security-audit
Installation
SKILL.md
What I do
- Audit authentication & authorization (password hashing, MFA, sessions, RBAC, IDOR)
- Scan for injection vulnerabilities (SQL, XSS, command injection, path traversal)
- Review data protection at rest and in transit (encryption, TLS, sensitive data handling)
- Assess API surface security (rate limiting, CORS, query depth, pagination)
- Check dependency health (known CVEs, stale packages, license risks)
- Evaluate infrastructure hardening (containers, cloud IAM, firewall, SSH)
- Hunt hardcoded secrets and verify secret management hygiene
- Validate logging/monitoring for security events and anomaly detection
- Deliver a structured audit report with severity-graded findings and an action plan
When to use me
Activate this skill when:
- A user requests a security audit, security review, or vulnerability assessment
- A new feature, endpoint, or deployment surface is being introduced
- Pre-release hardening or compliance (GDPR, PCI-DSS, HIPAA, SOC 2) is needed