What problem does it solve?
This Skill provides a repeatable, end-to-end security audit framework that helps teams identify, prioritize, and validate vulnerabilities in arbitrary source code repositories.
Core Features & Use Cases
- 10-phase audit methodology orchestrated by advisory intelligence, knowledge base construction, static analysis, risk modeling, deep bug hunting, and final reporting.
- Deterministic workflow with resumption that supports partial re-runs and incremental audits using persisted state.
- Integrated tooling & artifacts: CodeQL structural analysis outputs, Semgrep Pro passes, and domain threat modeling guidance embedded in KB.
- Operational guidance for large/complex repos: multi-component architectures, distributed systems, or non-standard stacks.
- Final reporting: consolidated vulnerability findings with PoCs and executive-ready final audit report.
Quick Start
Trigger a full repository audit to start Phase 1 intelligence gathering and initiate the 10-phase lifecycle.