SE

Provides comprehensive security reviews, auditing for vulnerabilities and compliance.

Install

mkdir -p .claude/skills/security-audit-thedarkskyxd && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/15616" && unzip -o skill.zip -d .claude/skills/security-audit-thedarkskyxd && rm skill.zip

Installs to .claude/skills/security-audit-thedarkskyxd

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Security auditing and vulnerability assessment specialist. Use when conducting
78 chars✓ has a “when” trigger
Advanced

Key capabilities

  • Conduct security code reviews
  • Identify vulnerabilities with CVSS scoring
  • Perform OWASP Top 10 assessments
  • Review authentication and authorization mechanisms
  • Analyze dependency vulnerabilities
  • Create remediation roadmaps for identified issues

How it works

This skill performs security audits by reviewing code, assessing vulnerabilities against OWASP Top 10, analyzing dependencies, and documenting findings with CVSS scores and remediation plans.

Inputs & outputs

You give it
Application code, system architecture, or dependency lists
You get back
Security audit report including severity, CVSS score, CWE classification, proof of concept, and remediation steps

When to use security-audit

  • Perform security audit
  • Check owasp top 10
  • Analyze dependency risks
  • Create remediation roadmap

About this skill

Security Audit Skill

Comprehensive security auditing covering code review, vulnerability assessment, OWASP Top 10, dependency analysis, and remediation planning.

What This Skill Does

  • Conducts security code reviews
  • Identifies vulnerabilities (CVSS scoring)
  • Performs OWASP Top 10 assessments
  • Audits authentication/authorization
  • Reviews data protection controls
  • Analyzes dependency vulnerabilities
  • Creates remediation roadmaps

When to Use

  • Security reviews before release
  • Compliance audits
  • Penetration test preparation
  • Incident response analysis
  • Dependency vulnerability assessment

Reference Files

  • references/SECURITY_AUDIT.template.md - Comprehensive security audit report format
  • references/owasp_checklist.md - OWASP Top 10 checklist with CVSS scoring and CWE references

Workflow

  1. Define scope and methodology
  2. Perform static/dynamic analysis
  3. Document findings by severity
  4. Map to OWASP categories
  5. Create remediation roadmap
  6. Verify fixes

Output Format

Security findings should include:

  • Severity (Critical/High/Medium/Low)
  • CVSS score and vector
  • CWE classification
  • Proof of concept
  • Remediation steps

When not to use it

  • When only general code quality checks are needed
  • When the focus is solely on performance optimization

Limitations

  • Requires defining the scope and methodology for the audit
  • Findings must be documented by severity
  • Remediation roadmaps must be created

How it compares

This skill provides a structured and complete security auditing process, including CVSS scoring and OWASP mapping, which is more detailed than a basic code review.

Compared to similar skills

security-audit side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
security-audit (this skill)06moNo flagsAdvanced
software-security216moNo flagsIntermediate
fix-dependabot-alerts186moReviewIntermediate
backend-security-coder244moNo flagsIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

You might also like

software-security

project-codeguard

A software security skill that integrates with Project CodeGuard to help AI coding agents write secure code and prevent common vulnerabilities. Use this skill when writing, reviewing, or modifying code to ensure secure-by-default practices are followed.

2186

fix-dependabot-alerts

microsoft

Fix Dependabot security alerts by updating vulnerable npm dependencies. Use when the user mentions "dependabot", "security alerts", "vulnerability", "CVE", or wants to update packages with security issues.

1872

backend-security-coder

sickn33

Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.

2446

equilateral-agents

Equilateral-AI

22 production-ready AI agents with database-driven orchestration for security reviews, code quality analysis, deployment validation, infrastructure checks, and compliance. Auto-activates for security concerns, deployment tasks, code reviews, quality checks, and compliance questions. Includes upgrade paths to enterprise features (GDPR, HIPAA, multi-account AWS, ML-based optimization).

564

top-100-web-vulnerabilities-reference

davila7

This skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about injection attacks", "review access control weaknesses", "analyze API security issues", "assess security misconfigurations", "understand client-side vulnerabilities", "examine mobile and IoT security flaws", or "reference the OWASP-aligned vulnerability taxonomy". Use this skill to provide comprehensive vulnerability definitions, root causes, impacts, and mitigation strategies across all major web security categories.

547

differential-review

trailofbits

Performs security-focused differential review of code changes (PRs, commits, diffs). Adapts analysis depth to codebase size, uses git history for context, calculates blast radius, checks test coverage, and generates comprehensive markdown reports. Automatically detects and prevents security regressions.

3115

Search skills

Search the agent skills registry