AthenodeAthenode

Back to Security Review

security-audit

Created here

Use when a repository, a path or the current diff needs a full security audit that combines code review, dependency audit and scanner results into one verified report.

SKILL.md

Run a full defensive security audit of this project and return one report that holds only findings that survived verification.

Arguments

  • A scope (optional): a path, diff for the uncommitted and branch changes, or nothing for the whole repository.

Flow

  1. Scope. Resolve the scope. For the whole repository, list its languages, frameworks, entry points (HTTP routes, CLI commands, queue consumers, cron jobs), dependency manifests, CI workflows and infrastructure files. In a large repository, say which parts you will cover first and why.
  2. Scan. Invoke the security-scan skill for the scope and keep its results as leads.
  3. Review in parallel. Delegate at the same time:
    • to the security-code-reviewer agent: the scope, the entry points and the scanner leads about source code;
    • to the security-dependency-auditor agent: the dependency manifests, lockfiles, CI workflows and the scanner leads about dependencies. Without subagent support, do both reviews yourself, one after the other, following the security-review and owasp-security skills for code and the gha-security-review skill for GitHub Actions workflows.
  4. Verify. Pass every finding to the security-finding-verifier agent (several agents for many findings, a few findings each). Drop the findings it disproves; keep the ones it could not decide as "unverified".
  5. Threat model (only on request, or for a new system). Use the stride-analysis-patterns skill on the architecture found in step 1.
  6. Give the report. Change no code.

Report

  • Summary: the scope covered, what was not covered, the scanners that ran and the ones missing, and the count of findings per severity.
  • Verified findings, most severe first. For each: title, severity (critical, high, medium, low), confidence, file and line, how attacker-controlled input reaches it, the impact, and the smallest fix.
  • Unverified findings, in the same format, with what would settle each one.
  • Hardening notes: weaknesses with no demonstrated attack path, one line each.
  • Dropped: how many findings verification disproved, with the most common reason.

SKILL.md

SKILL.md holds the skill's instructions; it is edited on the Instructions tab.

Frontmatter written into each target's SKILL.md.

Common

No fields set for this target.

Ready to ship better, together?

Spec it. Decompose it. Ship it. All with your AI agent.

Start for free

Join engineers building with Athenode today.