audit-security

Audit web applications, APIs, MCP servers, and AI agents for OWASP/CWE vulnerabilities.

4|1|Updated Dec 30, 2025
One-click install
npx skills add https://github.com/lushly-dev/afd --skill audit-security-lushly-dev
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: audit-security
Source: https://github.com/lushly-dev/afd/tree/main/.claude/skills/audit-security
Command: npx skills add https://github.com/lushly-dev/afd --skill audit-security-lushly-dev

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill addresses the critical need for thorough security assessments across diverse digital assets, from web applications to AI agent systems, ensuring robust protection against evolving threats.

Core Features & Use Cases

  • Vulnerability Discovery: Identifies OWASP/CWE-mapped vulnerabilities in web apps, APIs, and MCP servers.
  • Threat Modeling: Guides the process of identifying assets, trust boundaries, and abuse cases to focus audit efforts.
  • Agent & MCP Security: Reviews AI agent permission models and hardens MCP server configurations.
  • Use Case: A development team needs to ensure their new microservice is secure before deployment. They use this Skill to perform a comprehensive security audit, identify potential vulnerabilities, and receive actionable remediation steps.

Quick Start

Use the audit-security skill to perform a security audit on the provided codebase.

Frequently Asked Questions about audit-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit on an MCP server?

To perform an MCP server security audit, you review security configurations, harden server settings, and assess agent permission models to identify vulnerabilities and ensure robust protection against evolving threats.

How does threat modeling identify CWE vulnerabilities in web applications?

Threat modeling identifies CWE vulnerabilities in web applications by mapping out assets, defining trust boundaries, and analyzing abuse cases to focus audit efforts on discovering security configuration weaknesses.

Can I use this security audit approach for AI agent systems?

Yes, this security audit approach works for AI agent systems by reviewing agent permission models, hardening MCP server configurations, and assessing supply chain security practices to identify potential vulnerabilities.

What is the best way to integrate SAST and DAST tooling for vulnerability assessment?

The best way to integrate SAST and DAST tooling for vulnerability assessment is to guide their configuration within the audit process, enabling comprehensive OWASP-mapped vulnerability discovery across your web apps and APIs.

When do I need a comprehensive security audit for my APIs?

You need a comprehensive security audit for your APIs before deploying new microservices, ensuring that OWASP and CWE vulnerabilities are identified and actionable remediation steps are provided for robust protection.