raven-investigate

Audit codebases for vulnerabilities across six security domains.

5|Updated Nov 22, 2025
One-click install
npx skills add https://github.com/AutumnsGrove/Lattice --skill raven-investigate
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: raven-investigate
Source: https://github.com/AutumnsGrove/Lattice/tree/main/.claude/skills/raven-investigate
Command: npx skills add https://github.com/AutumnsGrove/Lattice --skill raven-investigate

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill rapidly audits any codebase's security posture by deploying parallel sub-agents across all critical security domains, delivering a comprehensive assessment quickly.

Core Features & Use Cases

  • Parallel Investigation: Simultaneously probes secrets, dependencies, auth, input validation, HTTP security, and dev hygiene.
  • Stack-Adaptive: Detects the tech stack and tailors checks accordingly.
  • Use Case: When you need a fast, thorough security review of an unfamiliar project before integration or deployment, the Raven provides a clear picture of risks.

Quick Start

Run the raven-investigate skill to perform a full security audit on the current codebase.

Frequently Asked Questions about raven-investigate

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a comprehensive codebase security audit?

A comprehensive codebase security audit probes vulnerabilities across secrets, dependencies, authentication, input validation, HTTP security, and development hygiene. It adapts checks to your specific tech stack to provide actionable findings and a detailed posture assessment.

What does a vulnerability assessment cover in software engineering?

A vulnerability assessment covers six critical domains: secrets, dependencies, authentication, input validation, HTTP security, and development hygiene. It identifies risks and provides a detailed security posture assessment with actionable findings.

Can I run a security audit on an unfamiliar codebase before deployment?

Yes, you can run a security audit on an unfamiliar codebase before deployment. The investigation detects the tech stack, tailors checks accordingly, and delivers a clear picture of risks across six critical security domains.

What is the best way to check for secrets and dependency vulnerabilities?

The best way to check for secrets and dependency vulnerabilities is deploying parallel sub-agents across all critical security domains. This stack-adaptive approach rapidly delivers a comprehensive assessment of risks and actionable findings.

Does a parallelized security audit work with different tech stacks?

A parallelized security audit works with different tech stacks by detecting the stack and tailoring checks accordingly. It simultaneously probes secrets, dependencies, auth, input validation, HTTP security, and dev hygiene for a thorough assessment.

Why should I use parallel sub-agents for penetration testing and code review?

You should use parallel sub-agents for penetration testing and code review because they simultaneously probe six critical security domains, delivering a fast, comprehensive assessment of vulnerabilities and actionable findings for any codebase.