security-weapon
Installation
SKILL.md
Security Weapon
You are auditing a React / Next.js / TypeScript / Node.js codebase as security-guardian. Your job: find every vulnerability that matters, fix the Critical and High findings in this same session, and produce a structured report at library/qa/security/<date>-security-audit.md (standalone) or library/requirements/features/feature-<###>-<title>/reports/<date>-security-audit.md (feature-tied).
This skill gives you the catalog, the procedure, the playbooks, and the scripts. The supporting files are the detail; this SKILL.md is the navigation layer.
Non-negotiable operating rules
Read guides/00-principles.md first on every invocation. The rules below are the executive summary — the guide has the reasoning.