Sponsor Suno AI Music arrow_forward
Plugin

Security Audit Reporter

Generate comprehensive security audit reports

Type
Plugin
GitHub stars
2.8k
License
MIT
Repo last updated
Sep 27, 2026
Version
1.28.0
Author
Jeremy Longshore

What Security Audit Reporter is

Security Audit Reporter is a plugin published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”

A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.

Installing Security Audit Reporter adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.

How to install Security Audit Reporter

Claude Code

  1. Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace
  2. Install the plugin: claude plugin install security-audit-reporter@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
  3. Restart the session if the new skills or commands don't appear straight away.

Claude Cowork

  1. Open Customize → Plugins and choose Add marketplace.
  2. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub).
  3. Find Security Audit Reporter in the list, click Install, then connect any connectors it needs from its Connectors tab.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/security/security-audit-reporter/.claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.

Generate comprehensive security audit reports with vulnerability assessments, compliance status, and remediation roadmaps.

Features

  • Executive Summaries - High-level security posture for leadership
  • Technical Details - In-depth vulnerability analysis for security teams
  • Compliance Tracking - OWASP, GDPR, HIPAA, PCI-DSS, SOC2 status
  • Remediation Roadmaps - Prioritized action plans
  • Multiple Formats - PDF, HTML, JSON, Markdown
  • Trend Analysis - Security metrics over time

Installation

/plugin install security-audit-reporter@claude-code-plugins-plus

Usage

# Generate full security audit report
/audit-report

# Or use shortcut
/auditreport

Report Structure

1. Executive Summary

SECURITY AUDIT REPORT
=====================
Organization: Example Corp
Audit Date: 2025-10-11
Auditor: Security Team

OVERALL SECURITY POSTURE: MODERATE RISK

Risk Score: 6.5/10 (Previous: 7.2/10) ↓ Improving
- Critical Issues: 2
- High Issues: 12
- Medium Issues: 34
- Low Issues: 67

TOP RECOMMENDATIONS:
1. Address SQL injection in customer portal (CRITICAL)
2. Implement multi-factor authentication (HIGH)
3. Upgrade vulnerable dependencies (HIGH)
…

2. Vulnerability Details

CRITICAL VULNERABILITIES
------------------------

CVE-2023-XXXX: SQL Injection in Authentication
Severity: Critical (CVSS 9.8)
Location: /api/auth/login
Status: Open
Age: 45 days

Description:
The login endpoint does not use parameterized queries,
allowing SQL injection via the username parameter.

Proof of Concept:
username=' OR '1'='1' --

Impact:
- Complete database access
…

3. Compliance Status

COMPLIANCE DASHBOARD
====================

OWASP Top 10 (2021): 70% Coverage
 A01: Broken Access Control - Partial
 A02: Cryptographic Failures - Non-Compliant
 A03: Injection - Addressed
 A04: Insecure Design - Issues Found
...

GDPR Compliance: 85%
 Data encryption at rest
 Right to deletion implemented
 Data processing agreements incomplete
 Privacy policy published

PCI-DSS: 60% (Not Ready for Audit)
 Requirement 2: Default passwords not changed
…

4. Security Controls Assessment

AUTHENTICATION & AUTHORIZATION
-------------------------------
 Password hashing (bcrypt)
 Multi-factor authentication (Not implemented)
 Session management (Secure cookies)
 Account lockout (Not configured)
 Password policy (12+ chars, complexity)

ENCRYPTION
----------
 TLS 1.3 for data in transit
 AES-256 for data at rest
 Database encryption (Not enabled)
 Secure key management

LOGGING & MONITORING
--------------------
 Security event logging (Minimal)
…

5. Remediation Roadmap

PRIORITY 1 - IMMEDIATE (0-7 days)
----------------------------------
1. Fix SQL injection vulnerabilities (4 hours)
2. Rotate exposed API keys (2 hours)
3. Patch critical CVEs in dependencies (4 hours)

PRIORITY 2 - SHORT TERM (1-4 weeks)
------------------------------------
4. Implement multi-factor authentication (40 hours)
5. Enable comprehensive security logging (16 hours)
6. Deploy WAF with OWASP ruleset (24 hours)
7. Implement rate limiting (8 hours)

PRIORITY 3 - MEDIUM TERM (1-3 months)
--------------------------------------
8. Complete GDPR compliance gaps (80 hours)
9. Implement database encryption (40 hours)
10. Deploy intrusion detection system (60 hours)
…

Audit Frequency

  • Critical Systems: Monthly
  • Production Systems: Quarterly
  • Development Systems: Bi-annually
  • After Major Changes: Immediate
  • Post-Incident: Immediate

Stakeholder Distribution

Executive Leadership

  • Executive summary
  • Risk trends
  • Budget requirements
  • Business impact

Security Team

  • Full technical report
  • Vulnerability details
  • Remediation steps
  • Testing procedures

Development Team

  • Code-specific findings
  • Secure coding guidelines
  • Fix priorities
  • Testing requirements

Compliance Team

  • Compliance status
  • Gap analysis
  • Policy updates
  • Audit preparation

Best Practices

  1. Regular Audits
  • Schedule recurring audits
  • Track metrics over time
  • Compare against industry benchmarks
  1. Actionable Findings
  • Clear remediation steps
  • Realistic timelines
  • Resource allocation
  • Verification procedures
  1. Stakeholder Engagement
  • Tailor reports to audience
  • Present findings clearly
  • Get commitment for fixes
  • Track remediation progress
  1. Continuous Improvement
  • Update security policies
  • Enhance security controls
  • Train development teams
  • Automate security testing

Requirements

  • Access to vulnerability scan results
  • Compliance framework documentation
  • Security control inventory
  • Previous audit reports for trending

License

MIT License - See LICENSE file for details

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Security Audit Reporter?

Security Audit Reporter is a plugin for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Generate comprehensive security audit reports

How do I install Security Audit Reporter in Claude Code?

Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace Install the plugin: claude plugin install security-audit-reporter@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.

Can I use Security Audit Reporter in Claude Cowork?

Open Customize → Plugins and choose Add marketplace. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub). Find Security Audit Reporter in the list, click Install, then connect any connectors it needs from its Connectors tab.

Is Security Audit Reporter safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.