What problem does it solve?
This Skill helps identify and remediate security weaknesses that could compromise confidentiality, integrity, availability, privacy, tenant isolation, or privileged actions. It replaces checklist-driven reviews with architecture-aware threat analysis and evidence-based fixes.
Core Features & Use Cases
- Architecture-Led Auditing: Reconstruct assets, actors, trust boundaries, data flows, entry points, privileges, dependencies, and deployment assumptions before testing.
- Comprehensive Security Coverage: Examine authentication, authorization, injection, APIs, business logic, data protection, supply chain, infrastructure, runtime resilience, client surfaces, AI systems, and configuration.
- Evidence-Based Remediation: Trace attacker-controlled inputs to sensitive sinks, rank findings by realistic impact, propose safe fixes, verify regressions, and document reviewed, inapplicable, or deferred areas.
- Use Case: Apply it to a web application before release to uncover cross-tenant access flaws, SSRF, exposed secrets, weak session handling, vulnerable dependencies, and unsafe deployment settings.
Quick Start
Use the audit-security skill to perform a comprehensive security review of the specified path, fix safe findings, and provide a coverage ledger with residual risks.