kernel-audit-security
Installation
SKILL.md
Security work in two modes. Pick by request intent; if ambiguous, ask one question.
Evidence bar (both modes)
Every finding must include file and line evidence, a concrete attack scenario ("send this request, get this result" — not "an attacker could theoretically"), impact, confidence, and remediation. Defense-in-depth gaps are hardening notes, not findings. Severity requires demonstrated likelihood and impact. Do not pad reports with LOW findings; say what the codebase does well.
Mode 1: Review (scoped, checklist-grounded)
Use the vendored specialist skills under reviews/ with their procedures under plays/: