Sponsor Suno AI Music arrow_forward
Skill

Absolute Audit

Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without suppressing. Complements the built-in /security-review. Triggers on "absolute audit", "security audit", "are we vulnerable", "scan for CVEs", "check for secrets/injection", "harden this".

Type
Skill
Repository
maddhruv/absolute
GitHub stars
215
License
MIT
Repo last updated
Jul 6, 2026
Version
0.5.0

What Absolute Audit is

Absolute Audit is a skill published in the maddhruv/absolute repository on GitHub, which has about 215 stars. The repository describes itself as: “Absolute Skills to 10x your Development Lifecycle”

A skill is a folder with a SKILL.md file: frontmatter with a name and a description, followed by instructions Claude follows. Claude loads a skill automatically when a task matches its description, and you can also run it directly with a slash and its name.

Skills work in Claude Code and in Claude Cowork, which makes Absolute Audit a portable way to give Claude the same method everywhere.

How to install Absolute Audit

Claude Code

  1. Download the absolute-audit folder from the repository.
  2. Save it as ~/.claude/skills/<skill-name>/SKILL.md for all projects, or .claude/skills/<skill-name>/SKILL.md for one project.
  3. Claude loads it automatically when a task matches; you can also run it with / and its name.

Claude Cowork

  1. Zip the skill folder so SKILL.md sits at the top level of the folder.
  2. Open Customize → Skills, click +, then upload the ZIP.
  3. Start a task that matches the description, or call it by name with /.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from skills/absolute-audit/SKILL.md, shared under the repository's MIT license. Read the full file on GitHub.

> Start your first response with the 🔒 emoji.

Absolute Audit

Find and triage security problems across the repo — vulnerable dependencies (CVEs) and risky code patterns — then fix the ones worth fixing, safely. Output is a severity-ranked findings table with a remediation per item, not a raw scanner dump.

Runs the shared engine in references/health-engine.md — read it for the DETECT → SCAN → TRIAGE → FIX → VERIFY → REPORT loop and the safety contract. This file covers only what's specific to security auditing.

> Authorized defensive use. This command audits the user's own repository to find > and fix weaknesses. It is for hardening, not for attacking systems or evading detection.

When to use

  • "Run a security audit", "are we vulnerable?", "check our deps for CVEs".
  • After a CVE disclosure affecting something you use.
  • Periodic hygiene on main.

Distinct from the built-in /security-review (reviews the pending diff on your branch) — audit scans the whole committed repo, deps included. They complement.

What it scans

1. Dependency vulnerabilities (CVEs) — primary:

2. Code-level patterns — read-only grep/static pass for high-signal issues only: hardcoded secrets/keys/tokens, eval/dynamic exec on input, SQL built by string concatenation, missing authz checks on sensitive routes, disabled TLS verification, unsafe deserialization, overly-broad CORS. Prefer the project's existing SAST/linter security rules (eslint-plugin-security, bandit, gosec) if configured.

Report suspected leaked secrets but never print the secret value — reference path:line and the kind.

Risk ranking (TRIAGE)

Rank by severity × exploitability × reachability, not raw CVSS:

Mark each: is it reachable from the app's actual code paths? A CVE in an unused transitive branch is lower priority than a Moderate one on a hot path. State the fixed version or the mitigation for each.

Fix & verify

  • Dep CVEs → resolve via the smallest version move that clears it (delegate the actual bump mechanics to the upgrade flow's per-ecosystem steps). Prefer patched minors; escalate to a major only when that's the only fix, and gate it.
  • Code issues → apply the concrete fix (parameterize the query, move the secret to env
  • flag the leaked one for rotation, add the authz check). Each fix is its own small wave.
  • After each wave, re-run the scanner: the finding must actually disappear, and tests/build stay green. Never resolve by suppressing/allowlisting the alert.
  • Leaked live secrets: flag for rotation — removing from code doesn't undo exposure.

Gotchas

  1. Audit fatigue → blanket ignore. Triage by reachability instead of muting the scanner.
  2. Fixing a CVE by suppressing it. An allowlisted advisory is still a vulnerability.
  3. Printing the secret. Reference location + type only; never echo the value.
  4. Deleting a secret from code ≠ safe. It's in git history and was exposed — rotate it.
  5. Stopping at deps. Many real issues are in code, not the dependency tree — run both passes.

Companion commands

  • /absolute upgrade — does the actual version moves for vulnerable deps.
  • /security-review (built-in) — pair with this to also cover your pending diff.
  • /absolute work — if remediation is a real refactor (e.g. replacing an auth flow), hand off.

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Absolute Audit?

Absolute Audit is a skill for Claude Code and Claude Cowork from the maddhruv/absolute repository on GitHub. Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without suppressing. Complements the built-in /security-review. Triggers on "absolute audit", "security audit", "are we vulnerable", "scan for CVEs", "check for secrets/injection", "harden this".

How do I install Absolute Audit in Claude Code?

Download the absolute-audit folder from the repository. Save it as ~/.claude/skills/<skill-name>/SKILL.md for all projects, or .claude/skills/<skill-name>/SKILL.md for one project. Claude loads it automatically when a task matches; you can also run it with / and its name.

Can I use Absolute Audit in Claude Cowork?

Zip the skill folder so SKILL.md sits at the top level of the folder. Open Customize → Skills, click +, then upload the ZIP. Start a task that matches the description, or call it by name with /.

Is Absolute Audit safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.