security-audit

Originally from89jobrien/steve
Installation
SKILL.md

Security Audit: Multi-Pass Application Security Review

Structured, multi-pass security audit. Combines automated tooling with manual pattern analysis, maps findings to OWASP Top 10:2025, and produces a prioritized report.

Patterns drawn from real OSS incidents (unauthenticated admin endpoints, credential exfiltration, zip slip, auth bypass whitelists, Trivy supply chain compromise) and OpenSSF/SLSA/OWASP standards.

Target versions (September 2026, release check 2026-09-10):

  • Semgrep 1.176.0, Bandit 1.9.4
  • Gitleaks 8.30.1, Betterleaks 1.8.1 (same author as Gitleaks), TruffleHog 3.97.4
  • Trivy 0.74.0 (0.69.4-0.69.6 was compromised - see known incidents; upgrade past the 0.69.x window)
  • OpenSSF Scorecard 5.5.0 (v6 in proposal stage)
  • OWASP Top 10:2025 (confirmed January 2026), OWASP Agentic Top 10:2026 (released December 2025)

Scope: TypeScript/JavaScript (Bun, Node.js, Deno), Python, Go, Rust web applications, CLI tools, Dockerfiles, Compose stacks, CI/CD workflows, Helm charts, Terraform, Proxmox/LXC configs, shell scripts. This skill is SAST + config + supply chain. Not DAST or network pentesting.

When to use

Installs
44
GitHub Stars
7
First Seen
Apr 1, 2026
security-audit — iuliandita/skills