Authorized Artifact Auditor
A CLI toolkit plus AI Agent skills for authorized software auditing — from binary fingerprinting to SBOM, CVE intel and remediation reports.
- Source repo
- ptn1411/skill
- Stars
- ★ 210
- Last updated
- 8d ago
- Primary language
- Python
- FA score
- 40/100 · Major gaps
At a glance
- How it runs
- Works with
- Universal · cross-platformChatGPT · Codex · Claude Code
- Cost
- Free, no paid service needed
- Setup effort
- Medium · a few setup steps
- You'll need
- Typical use
- A security engineer receives an internal Electron desktop app, unpacks the ASAR, audits webPreferences and preload bridges, and produces a remediation report.
- Not a fit if
- Users who need a GUI and avoid the terminal
- Teams wanting one-click cloud scanning without local setup or optional external tools
- Users who intend to test systems without authorization
- Source review
- 40/100 · Major gaps 1 safety controls not found
What does this agent do, and when should you use it?
This repository combines a Python CLI toolkit with AI Agent skill instructions for authorized software and infrastructure auditing. Its entry points are scripts/full_assess.py and scripts/orchestrate.py, which classify a target (IP, web URL, binary, bundle, sourcemap) and dispatch to the matching skill chain. Dedicated subdirectories cover binary identification, Electron unpacking and configuration analysis, JavaScript sourcemap recovery, Android APK static analysis, SBOM and supply-chain review, Docker/Kubernetes/Terraform/cloud configuration checks, passive web recon, an integrated Nmap scanner, Windows Event Log threat hunting, and CVE/exploit intelligence lookup across CISA KEV, FIRST EPSS, NIST NVD, Exploit-DB and GitHub PoC sources. Each skill is self-contained with its own SKILL.md, scripts/ and references/, and outputs structured reports with severity ratings and remediation guidance into output/. The project provides both a link_skills.py synchronizer for AI Agent global config directories and standalone Python scripts that can be run without any agent.
The toolkit is a set of independent Python CLI scripts that read local files, URLs, or network targets and write structured reports. scripts/orchestrate.py and scripts/assess.py classify a target path or URL (IP, web URL, binary, file bundle, sourcemap) and invoke the corresponding skill scripts; --dry-run previews the dispatch. binary-identifier/scripts/identify_app.py reads a binary and emits language, compiler, packager and framework fingerprints. electron-builder-unpacker/scripts/unpack_electron_builder.py unpacks Electron/ASAR bundles, and electron-app-analyzer/scripts/analyze_electron.py audits IPC, webPreferences and preload bridge configuration. javascript-deobfuscator/scripts/extract_sourcemap.py restores JS source from .map files, and android-apk-pentester/scripts/analyze_apk.py performs static analysis of APK/XAPK packages. vulnerability-lookup/scripts/lookup_vuln.py queries CISA KEV, FIRST EPSS, NIST NVD, Exploit-DB and GitHub PoC sources for a CVE, while searching-exploit-db/scripts/search_exploit_db.py searches a local Exploit-DB copy. container-cloud-auditor/scripts/analyze_container_cloud.py inspects Dockerfiles, Kubernetes YAML, Terraform and cloud configs, and sbom-supply-chain-auditor/scripts/analyze_supply_chain.py builds an SBOM, audits dependencies and flags dependency-confusion or malicious packages. web-app-scanner/scripts/web_recon.py performs passive recon (security headers, TLS, CORS, endpoint leaks), with sqli_test.py gated behind --authorized; network-scanner/scripts/nmap_scan.py wraps Nmap. windows-log-hunter/scripts/hunt_eventlog.py hunts local Windows Event Logs. All results are written under output/ with severity grading and defensive remediation suggestions.
- A security engineer receives an internal Electron desktop app, unpacks the ASAR, audits webPreferences and preload bridges, and produces a remediation report.
- A DevOps team runs container-cloud and SBOM supply-chain audits on Dockerfiles, Kubernetes YAML and Terraform before a release, generating dependency and SBOM evidence.
- A red or blue team with written authorization looks up CVE-2024-6387 or CVE-2021-44228 and aggregates CISA KEV, EPSS, NVD and Exploit-DB intel without executing exploits.
- A mobile security analyst statically inspects an internal APK/XAPK for permissions, components and misconfigurations without running the app.
- A Windows incident responder hunts local Event Logs for suspicious accounts, log clearing and attack traces using windows-log-hunter.
