security-expert

Identify and remediate security vulnerabilities across code, dependencies, and deployment configurations.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/phishkatlabs/phishkat-crew --skill security-expert-phishkatlabs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-expert
Source: https://github.com/phishkatlabs/phishkat-crew/tree/main/security-expert
Command: npx skills add https://github.com/phishkatlabs/phishkat-crew --skill security-expert-phishkatlabs

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Penetration tester and security auditor who systematically verifies every attack surface, authentication boundary, and dependency in the codebase.

Core Features & Use Cases

  • End-to-end security assessment: coverage of authentication, authorization, data handling, API interfaces, and third-party dependencies.
  • Structured findings: severity-rated reports with attack vectors, proof-of-concept, and remediation steps.
  • Threat modeling and compliance alignment: align with OWASP API/Top 10 and industry standards; provide remediation guidance.

Quick Start

Run a comprehensive security audit on the repository and generate a prioritized remediation report.

Frequently Asked Questions about security-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a security audit on my API-centric application?

Authentication flow verification systematically validates user identity boundaries, session tokens, and access controls within API-centric applications. It checks data isolation, input validation, and authorization mechanisms to prevent unauthorized access, producing actionable findings with severity ratings and remediation steps.

How do I identify dependency risks and configuration hardening issues in my codebase?

Threat modeling for API security aligns assessments with OWASP API Top 10 and industry standards to systematically identify potential attack vectors. It structures findings into severity-rated reports with proof-of-concept descriptions, providing actionable remediation guidance to harden codebases and deployment configurations.

What is the best way to generate a prioritized remediation report for security vulnerabilities?

Penetration testing for web services systematically probes API interfaces, authentication boundaries, and data handling mechanisms to verify secure deployment practices. It evaluates input validation and data isolation across development to production environments, yielding actionable findings with attack vectors and remediation steps.

Does this security audit cover both development and production environments?

Security audit findings include severity ratings, identified attack vectors, proof-of-concept descriptions, and actionable remediation steps. This structured reporting covers vulnerabilities across authentication, data access, API interfaces, and third-party dependencies, aligning with OWASP Top 10 standards for comprehensive threat mitigation.

When should I perform threat modeling and dependency audits on my web services?

Dependency audits for API-centric applications systematically evaluate third-party library risk, authentication flow integrity, and data access controls. This verifies secure deployment practices and configuration hardening, producing prioritized remediation reports with severity ratings and proof-of-concept descriptions for identified vulnerabilities.

Can I use this penetration testing approach for compliance alignment with OWASP standards?

Security audits for deployment configurations verify hardening practices, dependency risk, and data isolation across development to production environments. They assess authentication boundaries and API interfaces, generating severity-rated findings with attack vectors, proof-of-concept descriptions, and remediation steps for secure deployment.