security-auditor

Audit code, CI/CD pipelines, and deployments for DevSecOps security gaps.

10|Updated May 20, 2026
One-click install
npx skills add https://github.com/AI-Safeter/antigravity-cli-plugin --skill security-auditor-ai-safeter
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-auditor
Source: https://github.com/AI-Safeter/antigravity-cli-plugin/tree/main/plugins/security-auditor
Command: npx skills add https://github.com/AI-Safeter/antigravity-cli-plugin --skill security-auditor-ai-safeter

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Provides expert DevSecOps security auditing, threat modeling, and compliance guidance to help teams identify and remediate security gaps across code, pipelines, and deployments.

Core Features & Use Cases

  • Threat modeling and risk assessment across CI/CD pipelines and production systems.
  • Vulnerability triage, remediation planning, and policy-driven security controls.
  • Compliance mapping and governance guidance for frameworks like NIST, ISO 27001, and SOC 2.

Quick Start

Initiate a security audit of the target system and outline prioritized remediation steps.

Frequently Asked Questions about security-auditor

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a DevSecOps security audit across my code and CI/CD pipelines?

Perform a DevSecOps security audit by evaluating code, CI/CD pipelines, and deployments to identify security gaps. The audit coordinates SAST/DAST/IAST scanning, threat modeling, and policy-as-code controls to deliver prioritized remediation steps.

What is threat modeling for CI/CD pipelines and production systems?

Threat modeling for CI/CD pipelines is a risk assessment process that identifies and evaluates security vulnerabilities across your deployment workflow. It maps potential attack vectors in production systems to prioritize remediation and ensure compliance readiness.

How do I map software vulnerabilities to compliance frameworks like NIST or SOC 2?

Map software vulnerabilities to compliance frameworks by triaging identified risks and aligning them with NIST, ISO 27001, and SOC 2 governance requirements. This process establishes remediation traceability and ensures policy-driven security controls meet regulatory standards.

Can I use this security audit for vulnerability triage and risk prioritization?

Yes, this security audit supports vulnerability triage and risk prioritization. It evaluates identified vulnerabilities across your software projects, ranks them by severity and impact, and generates a remediation plan with traceability for policy-as-code security controls.

What is the best way to coordinate SAST, DAST, and IAST results during a security review?

The best way to coordinate SAST, DAST, and IAST results is to consolidate their findings into a unified vulnerability triage workflow. This provides comprehensive risk assessment, cross-validates detection coverage, and streamlines remediation planning across code and deployments.

Do I need policy-as-code security controls to prepare for compliance readiness?

You need policy-as-code security controls to automate and enforce compliance readiness effectively. They provide continuous governance validation for frameworks like NIST and ISO 27001, ensuring your CI/CD pipelines and deployments maintain required security baselines.