bimsmarter-security-audit

Audit BIMSmarter React, Firebase, PHP proxy, and n8n for vulnerabilities.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/rcliment1987/skills-bimsmarter --skill bimsmarter-security-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bimsmarter-security-audit
Source: https://github.com/rcliment1987/skills-bimsmarter/tree/main/bimsmarter-security-audit
Command: npx skills add https://github.com/rcliment1987/skills-bimsmarter --skill bimsmarter-security-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The security audit skill identifies vulnerabilities and misconfigurations across the BIMSmarter stack to prevent data leaks and unauthorized access.

Core Features & Use Cases

  • End-to-end security assessment of React frontend, Firebase services, PHP Mistral proxy, and n8n webhooks.
  • Supports multiple audit modes: Full, Quick, Diff, Focus:auth, Focus:api, Focus:config, Focus:llm to tailor scope.
  • Generates findings with exact code references and actionable remediation steps.

Quick Start

Run /audit to perform a full BIMSmarter security assessment across the entire stack.

Frequently Asked Questions about bimsmarter-security-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
Does this security audit tool support reviewing recent code changes only?

Yes, the Diff audit mode allows you to perform a security audit on recent code changes across the BIMSmarter stack. This ensures that new vulnerabilities are caught in React, Firebase, n8n, or PHP proxy updates without scanning the entire project.

What is the best way to audit Firebase Auth and Storage rules for data leak vulnerabilities?

Use the Focus:auth audit mode to specifically target Firebase Auth and Storage configurations. This security audit identifies misconfigurations that could lead to data leaks, citing real code and providing exact file references for actionable remediation.

Can I run a quick security scan on my n8n webhooks and PHP proxy?

Yes, use the Quick audit mode for a fast security assessment of the BIMSmarter stack. For deeper analysis of n8n webhooks and the Mistral PHP proxy, the Full or Focus:api modes provide targeted vulnerability detection with concrete code references.

How do I check for vulnerabilities in Mistral LLM proxy configurations?

Use the Focus:llm audit mode to perform a targeted security check on the Mistral PHP proxy. This mode identifies vulnerabilities and misconfigurations related to the LLM integration, citing real code and providing actionable mitigation steps.

Does this security audit tool support reviewing recent code changes only?

Yes, the Diff audit mode allows you to perform a security audit on recent code changes across the BIMSmarter stack. This ensures that new vulnerabilities are caught in React, Firebase, n8n, or PHP proxy updates without scanning the entire project.