What problem does it solve?
This Skill helps identify, validate, prioritize, and remediate real security vulnerabilities in source code, applications, and authorized live targets while reducing false positives and unsupported severity claims.
Core Features & Use Cases
- Repository Security Audits: Performs reconnaissance, vulnerability hunting, adversarial validation, structured reporting, and independent verification across an entire codebase.
- Focused Security Workflows: Supports diff reviews, threat modeling, attack-path tracing, vulnerability discovery, triage, remediation, fix validation, and finding tracking.
- Authorized Penetration Testing: Provides passive and active reconnaissance, web enumeration, vulnerability scanning, controlled exploitation guidance, and evidence collection for localhost or explicitly authorized remote targets.
- Evidence-Based Reporting: Records repo-relative locations, data-flow traces, concrete attack scenarios, severity rationale, confidence scores, remediation guidance, and validated JSON or HTML reports.
Quick Start
Ask the security-specialist skill to perform a full security audit of the specified repository and produce a validated report of confirmed exploitable findings.