Skip to content
Development
Skill

/dev-security-audit

Comprehensive developer workstation security audit — scans for exposed credentials, compromised application data, persistence mechanisms, and supply chain attack indicators. Use this skill whenever the user suspects their machine may be compromised, wants to check for exposed

From plugin
sd0x-dev-flow
18899 skills16 agents5 hooks
Install
$ npx -y skills add sd0xdev/sd0x-dev-flow --skill dev-security-audit --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/dev-security-audit

Context preview

The summary Claude sees to decide when to auto-load this skill.

Comprehensive developer workstation security audit — scans for exposed credentials, compromised application data, persistence mechanisms, and supply chain attack indicators. Use this skill whenever the user suspects their machine may be compromised, wants to check for exposed

SKILL.md

dev-security-audit.SKILL.md
name: dev-security-audit
description: "Comprehensive developer workstation security audit — scans for exposed credentials, compromised application data, persistence mechanisms, and supply chain attack indicators. Use this skill whenever the user suspects their machine may be compromised, wants to check for exposed secrets, asks about supply chain attacks, or wants a full security audit of their development environment. Also triggers on: 'am I compromised', 'check my security', 'scan for leaked keys', 'credential audit', 'supply chain attack', 'supply chain check', 'check if I was hacked'."

Developer Workstation Security Audit

A systematic, multi-phase security audit for developer workstations. Checks for supply chain compromise indicators (via case-based IoC library at `references/cases/`), scans for exposed credentials across 20+ categories, and generates a prioritized remediation plan.

When to Use

  • User suspects their machine was compromised
  • User wants to check for exposed secrets/credentials
  • User heard about a supply chain attack and wants to check if affected
  • User wants a general security audit of their dev environment
  • Post-incident response: credential rotation planning

When NOT to Use

  • Code-level security review (use `/codex-security` or `/security-review`)
  • Dependency vulnerability audit (use `/dep-audit`)
  • OWASP Top 10 web app audit (use `/codex-security`)
  • Runtime application security testing

Workflow Overview

sequenceDiagram
    participant U as User
    participant C as Claude
    participant S as System
    C->>S: Phase 0: Supply Chain IoC Dispatch (case-driven)
    C->>S: Phase 1: Credential & Secret Exposure Scan
    C->>S: Phase 2: Application & Browser Data Scan
    C->>S: Phase 3: Persistence & Backdoor Check
    C->>U: Phase 4: Report Generation & Remediation Plan

Run phases sequentially. Each phase produces findings that feed into the final report. Use the reference files for detailed scan targets and IoC lists.

**Evidence preservation**: Before any cleanup or deletion, always copy/archive artifacts for forensic analysis. Never destroy evidence before the report is generated.

Phase 0: Supply Chain IoC Dispatch

Check for known supply chain compromises using the case library (`references/cases/`). This phase is conditional — it runs only when matching cases are found.

Dispatch Algorithm

1. **Detect platform**: macOS / Linux / Windows 2. **Load case catalog**: Read `references/cases/README.md` for active cases 3. **Scan product presence**: For each active case, check if the product is installed on the system 4. **Execute matching cases**: Load the case file and run its Detection Commands section

Dispatch Rules

| Condition | Action | |-----------|--------| | No matching case (product not installed) | Skip Phase 0, proceed to Phase 1 | | Single match | Load case file, run detection + interpretation | | Multiple matches | Iterate: execute each case sequentially |

Output Contract

For each matched case, report:

| Field | Description | |-------|-------------| | `case_id` | From case frontmatter (e.g., `PRODUCT-YYYY-MM`) | | `status` | `COMPROMISED` / `INCONCLUSIVE` / `CLEAN` / `NOT_INSTALLED` | | `confidence` | From case frontmatter + detection result |

If any case returns `COMPROMISED`, execute evidence preservation per case file instructions before proceeding.

Phase 1: Credential & Secret Exposure Scan

Scan for ALL sensitive files an attacker with user-space read access could have exfiltrated. This scan reveals credential hygiene issues regardless of supply chain compromise status.

Read `references/scan-targets.md` for the complete list. Below is the execution strategy.

Scan Strategy

Run scans in parallel where possible (use subagents for independent categories). Group into 3 parallel tracks:

**Track A — Cloud & Infrastructure Credentials:**

  • AWS (`~/.aws/credentials`, `~/.aws/config`)
  • GCP (`~/.config/gcloud/` — credentials.db, access_tokens.db, application_default_credentials.json)
  • Azure (`~/.azure/`)
  • Kubernetes (`~/.kube/config`, `~/.kube/custom-contexts/`)
  • Terraform (`~/.terraform.d/credentials.tfrc.json`)
  • Docker (`~/.docker/config.json`)

**Track B — Development Tool Tokens:**

  • SSH keys (`~/.ssh/`)
  • Git credentials (`~/.git-credentials`, `~/.gitconfig`)
  • GitHub CLI (`~/.config/gh/`)
  • GitLab CLI (`~/.config/glab-cli/`)
  • npm (`~/.npmrc`)
  • GPG keys (`~/.gnupg/private-keys-v1.d/`)

**Track C — Application Secrets & History:**

  • Shell history token scan (grep for patterns below)
  • `.env` files (`find ~ -maxdepth 5 \( -name ".env" -o -name ".env.*" \) 2>/dev/null | grep -v node_modules | grep -v .git`)
  • Crypto wallets (Solana, Electrum, etc.)
  • VPN configs (`*.ovpn`, WireGuard)

Parallel Scan Merge Rules

| # | Rule | Description | |---|------|-------------| | 1 | Subagent parallel | Tracks A/B/C may run via subagents in parallel for speed | | 2 | Unified output schema | All tracks emit: `Category \| Path \| Severity \| Redacted Sample \| Action` | | 3 | Dedup by key | Merge results using `(Path + Indicator Type + Token Prefix)` as dedup key | | 4 | Critical bubble-up | Critical/Critical+ findings surface immediately — do not wait for full scan |

Token Pattern Reference

Use these regex patterns to extract tokens from shell history and .env files:

OpenAI:           sk-[a-zA-Z0-9_-]{20,}
Anthropic:        sk-ant-[a-zA-Z0-9_-]{20,}
GitHub Classic:   gh[posur]_[a-zA-Z0-9]{20,}
GitHub Fine-grain: github_pat_[a-zA-Z0-9_]{20,}
GitLab PAT:       glpat-[a-zA-Z0-9_-]{20,}
AWS Access:       AKIA[A-Z0-9]{16}
AWS Temp:         ASIA[A-Z0-9]{16}
HuggingFace:      hf_[a-zA-Z0-9]{20,}
npm:              npm_[a-zA-Z0-9]{20,}
Docker Hub:       dckr_pat_[a-zA-Z0-9_-]{20,}
Slack:            xox[bsrp]-[a-zA-Z0-9-]{20,}
Stripe:           [rs]k_live_[a-zA-Z0-9]{20,}
Firebase:         AIza[a-zA-Z0-9_-]{30,}
JWT:              eyJ[a-zA-Z0-9_-]+\.eyJ[a-zA-Z0-9_-]+\.[a-zA-Z0-9_-]+
Read more
Ships withsd0x-dev-flow

Language: English | 繁體中文 | 简体中文 | 日本語 | 한국어 | Español The harness layer for Claude Code. Let the model choose the path. Keep "done" verifiable. Full control plane on Claude Code. Skills-only distribution for Codex CLI and other compatible agents.

Get the whole plugin

Other skills on sd0x-dev-flow.