security-audit
Created here
Use when a repository, a path or the current diff needs a full security audit that combines code review, dependency audit and scanner results into one verified report.
SKILL.md
Run a full defensive security audit of this project and return one report that holds only findings that survived verification.
Arguments
- A scope (optional): a path,
difffor the uncommitted and branch changes, or nothing for the whole repository.
Flow
- Scope. Resolve the scope. For the whole repository, list its languages, frameworks, entry points (HTTP routes, CLI commands, queue consumers, cron jobs), dependency manifests, CI workflows and infrastructure files. In a large repository, say which parts you will cover first and why.
- Scan. Invoke the
security-scanskill for the scope and keep its results as leads. - Review in parallel. Delegate at the same time:
- to the
security-code-revieweragent: the scope, the entry points and the scanner leads about source code; - to the
security-dependency-auditoragent: the dependency manifests, lockfiles, CI workflows and the scanner leads about dependencies. Without subagent support, do both reviews yourself, one after the other, following thesecurity-reviewandowasp-securityskills for code and thegha-security-reviewskill for GitHub Actions workflows.
- to the
- Verify. Pass every finding to the
security-finding-verifieragent (several agents for many findings, a few findings each). Drop the findings it disproves; keep the ones it could not decide as "unverified". - Threat model (only on request, or for a new system). Use the
stride-analysis-patternsskill on the architecture found in step 1. - Give the report. Change no code.
Report
- Summary: the scope covered, what was not covered, the scanners that ran and the ones missing, and the count of findings per severity.
- Verified findings, most severe first. For each: title, severity (critical, high, medium, low), confidence, file and line, how attacker-controlled input reaches it, the impact, and the smallest fix.
- Unverified findings, in the same format, with what would settle each one.
- Hardening notes: weaknesses with no demonstrated attack path, one line each.
- Dropped: how many findings verification disproved, with the most common reason.
SKILL.md
SKILL.md holds the skill's instructions; it is edited on the Instructions tab.
Frontmatter written into each target's SKILL.md.
Common
No fields set for this target.