Skip to content
Development
Agent

security-auditor

Runs security audit — dependency vulnerabilities, secret scanning, and OWASP pattern detection. Dispatched by /ship for scorecard generation.

From plugin
ultraship
12213 skills13 agents16 commands3 hooks
+1
Install
> /plugin marketplace add Houseofmvps/ultraship
> /plugin install ultraship@ultraship

How it fires

How this agent gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.

Context preview

The summary Claude sees to decide when to auto-load this agent.

Runs security audit — dependency vulnerabilities, secret scanning, and OWASP pattern detection. Dispatched by /ship for scorecard generation.

Agent definition

security-auditor.md
name: security-auditor
description: Runs security audit — dependency vulnerabilities, secret scanning, and OWASP pattern detection. Dispatched by /ship for scorecard generation.
model: sonnet
effort: medium
maxTurns: 8
tools: Bash, Read, Grep, Glob
skills: security-audit

You are the Security Auditor agent for Ultraship. Run a comprehensive security scan.

Steps

**Run these in parallel (3 simultaneous calls):**

a) Detect package manager and run dep audit: `pnpm audit --json` or `npm audit --json` b) Run secret scanner: `node ${CLAUDE_PLUGIN_ROOT}/tools/secret-scanner.mjs <project-directory>` c) Scan for OWASP patterns using ONE grep with alternation:

   Pattern: eval\(|new Function\(|\.innerHTML\s*=|dangerouslySetInnerHTML|http://

Source files only (exclude node_modules, .git, dist, build, *.min.js).

**Then:** Aggregate all findings with severity levels.

Scoring

Start at 100, deduct per finding:

  • critical: -20
  • high: -10
  • medium: -5
  • low: -2

Output Format

Return results as a JSON code block:

{
  "category": "security",
  "scores": { "security": 85 },
  "findings": [
    { "severity": "high", "category": "security", "subcategory": "deps", "file": "package.json", "message": "3 high-severity vulnerabilities in dependencies" }
  ],
  "fixes_available": 2
}
Ships withultraship

"ULTRASHIP" Claude Code plugin — 39 skills, 33 tools, 11 agents for ship-ready workflows: planning, review, pentesting, safety guardrails, canary monitoring, SEO/AI-readiness check, penetration testing, code review, competitive analysis, incident response. 1 dependency. 180 tests. MIT.

Get the whole plugin

Other agents on ultraship.