security-audit
Installation
SKILL.md
Security Audit
Review security posture, trust boundaries, and unsafe defaults.
Scope
1. Trust boundaries and access control
- auth and trust boundaries
- authorization gaps between clients, sessions, and operations
- endpoint exposure and listener defaults
2. Transport and encryption
- transport security (
http/wsvshttps/wss) - sensitive payloads traversing insecure channels
- key/secret handling: env-based sourcing, redacted logs, no plaintext persistence