smithery/kimhons

ralph-security-audit

Run comprehensive security audit combining multiple scanners (npm audit, pip-audit, semgrep, trivy) with secret detection, dependency vulnerability scanning, and OWASP Top 10 checks. Use for security review before deployment or during PR review.

Installation

$ npx skills add smithery/kimhons --skill ralph-security-audit

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from smithery/kimhons.

npx skills add smithery/kimhons

Browse all from smithery/kimhons

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Skill metadata

Parsed from SKILL.md frontmatter.

Allowed toolsRead, Bash, Grep, Glob

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,677 B
  • docs SUMMARY.md 273 B

History

  1. First recorded snapshot · 0 installs

SKILL.md

Ralph Ultra Security Audit

Comprehensive multi-scanner security analysis.

What this does

  1. Dependency scanning — npm audit, pip-audit, cargo-audit
  2. Static analysis — semgrep with auto-config rules
  3. Container scanning — trivy for Docker images
  4. Secret detection — Regex-based scan for API keys, tokens, passwords
  5. OWASP Top 10 — Check for common vulnerability patterns
  6. License audit — Flag copyleft licenses in commercial projects

Usage

/ralph-ultra:ralph-security-audit [--fix] [--severity critical,high]

Options

Option Description
--fix Auto-fix safe vulnerabilities (patch updates)
--severity Only report issues at specified levels

Severity Levels

  • CRITICAL — Immediate action required (RCE, auth bypass)
  • HIGH — Fix before deployment (SQL injection, XSS)
  • MEDIUM — Fix in next sprint (info disclosure, CSRF)
  • LOW — Track for later (deprecated APIs, minor config issues)

Scanners Used

Runs whichever tools are available:

  • npm audit / yarn audit — Node.js dependencies
  • pip-audit / safety — Python dependencies
  • semgrep — Multi-language SAST
  • trivy — Container and filesystem scanning
  • Built-in regex — Hardcoded secrets, insecure URLs, .env exposure