Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    Security Sweep

    2

    An automated security auditor that scans code for OWASP vulnerabilities, secrets, and injection flaws before deployment.

    $5

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned
    Security Sweep

    Security Sweep

    Example session with this skill installed

    I'm done with the login controller. Can you review it for security before I push?

    • Read your context and instructions
    • Compiled the security sweep

    Security Sweep — login_controller.py

    🔴 Critical

    • Broken Access Control — login_controller.py:22, function get_user_data()
      What: trusted client-provided user_id without session verification.
      Risk: IDOR — any logged-in user can view any other user's data.
      Fix: verify session.user_id === req.body.user_id.

    ✅ Checked, looked clean

    • Hardcoded secrets
    • SQL Injection (using parameterized queries)
    • XSS

    Summary: 1 critical found. The IDOR vulnerability allows unauthorized data access.
    Note: this is a review, not a guarantee.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Detect hardcoded API keys and tokens before they reach version control.Identify SQL injection and XSS risks in new feature code.Verify authorization logic on new API endpoints.Audit third-party dependencies for known security vulnerabilities.

    About this skill

    AI-written code looks finished and correct while quietly carrying vulnerabilities. A large share of AI-generated code introduces OWASP Top 10 flaws — and the person shipping it usually feels more confident it's safe, not less.

    What it does

    • Scans your whole codebase or a single diff for security holes
    • Flags OWASP Top 10 issues and leaked secrets or keys
    • Explains each finding, fixes it, then re-scans to confirm the fix held
    • Runs automatically the moment code reads as "done"

    Why it beats prompting yourself

    "Is this safe?" gets you a reassuring answer, not an actual audit. This runs a real check against the vulnerability classes AI code fails most, before anything ships.

    Use cases

    • A pre-commit or pre-deploy security pass
    • Auditing AI-generated code before you trust it
    • Catching hardcoded keys and secrets before they leak
    • A second set of eyes on a finished feature

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 2 months ago

    • Passed all security checks, Safe to install

    Listed2 months ago

    What's inside

    Frequently Asked Questions