Create an executive summary with key recommendations
Use automated security scanning tools when available and provide manual review for complex security patterns.
Related Claude Code Commands
Dependency Audit
Audit dependencies for security vulnerabilities, license compliance, and update recommendations
Secrets Scanner
Scan codebase for exposed secrets, credentials, and sensitive information
Add Authentication System
Implement secure user authentication system with chosen method and security best practices
Security Hardening
Harden application security configuration with comprehensive security controls
Penetration Test
Perform penetration testing and vulnerability assessment on application
Generate Tests
Generate a complete test file for a specified source file or component. Use when the user explicitly asks to write, create, or generate tests for a specific file.
Catalog data and component content are sourced from the open-source davila7/claude-code-templates project (MIT license). ToolZip curates the listing and writes original descriptions; every component links back to its original source. Claude Code is a product of Anthropic. ToolZip is an independent catalog and is not affiliated with or endorsed by Anthropic.