sec-config-auditor
Installation
SKILL.md
Configuration Auditor
This skill focuses on the security of the infrastructure and deployment environment, specifically targeting A02:2025 – Security Misconfiguration and A09:2025 – Security Logging & Alerting Failures.
Usage
Triggers when reviewing infrastructure-as-code (IaC), reverse proxy settings, container configurations, or environment variable templates.
Example Triggers:
- "Can you audit my
Dockerfileanddocker-compose.ymlfor security best practices?" - "Review my NGINX configuration. Are my security headers correct?"
- "Check these Kubernetes manifests for any overly permissive role bindings."
Workflow
When analyzing configuration files, the AI should check against the following hardening checklists: