security-auditor

Audits code and infrastructure vulnerabilities and compliance gaps across deployments.

3|2|Updated Feb 27, 2026
One-click install
npx skills add https://github.com/grasberg/sofia --skill security-auditor-grasberg
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-auditor
Source: https://github.com/grasberg/sofia/tree/main/workspace/skills/security-auditor
Command: npx skills add https://github.com/grasberg/sofia --skill security-auditor-grasberg

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The security-auditor helps teams identify vulnerabilities and misconfigurations across code and infrastructure, assess threat models, and prepare actionable remediation plans to meet compliance requirements (SOC 2, GDPR, PCI-DSS).

Core Features & Use Cases

  • Identify vulnerabilities using OWASP Top 10, CWE Top 25, and SANS Top 25 as guiding frameworks.
  • Analyze CVEs and assess severity, exploitability, affected versions, and available patches.
  • Review authentication/authorization flows, session management, and MFA implementations; audit encryption, TLS, key management, and data-at-rest protections.
  • Assess configurations for compliance with SOC 2, GDPR, HIPAA, PCI-DSS, ISO 27001; produce hardening guides and remediation timelines.
  • Produce structured security assessment reports with severity ratings, evidence, remediation steps, and executive summaries.

Quick Start

Provide a security assessment of a project by analyzing code, configurations, and deployment pipelines to identify vulnerabilities and deliver a remediation plan.

Frequently Asked Questions about security-auditor

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit code and infrastructure for security vulnerabilities?

To audit code and infrastructure for security vulnerabilities, you analyze application code, configurations, and deployment pipelines against OWASP Top 10 and CWE Top 25 frameworks to identify risks and deliver structured remediation plans.

What is threat modeling and CVE analysis in a security audit?

Threat modeling and CVE analysis in a security audit involve assessing vulnerability severity, exploitability, and affected versions to evaluate potential attack vectors and determine available patches for compliance reporting.

How do I check compliance gaps for SOC 2, GDPR, or PCI-DSS?

To check compliance gaps for SOC 2, GDPR, or PCI-DSS, you assess cloud and on-premise configurations against standard frameworks, producing hardening guides and structured reports with severity ratings and remediation timelines.

Can I assess authentication flows and encryption configurations during a security audit?

Yes, you can assess authentication flows and encryption configurations during a security audit by reviewing session management, MFA implementations, TLS protocols, key management, and data-at-rest protections across your environments.

Does this security audit approach work for both cloud and on-premise environments?

Yes, this security audit approach works for both cloud and on-premise environments by analyzing code, infrastructure configurations, and deployment pipelines to identify misconfigurations and vulnerabilities across diverse deployment targets.

What is the best way to generate a structured security assessment report?

The best way to generate a structured security assessment report is to compile identified vulnerabilities, evidence, severity ratings, and remediation steps into an executive summary that meets compliance requirements like ISO 27001 and HIPAA.