security-audit

Identify and rank security risks in codebases through multi-lens audits.

1|Updated Feb 27, 2026
One-click install
npx skills add https://github.com/justsml/ai-team-skills --skill security-audit-justsml
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-audit
Source: https://github.com/justsml/ai-team-skills/tree/main/security-audit
Command: npx skills add https://github.com/justsml/ai-team-skills --skill security-audit-justsml

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Modern codebases face evolving security risks across web apps, APIs, and services. This Skill provides a structured, multi-lens security assessment to identify, triage, and communicate vulnerabilities before deployment.

Core Features & Use Cases

  • Multi-lens evaluation by specialized teams (OWASP AppSec, Data Privacy, Exploit Research, LLM Risk, Holistic Reviewer).
  • Systematic scoping, asset/service mapping, and threat modeling to produce prioritized findings.
  • Use Case: When you need a comprehensive security review for a new release or hardening guidance, run an end-to-end audit and generate a single synthesized report.

Quick Start

Scope the project, initialize the .reports/security-audit directory, create the team named security-audit, run all specialists in parallel, and generate the final SECURITY-AUDIT.md report.

Frequently Asked Questions about security-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit on my codebase to identify vulnerabilities?

A security audit identifies and ranks risks in a codebase through a multi-lens evaluation covering OWASP AppSec, data privacy, and exploit research. It maps assets, models threats, and generates a synthesized report detailing prioritized findings for your web apps, APIs, and data stores.

What is the best way to prioritize security risks across web apps and APIs?

Prioritize security risks across web apps and APIs by deploying specialized teams to run parallel tasks covering OWASP AppSec, data privacy, and exploit research. This multi-lens approach scopes the project, maps assets, and synthesizes prioritized findings into a final report.

How do I generate a security audit report for a new release?

Generate a security audit report for a new release by scoping the project, initializing the .reports/security-audit directory, and creating a dedicated team. The assigned specialists run tasks in parallel and write the final synthesized findings into a SECURITY-AUDIT.md report.

Does this security audit approach work for CLI tools and data stores?

Yes, this security audit applies to CLI tools and data stores across diverse tech stacks. It systematically scopes your project, maps assets and services, and performs threat modeling to evaluate vulnerabilities, ensuring comprehensive risk assessment for various application types.

Can I automate threat modeling and risk assessment for my codebase?

Automate threat modeling and risk assessment by initializing a dedicated specialist team that runs parallel tasks covering OWASP AppSec and exploit research. This multi-lens audit systematically evaluates your codebase, synthesizes identified vulnerabilities, and outputs a structured risk assessment report.

What frameworks are used for vulnerability reporting in this security audit?

The vulnerability reporting framework uses a multi-lens evaluation based on OWASP AppSec, data privacy, LLM risk, and exploit research principles. It scopes your codebase, assigns specialized team members to run parallel tasks, and synthesizes findings into a comprehensive markdown report.