security-review

Identify and document OWASP Top 10 vulnerabilities across code, configurations, and infrastructure.

60|14|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/brucesongs/kali-claw --skill security-review-brucesongs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review
Source: https://github.com/brucesongs/kali-claw/tree/main/skills/security-review
Command: npx skills add https://github.com/brucesongs/kali-claw --skill security-review-brucesongs

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Comprehensive, structured guidance for performing security reviews across applications, configurations, and infrastructure to identify vulnerabilities in OWASP Top 10 categories during penetration testing.

Core Features & Use Cases

  • Step-by-step audit workflow that surfaces threats, analyzes risk, and documents remediation suggestions.
  • Templates and evidence-capture patterns to support repeatable security assessments across code, configs, and deployments.
  • Use Case: Audit a web app and its cloud config to surface authentication weaknesses, misconfigurations, and insecure dependencies.

Quick Start

Initiate a full OWASP-based security review using the included guides and templates to surface, assess, and document findings.

Frequently Asked Questions about security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an OWASP security review on my web application?

An OWASP security review identifies vulnerabilities across web apps, APIs, and cloud services using a structured methodology. It applies step-by-step audit workflows to surface threats, analyze risk, and document remediation suggestions for authentication weaknesses and misconfigurations.

Can I use this security review methodology for cloud infrastructure and API configurations?

Yes, the security review methodology applies to code, configurations, and infrastructure across web apps, APIs, and cloud services. It identifies vulnerabilities in OWASP Top 10 categories by analyzing cloud configurations and deployments to surface misconfigurations and insecure dependencies.

What is a structured OWASP-based security review workflow?

A structured OWASP-based security review workflow systematically identifies and documents vulnerabilities using repeatable templates and evidence-capture patterns. It ensures consistent reporting and actionable remediation guidance by applying a step-by-step audit process to surface threats and analyze risk.

Does this penetration testing audit support evidence collection and remediation reporting?

Yes, the penetration testing audit supports evidence collection and remediation reporting through repeatable workflows and templates. It ensures consistent reporting by documenting vulnerabilities found in OWASP Top 10 categories and providing actionable remediation guidance for code and infrastructure.

What is the best way to document security vulnerabilities found during an audit?

The best way to document security vulnerabilities is using structured templates and evidence-capture patterns during the audit. This ensures consistent reporting and actionable remediation guidance, creating repeatable security assessments that surface threats and analyze risk across applications and infrastructure.

When should I not use a structured OWASP review for penetration testing?

A structured OWASP review focuses on identifying vulnerabilities in OWASP Top 10 categories across code, configs, and infrastructure. It may not cover threat categories outside the OWASP Top 10 or replace dynamic runtime exploitation required in advanced penetration testing scenarios.