security-audit

Installation
SKILL.md

Security Audit Pro

Use this skill for defensive security audits only. The user must own the target or have explicit authorization before any active probing, crawler-based DAST, fuzzing, brute-force simulation, or scanner that sends vulnerability payloads.

Core Rule

Be powerful, but evidence-driven and non-destructive:

  • Prefer local source, configs, lockfiles, logs, and official docs over guessing.
  • Run passive/local checks first.
  • Ask before active DAST on a public or third-party target unless the user already gave explicit authorization for that exact target.
  • Never print secrets. If a secret-like value is found, report only file, line, type, and a short redacted prefix/suffix.
  • Do not exploit, persist access, bypass auth, dump data, run credential attacks, or cause service degradation.

Audit Levels

Installs
2
GitHub Stars
2
First Seen
Jun 15, 2026
security-audit — xsourabhsharma/ai-security-audit-pro