What problem does it solve?
Many releases fail because critical vulnerabilities, leaked secrets, or insecure CI/dependency configurations are missed until after deployment. This Skill systematically uncovers OWASP Top 10 issues, secret exposures in code and history, and architectural threats so teams can remediate before shipping.
Core Features & Use Cases
- OWASP & STRIDE Audits: Full OWASP A01–A10 coverage and per-component STRIDE threat modeling with prioritized findings.
- Secrets & Dependency Scans: Git history checks, secrets redaction, and dependency vulnerability audits with actionable upgrade advice.
- CI/CD and Infrastructure Checks: Detect unpinned GitHub Actions, exposed secrets in workflows, Docker misconfigs, and AI endpoint risks.
- Use Case: Run this Skill on a pre-release branch or PR to produce an evidence-backed report listing file locations, exploitation scenarios, and precise code fixes.
Quick Start
Use the security skill to run an OWASP Top 10 and STRIDE audit over the repository and produce an actionable report.