security-audit

Plan and execute security audits with OWASP Top 10 and STRIDE threat modeling.

364|53|Updated May 9, 2026
One-click install
npx skills add https://github.com/cosmicstack-labs/mercury-agent-skills --skill security-audit-cosmicstack-labs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-audit
Source: https://github.com/cosmicstack-labs/mercury-agent-skills/tree/main/categories/security/security-audit
Command: npx skills add https://github.com/cosmicstack-labs/mercury-agent-skills --skill security-audit-cosmicstack-labs

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps you perform comprehensive security audits in a repeatable, evidence-based way so you can identify vulnerabilities, assess risk, and produce actionable remediation guidance.

Core Features & Use Cases

  • Structured audit methodology: Guides your workflow from scope definition through recon, testing, reporting, and remediation.
  • OWASP-aligned vulnerability assessment: Covers the OWASP Top 10 risk areas with clear checks and testing guidance.
  • Threat modeling and risk scoring: Uses STRIDE (and optionally DREAD) to systematically identify threats and prioritize mitigation work.
  • Professional reporting templates: Provides an audit report structure including executive summary, finding register, detailed findings, and risk heatmaps.

Quick Start

Use this skill to produce a complete security audit plan and report template for your application by asking an AI to apply the five-phase methodology and OWASP Top 10 coverage to your target scope.

Frequently Asked Questions about security-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run an OWASP Top 10 security audit for a web application?

To run an OWASP Top 10 security audit, you need a structured methodology covering scope definition, recon, automated and manual testing, and evidence-backed findings. This process ensures comprehensive vulnerability assessment and actionable remediation guidance.

What is threat modeling using STRIDE and how does it classify risk?

Threat modeling using STRIDE systematically identifies threats across your application architecture. Paired with CVSS-aligned severity classification, it prioritizes mitigation work by scoring vulnerability impact and exploitability.

How do I structure a professional security audit report with an executive summary?

A professional security audit report structure includes an executive summary, finding register, detailed findings, and risk heatmaps. This format ensures evidence-backed findings are communicated clearly to both technical and management stakeholders.

Can I use dependency scanning to validate vulnerabilities during a security audit?

Yes, dependency scanning is integrated into the security audit workflow to identify vulnerable components. Vulnerability validation occurs during the testing phase to verify discovered risks before generating the final audit report.

What is the best way to ensure repeatable evidence-based security testing?

Repeatable evidence-based security testing requires a structured audit methodology that guides your workflow from scope definition through recon, testing, reporting, and remediation verification, ensuring consistent OWASP Top 10 coverage and CVSS-aligned severity classification.