AgentStack
SKILL verified Apache-2.0 Self-run

Doncheli Security

skill-doncheli-don-cheli-sdd-doncheli-security · by doncheli

Perform OWASP Top 10 static security audit identifying vulnerabilities in access control, cryptography, injection, configuration, and logging. Activate when user mentions "security audit", "OWASP", "security scan", "vulnerabilities", "auditar seguridad".

No reviews yet
0 installs
9 views
0.0% view→install

Install

$ agentstack add skill-doncheli-don-cheli-sdd-doncheli-security

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Doncheli Security? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Don Cheli: OWASP Security Audit

Categories

  • A01: Broken Access Control — endpoints without auth, IDOR, CORS
  • A02: Cryptographic Failures — plaintext passwords, JWT without expiration
  • A03: Injection — SQL, XSS, command injection
  • A04: Insecure Design — missing validation, bypassable business logic
  • A05: Security Misconfiguration — debug mode, default credentials, missing headers
  • A06: Vulnerable Components — dependencies with known CVEs
  • A07: Auth Failures — no brute-force protection, no session management
  • A08: Data Integrity — insecure deserialization
  • A09: Logging Failures — no audit log for security operations
  • A10: SSRF — unvalidated user-supplied URLs

Output

For each finding: ID, severity (Critical/High/Medium/Low), OWASP category, file:line, description, impact, recommended fix, effort estimate.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.