What problem does it solve?
This Skill provides a systematic, deep security audit of a codebase to identify vulnerabilities across dependencies, hardcoded secrets, injection vectors, authentication and authorization flaws, insecure configuration, and deployment exposures, turning fragmented manual checks into a repeatable, prioritized assessment.
Core Features & Use Cases
- Comprehensive scanning: Secret detection, dependency vulnerability checks, injection pattern searches (SQL/XSS/command), authentication and authorization reviews, and configuration checks.
- Context-aware analysis: Uses file-level pattern searches and dependency audits combined with manual review guidance to reduce false positives and surface actionable findings.
- Actionable reporting: Produces prioritized reports with file locations, impact descriptions, and concrete remediation steps for developers, security engineers, and CI pipelines.
- Use case: Pre-release security validation, CI security gates, third-party code vetting, and incident triage.
Quick Start
Run a full security audit of the repository and generate a prioritized report listing each finding with location, impact, and remediation guidance.