picky-security

Automate security audits with OWASP Top 10 and CWE mappings.

5|Updated Jan 28, 2026
One-click install
npx skills add https://github.com/kiruna-labs/picky-skills --skill picky-security
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: picky-security
Source: https://github.com/kiruna-labs/picky-skills/tree/main/picky-security
Command: npx skills add https://github.com/kiruna-labs/picky-skills --skill picky-security

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Ultra-thorough security audits that identify every vulnerability across API endpoints, user input vectors, dependencies, and configurations, delivering precise, actionable findings.

Core Features & Use Cases

  • Exhaustive scanning of frontend, backend, and API surfaces with OWASP Top 10 and CWE mappings
  • Generates scored reports with file:line references and concrete remediation steps
  • Triggerable by phrases like "security audit", "vulnerability scan", or "picky security" to integrate into CI/CD

Quick Start

Execute a full security audit across the project to generate a detailed, actionable report.

Frequently Asked Questions about picky-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is included in a vulnerability scan report with CVSS scores?

A security audit identifies vulnerabilities across API endpoints, user input vectors, dependencies, and configurations. It produces scored reports with CVSS scores, exact file:line references, and remediation guidance including secure code examples.

Does the security audit provide exact file and line fixes for remediation?

Yes, you can integrate the vulnerability scan into CI/CD workflows. It is triggerable by phrases like "security audit" or "picky security", automating exhaustive scanning across frontend, backend, and API surfaces to deliver precise findings.

Can I integrate an automated vulnerability scan into my CI/CD pipeline?

Yes, the security audit delivers precise remediation by providing exact file:line references for vulnerabilities. It includes a verification workflow to confirm fixes, ensuring actionable and traceable remediation guidance with secure code examples.

How do I run an OWASP Top 10 security audit across my codebase?

A vulnerability scan report includes CVSS scores, exhaustive OWASP Top 10 and CWE mappings, and concrete remediation steps. It provides a verification workflow to confirm fixes, ensuring vulnerabilities are fully addressed across the codebase.