security

Audit web applications and infrastructure for security vulnerabilities.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/paulund/ai --skill security-paulund
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security
Source: https://github.com/paulund/ai/tree/main/security/skills/security
Command: npx skills add https://github.com/paulund/ai --skill security-paulund

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps you identify and mitigate security vulnerabilities in your code, infrastructure, and development practices, ensuring robust protection against threats.

Core Features & Use Cases

  • Code Auditing: Detects common vulnerabilities like SQL injection, XSS, and insecure authentication.
  • Infrastructure Review: Assesses cloud configurations, container security, and compliance.
  • Use Case: You're preparing for a security audit. Use this Skill to generate a comprehensive checklist, run automated scans, and produce a detailed report of findings with remediation steps.

Quick Start

Use the security skill to perform a full security audit of the current project's codebase.

Frequently Asked Questions about security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a security audit on my web application codebase?

A security audit analyzes your codebase for vulnerabilities like SQL injection and XSS, reviews configurations, and validates controls against best practices. It uses detailed checklists and automated scanning to produce a report of findings with remediation steps.

What is penetration testing for cloud infrastructure and when do I need it?

Penetration testing for cloud infrastructure assesses configurations and container security to ensure compliance and robust protection. You need it when preparing for a security audit or validating that your infrastructure controls withstand threats.

Can I use automated scanning to detect SQL injection and XSS vulnerabilities?

Yes, automated scanning detects common vulnerabilities like SQL injection, XSS, and insecure authentication during a code audit. The process validates security controls and outputs structured reporting for findings with required remediation steps.

What's the best way to generate a compliance checklist for an infrastructure review?

The best way to generate a compliance checklist is using a security audit skill that assesses cloud configurations and container security. It validates controls against industry best practices and produces a detailed report of findings with remediation steps.

Does code review for security require adherence to specific checklists?

Yes, code review for security requires adherence to detailed checklists to accurately identify vulnerabilities. The structured process combines automated scanning tools with manual configuration reviews to validate controls and generate structured reporting for findings.