Security Audit Reporter
Generate comprehensive security audit reports
- Type
- Plugin
- Repository
- jeremylongshore/tons-of-skills-marketplace
- GitHub stars
- 2.8k
- License
- MIT
- Repo last updated
- Sep 27, 2026
- Version
- 1.28.0
- Author
- Jeremy Longshore
What Security Audit Reporter is
Security Audit Reporter is a plugin published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Security Audit Reporter adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Security Audit Reporter
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace
- Install the plugin: claude plugin install security-audit-reporter@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub).
- Find Security Audit Reporter in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/security/security-audit-reporter/.claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.
Generate comprehensive security audit reports with vulnerability assessments, compliance status, and remediation roadmaps.
Features
- Executive Summaries - High-level security posture for leadership
- Technical Details - In-depth vulnerability analysis for security teams
- Compliance Tracking - OWASP, GDPR, HIPAA, PCI-DSS, SOC2 status
- Remediation Roadmaps - Prioritized action plans
- Multiple Formats - PDF, HTML, JSON, Markdown
- Trend Analysis - Security metrics over time
Installation
/plugin install security-audit-reporter@claude-code-plugins-plusUsage
# Generate full security audit report
/audit-report
# Or use shortcut
/auditreportReport Structure
1. Executive Summary
SECURITY AUDIT REPORT
=====================
Organization: Example Corp
Audit Date: 2025-10-11
Auditor: Security Team
OVERALL SECURITY POSTURE: MODERATE RISK
Risk Score: 6.5/10 (Previous: 7.2/10) ↓ Improving
- Critical Issues: 2
- High Issues: 12
- Medium Issues: 34
- Low Issues: 67
TOP RECOMMENDATIONS:
1. Address SQL injection in customer portal (CRITICAL)
2. Implement multi-factor authentication (HIGH)
3. Upgrade vulnerable dependencies (HIGH)
…2. Vulnerability Details
CRITICAL VULNERABILITIES
------------------------
CVE-2023-XXXX: SQL Injection in Authentication
Severity: Critical (CVSS 9.8)
Location: /api/auth/login
Status: Open
Age: 45 days
Description:
The login endpoint does not use parameterized queries,
allowing SQL injection via the username parameter.
Proof of Concept:
username=' OR '1'='1' --
Impact:
- Complete database access
…3. Compliance Status
COMPLIANCE DASHBOARD
====================
OWASP Top 10 (2021): 70% Coverage
A01: Broken Access Control - Partial
A02: Cryptographic Failures - Non-Compliant
A03: Injection - Addressed
A04: Insecure Design - Issues Found
...
GDPR Compliance: 85%
Data encryption at rest
Right to deletion implemented
Data processing agreements incomplete
Privacy policy published
PCI-DSS: 60% (Not Ready for Audit)
Requirement 2: Default passwords not changed
…4. Security Controls Assessment
AUTHENTICATION & AUTHORIZATION
-------------------------------
Password hashing (bcrypt)
Multi-factor authentication (Not implemented)
Session management (Secure cookies)
Account lockout (Not configured)
Password policy (12+ chars, complexity)
ENCRYPTION
----------
TLS 1.3 for data in transit
AES-256 for data at rest
Database encryption (Not enabled)
Secure key management
LOGGING & MONITORING
--------------------
Security event logging (Minimal)
…5. Remediation Roadmap
PRIORITY 1 - IMMEDIATE (0-7 days)
----------------------------------
1. Fix SQL injection vulnerabilities (4 hours)
2. Rotate exposed API keys (2 hours)
3. Patch critical CVEs in dependencies (4 hours)
PRIORITY 2 - SHORT TERM (1-4 weeks)
------------------------------------
4. Implement multi-factor authentication (40 hours)
5. Enable comprehensive security logging (16 hours)
6. Deploy WAF with OWASP ruleset (24 hours)
7. Implement rate limiting (8 hours)
PRIORITY 3 - MEDIUM TERM (1-3 months)
--------------------------------------
8. Complete GDPR compliance gaps (80 hours)
9. Implement database encryption (40 hours)
10. Deploy intrusion detection system (60 hours)
…Audit Frequency
- Critical Systems: Monthly
- Production Systems: Quarterly
- Development Systems: Bi-annually
- After Major Changes: Immediate
- Post-Incident: Immediate
Stakeholder Distribution
Executive Leadership
- Executive summary
- Risk trends
- Budget requirements
- Business impact
Security Team
- Full technical report
- Vulnerability details
- Remediation steps
- Testing procedures
Development Team
- Code-specific findings
- Secure coding guidelines
- Fix priorities
- Testing requirements
Compliance Team
- Compliance status
- Gap analysis
- Policy updates
- Audit preparation
Best Practices
- Regular Audits
- Schedule recurring audits
- Track metrics over time
- Compare against industry benchmarks
- Actionable Findings
- Clear remediation steps
- Realistic timelines
- Resource allocation
- Verification procedures
- Stakeholder Engagement
- Tailor reports to audience
- Present findings clearly
- Get commitment for fixes
- Track remediation progress
- Continuous Improvement
- Update security policies
- Enhance security controls
- Train development teams
- Automate security testing
Requirements
- Access to vulnerability scan results
- Compliance framework documentation
- Security control inventory
- Previous audit reports for trending
License
MIT License - See LICENSE file for details
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Security Audit Reporter?
Security Audit Reporter is a plugin for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Generate comprehensive security audit reports
How do I install Security Audit Reporter in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace Install the plugin: claude plugin install security-audit-reporter@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Security Audit Reporter in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub). Find Security Audit Reporter in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Security Audit Reporter safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Database Cache Layer Database plugin for database-cache-layer Plugin · jeremylongshore/tons-of-skills-marketplace
- Data Validation Engine Database plugin for data-validation-engine Plugin · jeremylongshore/tons-of-skills-marketplace
- Database Connection Pooler Implement and optimize database connection pooling for improved performance and resource management Plugin · jeremylongshore/tons-of-skills-marketplace
- Database Backup Automator Automate database backups with scheduling, compression, encryption, and restore procedures Plugin · jeremylongshore/tons-of-skills-marketplace
- Security Pro Pack Professional security tools for Claude Code: vulnerability scanning, compliance, cryptography audit, container & API security Plugin · jeremylongshore/tons-of-skills-marketplace
- Secrets Manager Integrator Integrate with secrets managers (Vault, AWS Secrets Manager, etc) Plugin · jeremylongshore/tons-of-skills-marketplace
- Security Test Scanner Automated security vulnerability testing covering OWASP Top 10, SQL injection, XSS, CSRF, and authentication issues Plugin · jeremylongshore/tons-of-skills-marketplace
- Secret Scanner Scan codebase for exposed secrets, API keys, passwords, and sensitive credentials Plugin · jeremylongshore/tons-of-skills-marketplace