security-audit

Installation
SKILL.md

Security Audit Workflow

Run a comprehensive security audit that combines automated static analysis, threat modeling, and multi-perspective council review. This skill produces a prioritized audit report with actionable remediation steps.

Scope Exclusions

[!IMPORTANT] This audit covers application-level security only. Production infrastructure (TLS termination, reverse proxy, network segmentation, firewall rules, DNS) is managed by a separate project and is out of scope. Do not flag missing TLS, reverse proxy configuration, network-level MITM risks, or production deployment topology as findings.

Step 1: Define Audit Scope

Ask the user:

  • Scope: Full codebase or specific area? (e.g., apps/api/src/auth/, apps/web/src/)
  • Trigger: What prompted this audit? (routine, pre-release, security incident, new feature, dependency update)
  • Focus areas: Authentication, API security, data protection, frontend security, or all?

CHECKPOINT: Confirm the audit scope and focus areas with the user before proceeding.

Related skills

More from andrewvaughan/agent-council

Installs
21
GitHub Stars
6
First Seen
Mar 20, 2026