auditing-security

Audit code, deployment, and sprint artifacts across five categories into SECURITY-AUDIT-REPORT.md and findings.jsonl.

3|Updated Nov 25, 2025
One-click install
npx skills add https://github.com/AITOBIAS04/Echelon --skill auditing-security-aitobias04
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: auditing-security
Source: https://github.com/AITOBIAS04/Echelon/tree/main/.claude/skills/auditing-security
Command: npx skills add https://github.com/AITOBIAS04/Echelon --skill auditing-security-aitobias04

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

Auditing-security provides a rigorous, repeatable framework to identify and remediate security and quality issues across code, deployment, and sprint artifacts.

Core Features & Use Cases

  • Structured five-category audits (Security, Architecture, Code Quality, DevOps, Blockchain) with concrete checklists.
  • Generates human-readable SECURITY-AUDIT-REPORT.md and machine-readable findings.jsonl with file:line references, remediation steps, and references.
  • Supports codebase, deployment, and sprint audits with a consistent output structure and remediation tracking.

Quick Start

Audit sprint 1 using the codebase security checks and generate the SECURITY-AUDIT-REPORT.md and findings.jsonl in grimoires/loa/a2a/audits/YYYY-MM-DD.

Frequently Asked Questions about auditing-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a security audit on my codebase and deployment artifacts?

Run a security audit by applying a standardized five-category framework—Security, Architecture, Code Quality, DevOps, and Blockchain—to code, deployment, and sprint artifacts. The audit generates a SECURITY-AUDIT-REPORT.md and findings.jsonl with file:line references.

What is the best way to track remediation steps for infrastructure security findings?

Track remediation steps for security findings using the generated machine-readable findings.jsonl file. This output includes concrete file:line references and structured remediation tracking for code, deployment, and sprint artifacts.

Can I generate machine-readable audit findings for automated security pipelines?

Yes, the audit outputs a machine-readable findings.jsonl file under grimoires/loa/a2a/audits/YYYY-MM-DD. This allows you to integrate structured security, architecture, and code quality findings into automated pipelines.

How do I audit sprint artifacts for security and quality issues?

Audit sprint artifacts by running the standardized five-category checklist against sprint deliverables. It identifies security and code quality issues, outputting structured findings with file:line references and remediation steps in a SECURITY-AUDIT-REPORT.md.

What limitations exist when auditing blockchain components in my codebase?

The audit framework includes a Blockchain category for identifying security and quality issues, but the specific checklist constraints depend on the available artifacts. Findings are limited to generating file:line references and remediation steps within the structured report.