security-audit

Installation
SKILL.md

What I do

  • Audit authentication & authorization (password hashing, MFA, sessions, RBAC, IDOR)
  • Scan for injection vulnerabilities (SQL, XSS, command injection, path traversal)
  • Review data protection at rest and in transit (encryption, TLS, sensitive data handling)
  • Assess API surface security (rate limiting, CORS, query depth, pagination)
  • Check dependency health (known CVEs, stale packages, license risks)
  • Evaluate infrastructure hardening (containers, cloud IAM, firewall, SSH)
  • Hunt hardcoded secrets and verify secret management hygiene
  • Validate logging/monitoring for security events and anomaly detection
  • Deliver a structured audit report with severity-graded findings and an action plan

When to use me

Activate this skill when:

  • A user requests a security audit, security review, or vulnerability assessment
  • A new feature, endpoint, or deployment surface is being introduced
  • Pre-release hardening or compliance (GDPR, PCI-DSS, HIPAA, SOC 2) is needed
Installs
1
GitHub Stars
2
First Seen
Jul 15, 2026
security-audit — shahboura/agents-opencode