Absolute Audit
Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without suppressing. Complements the built-in /security-review. Triggers on "absolute audit", "security audit", "are we vulnerable", "scan for CVEs", "check for secrets/injection", "harden this".
- Type
- Skill
- Repository
- maddhruv/absolute
- GitHub stars
- 215
- License
- MIT
- Repo last updated
- Jul 6, 2026
- Source file
- skills/absolute-audit/SKILL.md
- Version
- 0.5.0
What Absolute Audit is
Absolute Audit is a skill published in the maddhruv/absolute repository on GitHub, which has about 215 stars. The repository describes itself as: “Absolute Skills to 10x your Development Lifecycle”
A skill is a folder with a SKILL.md file: frontmatter with a name and a description, followed by instructions Claude follows. Claude loads a skill automatically when a task matches its description, and you can also run it directly with a slash and its name.
Skills work in Claude Code and in Claude Cowork, which makes Absolute Audit a portable way to give Claude the same method everywhere.
How to install Absolute Audit
Claude Code
- Download the absolute-audit folder from the repository.
- Save it as ~/.claude/skills/<skill-name>/SKILL.md for all projects, or .claude/skills/<skill-name>/SKILL.md for one project.
- Claude loads it automatically when a task matches; you can also run it with / and its name.
Claude Cowork
- Zip the skill folder so SKILL.md sits at the top level of the folder.
- Open Customize → Skills, click +, then upload the ZIP.
- Start a task that matches the description, or call it by name with /.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from skills/absolute-audit/SKILL.md, shared under the repository's MIT license. Read the full file on GitHub.
> Start your first response with the 🔒 emoji.
Absolute Audit
Find and triage security problems across the repo — vulnerable dependencies (CVEs) and risky code patterns — then fix the ones worth fixing, safely. Output is a severity-ranked findings table with a remediation per item, not a raw scanner dump.
Runs the shared engine in references/health-engine.md — read it for the DETECT → SCAN → TRIAGE → FIX → VERIFY → REPORT loop and the safety contract. This file covers only what's specific to security auditing.
> Authorized defensive use. This command audits the user's own repository to find > and fix weaknesses. It is for hardening, not for attacking systems or evading detection.
When to use
- "Run a security audit", "are we vulnerable?", "check our deps for CVEs".
- After a CVE disclosure affecting something you use.
- Periodic hygiene on main.
Distinct from the built-in /security-review (reviews the pending diff on your branch) — audit scans the whole committed repo, deps included. They complement.
What it scans
1. Dependency vulnerabilities (CVEs) — primary:
2. Code-level patterns — read-only grep/static pass for high-signal issues only: hardcoded secrets/keys/tokens, eval/dynamic exec on input, SQL built by string concatenation, missing authz checks on sensitive routes, disabled TLS verification, unsafe deserialization, overly-broad CORS. Prefer the project's existing SAST/linter security rules (eslint-plugin-security, bandit, gosec) if configured.
Report suspected leaked secrets but never print the secret value — reference path:line and the kind.
Risk ranking (TRIAGE)
Rank by severity × exploitability × reachability, not raw CVSS:
Mark each: is it reachable from the app's actual code paths? A CVE in an unused transitive branch is lower priority than a Moderate one on a hot path. State the fixed version or the mitigation for each.
Fix & verify
- Dep CVEs → resolve via the smallest version move that clears it (delegate the actual bump mechanics to the upgrade flow's per-ecosystem steps). Prefer patched minors; escalate to a major only when that's the only fix, and gate it.
- Code issues → apply the concrete fix (parameterize the query, move the secret to env
- flag the leaked one for rotation, add the authz check). Each fix is its own small wave.
- After each wave, re-run the scanner: the finding must actually disappear, and tests/build stay green. Never resolve by suppressing/allowlisting the alert.
- Leaked live secrets: flag for rotation — removing from code doesn't undo exposure.
Gotchas
- Audit fatigue → blanket ignore. Triage by reachability instead of muting the scanner.
- Fixing a CVE by suppressing it. An allowlisted advisory is still a vulnerability.
- Printing the secret. Reference location + type only; never echo the value.
- Deleting a secret from code ≠ safe. It's in git history and was exposed — rotate it.
- Stopping at deps. Many real issues are in code, not the dependency tree — run both passes.
Companion commands
- /absolute upgrade — does the actual version moves for vulnerable deps.
- /security-review (built-in) — pair with this to also cover your pending diff.
- /absolute work — if remediation is a real refactor (e.g. replacing an auth flow), hand off.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Absolute Audit?
Absolute Audit is a skill for Claude Code and Claude Cowork from the maddhruv/absolute repository on GitHub. Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without suppressing. Complements the built-in /security-review. Triggers on "absolute audit", "security audit", "are we vulnerable", "scan for CVEs", "check for secrets/injection", "harden this".
How do I install Absolute Audit in Claude Code?
Download the absolute-audit folder from the repository. Save it as ~/.claude/skills/<skill-name>/SKILL.md for all projects, or .claude/skills/<skill-name>/SKILL.md for one project. Claude loads it automatically when a task matches; you can also run it with / and its name.
Can I use Absolute Audit in Claude Cowork?
Zip the skill folder so SKILL.md sits at the top level of the folder. Open Customize → Skills, click +, then upload the ZIP. Start a task that matches the description, or call it by name with /.
Is Absolute Audit safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Subagent Fan out a one-shot or flat parallel batch of cc-fleet PROVIDER subagents (headless `cc-fleet subagent`) that return a result — DeepSeek /… Skill · ethanhq/cc-fleet
- D3.js Visualization Teaches Claude to produce D3 charts and interactive data visualizations Skill · chrisvoncsefalvay/claude-d3js-skill
- 12 Factor App The Twelve-Factor App methodology for building scalable, maintainable cloud-native applications. Use when designing backend services… Skill · pproenca/dot-skills
- Analyzing Changes Analyzes code changes, detects documentation drift, and evaluates change impact scope. Use when reviewing diffs, checking doc sync, or running pre-commit analysis. Automatically triggered after design-level changes or refactoring. Skill · telagod/code-abyss
- Wordpress Router Use when the user asks about WordPress codebases (plugins, themes, block themes, Gutenberg blocks, WP core checkouts) and you need to quickly classify the repo and route to the correct workflow/skill (blocks, theme.json, REST API, WP-CLI, performance, security, testing, release packaging). Skill · Automattic/agent-skills
- Analytics Metrics Build data visualization and analytics dashboards. Use when creating charts, KPI displays, metrics dashboards, or data visualization components. Triggers on analytics, dashboard, charts, metrics, KPI, data visualization, Recharts. Skill · hoodini/ai-agents-skills
- Alert Manager Use when the user asks to "set SEO alerts" or "排名掉了提醒我"; configures threshold notifications for FUTURE ranking, traffic, technical, and… Skill · aaron-he-zhu/seo-geo-claude-skills
- Accessibility Accessibility patterns for WCAG 2.2 compliance, keyboard focus management, React Aria component patterns, cognitive inclusion, native HTML-first philosophy, and user preference honoring. Use when implementing screen reader support, keyboard navigation, ARIA patterns, focus traps, accessible component libraries, reduced motion, or cognitive accessibility. Skill · yonatangross/orchestkit