- An AI Agent user syncs the whole skill set into Claude Code or Gemini CLI so the agent can call the scripts inside an audit workflow.
How do you install or deploy this agent?
Python 3.10 or newer is required. Clone the repository and install Python dependencies:
git clone https://github.com/ptn1411/skill.git
cd skill
python -m pip install -r requirements.txtTo sync all skills into the global config directories of supported AI Agents (recommended on Windows):
python scripts\link_skills.pyOr create an NTFS directory junction:
python scripts\link_skills.py --mode junctionExternal tools (Node.js, asar, Android SDK, JADX, Nmap, ilspycmd) are only needed for the workflows that use them; see TOOLS.md. Manifest configuration for other CLI agents (Codex, OpenAI) is documented in INSTALL.md.
How do you use this agent?
The primary entry point is the orchestration script, which classifies the target and runs the matching chain:
python scripts\full_assess.py https://app.example.com --out output\assessment
python scripts\full_assess.py 192.168.1.10 --out output\assessment
python scripts\orchestrate.py "C:\path\to\owned-app.exe" --out output
python scripts\orchestrate.py "C:\path\to\app-folder" --out output
python scripts\assess.py example.com --dry-runVulnerability intelligence and Exploit-DB search:
python vulnerability-lookup\scripts\lookup_vuln.py --cve CVE-2024-6387
python vulnerability-lookup\scripts\lookup_vuln.py --cve CVE-2021-44228 --out output\cve-report
python searching-exploit-db\scripts\search_exploit_db.py --cve CVE-2021-44228
python searching-exploit-db\scripts\search_exploit_db.py --query "OpenSSH 9.8"Container, cloud and supply-chain audits:
python container-cloud-auditor\scripts\analyze_container_cloud.py . --out output\container-cloud
python sbom-supply-chain-auditor\scripts\analyze_supply_chain.py . --out output\sbomWeb recon, controlled SQLi testing and network scanning:
python web-app-scanner\scripts\web_recon.py https://example.com --out output\web-recon
python web-app-scanner\scripts\sqli_test.py "https://example.com/item?id=1" --authorized
python network-scanner\scripts\nmap_scan.py 192.168.1.0/24 --profile quick --out output\nmapBinary, Electron, sourcemap, APK and Windows log workflows:
python binary-identifier\scripts\identify_app.py target.exe
python electron-builder-unpacker\scripts\unpack_electron_builder.py app-dir --out output\electron-unpacked
python electron-app-analyzer\scripts\analyze_electron.py output\electron-unpacked --out output\electron-analysis
python javascript-deobfuscator\scripts\extract_sourcemap.py "https://example.com/app.js.map" output\recovered-js
python android-apk-pentester\scripts\analyze_apk.py app.apk --out output\apk-analysis
python windows-log-hunter\scripts\hunt_eventlog.py --out output\huntRegression tests and skill contract validation:
python -m unittest discover -s tests -v
python orchestrator-plugin-sdk\scripts\validate_skill_contract.py container-cloud-auditorWhat are this agent's strengths and limitations?
- Ships both AI Agent skill instructions and standalone Python CLIs, so the same workflows run inside Claude Code / Gemini CLI or directly from a terminal
- Broad coverage: binary fingerprinting, Electron unpacking and config analysis, sourcemap recovery, APK static analysis, SBOM, container/cloud config checks, web recon, Nmap, Windows Event Logs and CVE intelligence
- Orchestration scripts (orchestrate.py, full_assess.py) auto-dispatch by target type and offer a --dry-run preview
- CVE lookup aggregates CISA KEV, FIRST EPSS, NIST NVD, Exploit-DB and GitHub PoC sources without downloading or running exploits
- Includes a MASTER_POLICY.md authorization boundary and a regression/contract test workflow that keeps skills consistent
- link_skills.py syncs skills into AI Agent config directories in one command, with a Windows junction mode
- Several workflows depend on external tools (Node.js, asar, Android SDK, JADX, Nmap, ilspycmd), increasing setup effort
- README examples and link_skills.py are PowerShell-oriented, so cross-platform users must adapt paths and commands
- License is listed as unknown, so redistribution and commercial use terms need to be verified first
- Requires Python 3.10+ and does not document an official packaged release or container deployment path
- Primary documentation is in Vietnamese, adding a reading burden for non-Vietnamese users
- No standard packaging for a specific Agent platform is described; integration depends on each agent's own manifest format
How does this agent compare with similar options?
