security-audit

Audit advocacy software for dependency, retention, and encryption compliance.

4|3|Updated Feb 25, 2026
One-click install
npx skills add https://github.com/Open-Paws/no-animal-violence --skill security-audit-open-paws
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-audit
Source: https://github.com/Open-Paws/no-animal-violence/tree/main/.claude/skills/security-audit
Command: npx skills add https://github.com/Open-Paws/no-animal-violence --skill security-audit-open-paws

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill guides defenders of advocacy projects to systematically verify dependencies, enforce zero-retention policies, and protect sensitive data through encryption and instruction integrity checks.

Core Features & Use Cases

  • Dependency verification: ensure every external package exists and is maintainable.
  • Retention and encryption controls: enforce zero-retention for sensitive data and verify encryption at rest and in transit.
  • Policy and integrity reviews: audit instruction file integrity, input validation, and device seizure readiness across project workflows.

Quick Start

Provide a structured governance check for a new dependency added to the project and confirm zero-retention settings across APIs.

Frequently Asked Questions about security-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit advocacy software for security and compliance across dependencies and retention?

To audit advocacy software for security and compliance, verify dependencies, enforce zero-retention policies, and check encryption across data handling workflows. This process covers dependency verification, API retention checks, storage encryption, input validation, and findings reporting.

What is zero-retention policy verification for sensitive investigation data?

Zero-retention verification for investigation data confirms that APIs and storage layers do not persist sensitive activist communications. It involves checking retention settings across project workflows to ensure sensitive data is not stored beyond its immediate processing need.

How do I prepare a codebase for device seizure readiness in activist projects?

Device seizure readiness for activist projects requires verifying instruction file integrity, enforcing encryption at rest and in transit, and applying zero-retention checks. This ensures investigation data and activist communications remain protected if hardware is confiscated.

Can I use this security audit for codebases containing activist communications?

Yes, this security audit is specifically designed for codebases containing investigation data and activist communications. It systematically verifies dependencies, checks API retention policies, and validates encryption to satisfy multi-step governance requirements for advocacy projects.

What's the best way to verify external package dependencies for advocacy software?

The best way to verify external package dependencies for advocacy software is to ensure every package exists and is actively maintainable. This dependency verification step confirms external packages meet governance requirements before integration into sensitive project workflows.

What does an end-to-end security audit for advocacy projects include?

An end-to-end security audit for advocacy includes dependency verification, zero-retention checks, encryption validation, instruction-file integrity reviews, input validation, and device seizure readiness. It provides a structured governance check covering all data handling and storage workflows.