hm-security

Identify and report security vulnerabilities in software projects with structured findings.

184|43|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/rodrigohighermind/highermind-code-skills --skill hm-security
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hm-security
Source: https://github.com/rodrigohighermind/highermind-code-skills/tree/main/hm-security
Command: npx skills add https://github.com/rodrigohighermind/highermind-code-skills --skill hm-security

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security auditing helps teams identify vulnerabilities across code, configurations, and dependencies before attackers exploit them.

Core Features & Use Cases

  • Covers container security, API authentication, data handling, and third-party integrations across baseline to critical levels.
  • Produces structured findings with severity, impact, PoC steps, fixes, and references.
  • Supports repeatable security checks in CI/CD, multi-tenant setups, and LLM-integrated workflows.

Quick Start

Run an initial security audit pass on the repository to generate the first findings.

Frequently Asked Questions about hm-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit code for security vulnerabilities in a CI/CD pipeline?

You can perform a security audit on your software projects by scanning CI/CD pipelines, APIs, and containers to identify vulnerabilities and generate structured findings with severity, impact, proof of concept, and explicit fixes.

What is structured security audit reporting based on OWASP ASVS?

Structured security audit reporting based on OWASP ASVS provides findings categorized from baseline (L1) to critical (L3) checks, including severity, impact, PoC steps, and references to ensure comprehensive cross-domain coverage.

Does this security audit tool cover container and API authentication checks?

Yes, this security audit covers container security, API authentication, data handling, and third-party integrations across baseline to critical levels, ensuring comprehensive vulnerability detection across your software components.

How to generate reproducible proof of concepts for code vulnerabilities?

To generate reproducible proof of concepts for code vulnerabilities, run an initial security audit pass on the repository to produce structured findings that include explicit PoC steps, fixes, and references.

What is the best way to automate vulnerability checks for multi-tenant setups?

The best way to automate vulnerability checks for multi-tenant setups is to implement structured audit requirements that support repeatable security checks across baseline to critical levels, targeting data-handling components and third-party integrations.