esaa-security-audit
Installation
SKILL.md
ESAA-Security Audit Skill
Skill by ara.so — Security Skills collection.
Overview
ESAA-Security applies the Event Sourcing for Autonomous Agents (ESAA) architecture to automated security auditing. It executes structured security audits across 16 security domains with 95 executable checks, governed by an immutable append-only event log. Every finding, classification, and remediation decision is recorded as a verifiable fact.
Key differentiators:
- Deterministic audits — same repository state produces same findings via event replay
- Hallucination prevention — schema-validated outputs with evidence requirements
- Complete audit trail —
.roadmap/activity.jsonlrecords every check execution - Governed agents — PARCER contracts enforce decision hygiene and token budgets
- Verifiable reports — SHA-256 hash verification from events to final output