forge-security

Installation
SKILL.md
Contains Hooks

This skill uses Claude hooks which can execute code automatically in response to events. Review carefully before installing.

Forge Security

Cross-Platform AI Agent Skill This skill works with any AI agent platform that supports the skills.sh standard.

Security Audit

OWASP Top 10 2021 focused security audit for SaaS applications. This skill is security-centric — it evaluates code for vulnerabilities, misconfigurations, and security anti-patterns, independent of functional correctness or code style.

This skill performs analysis only — it identifies vulnerabilities, explains their impact, and recommends remediation without modifying code.

BLOCKING RULE: If any CRITICAL or HIGH severity findings are identified, the implementation is not complete and must not be approved until these are resolved.

Anti-Hallucination Guidelines

CRITICAL: Security findings must be grounded in actual code evidence:

  1. Read before reporting — Never report a vulnerability in code you have not read
  2. Exact references — Every finding must include file:line and a code excerpt
  3. No invented CVEs — Only reference real vulnerabilities when citing external context
Related skills
Installs
5
GitHub Stars
4
First Seen
Mar 26, 2026