Key facts side by side with the most closely related agents.
| Agent | Source review | Form / cost | Stars | Updated | Language | Full support on |
|---|---|---|---|---|---|---|
| Authorized Artifact Auditor This agent | 40 · Major gaps | CLIFree | ★ 210 | 8d ago | Python | ChatGPT · Codex · Claude Code |
| PentestCode | 55 · Major gaps | CLIFree + model costs | ★ 715 | 28d ago | TypeScript | OpenAI API · Claude API |
| Semia — Security Audit for AI Agent Skills | 59 · Major gaps | CLIFree + model costs | ★ 608 | 3mo ago | Python | Codex · Claude Code · OpenAI API · Claude API |
| PentestAgent | 50 · Major gaps | CLIFree + model costs | ★ 3.1k | 9d ago | Python | OpenAI API · Claude API |
How does FollowAgents rate this agent?
Why each dimension lost points
README restricts use to owned or explicitly authorized assets and references MASTER_POLICY.md; sqli_test.py requires an --authorized flag, which is thin evidence of user confirmation. least_privilege scores 1: link_skills.py copies/links all skills into global ~/.gemini and ~/.claude config, a broad scope with no minimization rationale. data_flow_transparency and sensitive_data_handling score 1: README advises not committing secrets and redacting reports, but never states runtime data flows, egress, or log retention. dependency_security scores 1: requirements.txt uses only lower bounds (requests>=2.31.0 etc.) with no lockfile, hashes, or audit record. external_effects scores 1: full_assess/nmap_scan actively scan network targets; authorization is asserted but there is no default dry-run or quantified blast radius. rollback scores 0: no rollback, undo, or recovery mechanism is described. source_attribution scores 1: project structure is documented but third-party tools/data sources are not attributed.
self_consistency scores 2: README capabilities align with modules exercised in tests (android-apk-pentester, binary-identifier, container-cloud-auditor, orchestrate) and naming is consistent. dependency_availability scores 1: pyinstxtractor-ng, ilspycmd, mitmproxy, frida-tools are commented out or external, with no availability check or degradation path. failure_messages scores 1: tests assert return codes and output tails, but source is not shown, so diagnostic quality of error messages cannot be confirmed.
audience_and_scenarios scores 2: README targets security audit/defense with multiple target classes (IP, URL, binary, APK, sourcemap). capability_boundaries scores 2: it explicitly disclaims bypassing controls and does not auto-download or run exploits, keeping to defensive advice. trigger_precision scores 1: orchestrate.py auto-classification logic is not shown, so trigger conditions cannot be judged. environment_fit scores 1: examples are PowerShell/Windows-centric; cross-platform fit beyond Python 3.10+ is not fully addressed.
information_architecture scores 2: README is well structured with capability table, install, commands, layout, tests, contribution. install_notes scores 2: pip install, link_skills.py sync, and on-demand external tools are documented. naming_stability scores 1: skill directory naming is fairly consistent but there is no versioned naming or stability commitment. examples_and_faq scores 2: command examples are plentiful across skills. known_limitations scores 1: only scattered notes about optional external tools; no consolidated limitations section. license scores 0: license metadata is unknown and no LICENSE file is present. versioning_changelog scores 0: no version number or changelog. maintenance_responsibility scores 1: contribution guide and issue channel exist, but publisher identity is unverified and the responsible maintainer is unclear.
output_usability scores 2: outputs are structured reports with severity grading and remediation advice, adequate for ordinary use. marginal_value scores 2: it integrates multiple audit skills with orchestration, adding value over single-purpose tools. cost_benefit scores 1: heavy external dependencies (Nmap, JADX, mitmproxy, frida) plus global skill sync raise cost while benefit is unquantified.
claim_traceability scores 1: README capability claims are not individually tied to verifiable source or test evidence. cross_source_corroboration scores 1: README and tests partially corroborate each other but coverage is incomplete. fact_inference_separation scores 1: capability descriptions and safety promises are interleaved without distinguishing verified facts from inference.
- Not found in source: rollback or recovery pathBack up first, or work on a git branch or snapshot, so its changes can be undone.
- Publisher identity is unverified; maintenance responsibility and update path are unclear, so verify independently before use.
- link_skills.py syncs all skills into global AI agent config directories, a broad scope; review before running.
- requirements.txt uses only lower-bound versions with no lockfile or hashes, leaving supply-chain risk unmitigated.
- Network scanning and SQLi testing have external effects with no default dry-run or blast-radius statement; confirm authorization scope.
- The repository lacks a LICENSE and any version/changelog, weakening compliance and traceability.