security-audit

Audit dependencies, CI/CD pipelines, and infrastructure for security gaps.

Updated Apr 20, 2026
One-click install
npx skills add https://github.com/sennett-lau/alice --skill security-audit-sennett-lau
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-audit
Source: https://github.com/sennett-lau/alice/tree/main/framework/skills/security-audit
Command: npx skills add https://github.com/sennett-lau/alice --skill security-audit-sennett-lau

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode for infrastructure-first security auditing: secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, and skill supply chain scanning. It provides OWASP Top 10, STRIDE threat modeling, and active verification with daily and comprehensive modes to track trends across runs.

Core Features & Use Cases

  • Threat modeling and risk-based security posture assessments across code, pipelines, and infrastructure.
  • Integrated coverage of dependencies, secrets hygiene, CI/CD security, and supply chain integrity.
  • Actionable Security Posture Reports with remediation plans and executive-ready findings.
  • Use Case: A CSO or security engineer runs daily checks to surface high-severity issues before deployment.

Quick Start

Run the security-audit skill to generate a Security Posture Report for your project.

Frequently Asked Questions about security-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a security audit on my codebase and CI/CD pipeline?

Run the security audit to generate a Security Posture Report by scanning your dependencies, CI/CD pipelines, and infrastructure, mapping the attack surface and detecting secrets archaeology issues.

What is STRIDE threat modeling and how does it apply to infrastructure security?

STRIDE threat modeling is a framework for identifying security threats across code and infrastructure, applied here alongside OWASP Top 10 checks to assess risk posture and prioritize remediation for deployment pipelines.

Can I use this security audit for zero-trust posture and supply chain analysis?

Yes, this security audit supports zero-trust posture requirements by performing dependency supply chain analysis, secrets hygiene checks, and CI/CD security checks across your codebase and deployment pipelines.

What's the best way to identify high-severity security gaps before deployment?

Run daily security audit checks to surface high-severity issues before deployment, tracking trends across runs with actionable remediation plans and executive-ready findings.

Does this audit cover LLM and AI security vulnerabilities in my stack?

Yes, the security audit includes LLM and AI security scanning as part of its comprehensive coverage, alongside skill supply chain scanning and infrastructure-first security checks.

When do I need a comprehensive security posture assessment with OWASP coverage?

You need a comprehensive security posture assessment with OWASP coverage when deploying codebases requiring zero-trust posture, mapping attack surfaces, and verifying remediation across phases 0 through 14.