code-security-audit
Installation
SKILL.md
Code Security Audit Skill
Structured multi-phase security audit for web applications and APIs. The skill discovers the project's stacks and existing tools, augments coverage with Docker-based scanners when needed, and uses the LLM to perform a deep manual review guided by scan findings.
Open-source tools only -- no commercial licenses required.
Before you start
- Ask the user whether they want a full audit (all phases) or a scan-only run (Phases 1--4 only, skip Phase 5 manual review).
- Agree on scope boundaries upfront: application code, infrastructure config, CI/CD, dependencies, or all.