harness-security-audit

Classify security findings into P0, P1, and P2 severity levels.

Updated Apr 18, 2026
One-click install
npx skills add https://github.com/ZhaoyuWu/Website-Wzy --skill harness-security-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: harness-security-audit
Source: https://github.com/ZhaoyuWu/Website-Wzy/tree/main/codex-skills/harness-security-audit
Command: npx skills add https://github.com/ZhaoyuWu/Website-Wzy --skill harness-security-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps security teams perform focused audits and quickly classify findings by severity to support go/no-go decisions.

Core Features & Use Cases

  • Structured review: evaluate trust boundaries, authentication, authorization, secrets handling, and logging hygiene.
  • Severity classification: categorize findings into P0, P1, and P2 and propose fixes.
  • Use Case: ideal for evaluator phase or pre-release checks to ensure risk posture before release.

Quick Start

Initiate a focused security audit using the provided arguments and return a prioritized findings report.

Frequently Asked Questions about harness-security-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a focused security audit for pre-release checks?

Run a focused security audit to evaluate trust boundaries, authentication, authorization, secrets handling, and logging hygiene across software projects, pipelines, and deployments before release.

How does severity classification work for security vulnerabilities during an audit?

Severity classification categorizes security vulnerabilities into P0, P1, and P2 risk levels to support go/no-go decisions and propose fixes for identified findings.

What is the best way to classify authorization risks in software pipelines?

The best way to classify authorization risks is through structured security audits that evaluate trust boundaries and categorize findings into P0, P1, and P2 severity levels with proposed fixes.

Can I use this security audit during the evaluator phase for risk assessment?

Yes, this security audit is ideal for the evaluator phase to perform risk assessment, classify findings by severity, and ensure the risk posture is acceptable before release.

What does a focused security audit cover for secrets handling and logging hygiene?

A focused security audit covers secrets handling and logging hygiene by structuring reviews across trust boundaries, authentication, and authorization to identify and classify security findings.

When do I need to perform a security audit with P0, P1, and P2 risk categorization?

You need to perform a security audit with P0, P1, and P2 risk categorization during evaluator phases or pre-release checks to ensure risk posture across software projects and deployments.