security-audit
Installation
SKILL.md
Security Audit
Perform a structured security audit of code, configuration, and architecture. Identify vulnerabilities, rank them by severity, and recommend concrete fixes grounded in OWASP standards, framework-specific best practices, and DevSecOps controls.
This is a read-only analysis. Do not modify code — audit, then report.
Usage
/security-audit [scope]
- With no argument, audit the current branch's diff against the default branch.
- With a path or module name, audit that scope.
- Use
fullto audit the whole repository for systemic issues.
Knowledge Base
The audit draws on five reference areas. Load the relevant reference file when a finding needs grounding or when you need detailed requirements for a topic: