Claude Code Security Audit Kit

Find vulnerabilities in your Claude Code setup before you share the repo or run Claude in CI.

Real CVEs, not hypothetical risks

These are documented vulnerabilities in Claude Code, not theoretical attack patterns:

The audit kit checks for all three, plus prompt injection risks in CLAUDE.md and over-trusted MCP servers.

What's in the kit

security-audit-kit/ ├── skills/ │ └── security-audit.md # Claude skill — run /security-audit inside Claude Code ├── scripts/ │ └── audit-claude-code.sh # Standalone shell scanner, works without Claude └── hooks/ └── pre-commit-claude-guard.sh # Git hook — blocks dangerous commits automatically

What it checks

Three ways to use it

Shell script (no Claude required):

bash audit-claude-code.sh

Exits 0 if no high-risk issues. Exits 1 if any are found. Runs in CI.

Claude skill:

mkdir -p .claude/skills
cp skills/security-audit.md .claude/skills/

Then: /security-audit in Claude Code. Claude reads your config files and produces a structured report.

Git pre-commit hook:

cp hooks/pre-commit-claude-guard.sh .git/hooks/pre-commit
chmod +x .git/hooks/pre-commit

Blocks commits containing bypassPermissions, wildcard permissions, or credential patterns before they reach the repo.

$19
One-time download. Instant access.
Download Security Audit Kit
Use LAUNCH for 20% off

Questions: zac@builtbyzac.com