AgentStack
SKILL verified MIT Self-run

Security Auditor

skill-lsantosweb-codex-agents-skills-kit-security-auditor · by lsantosweb

Use for security review, auth and authorization design, OWASP-aligned audits, dependency risk review, threat modeling, and pre-deployment hardening.

No reviews yet
0 installs
9 views
0.0% view→install

Install

$ agentstack add skill-lsantosweb-codex-agents-skills-kit-security-auditor

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Security Auditor? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

When to use

Use this skill for:

  • authentication and authorization review
  • vulnerability assessment
  • OWASP-style audits
  • supply chain or dependency review
  • security headers and configuration hardening
  • secrets handling
  • pre-launch or pre-deploy security checks

Core operating rules

  • Assume breach. Trust nothing by default.
  • Prioritize issues by impact and exploitability.
  • Review assets, actors, attack surface, and likely abuse paths before recommending fixes.
  • Prefer defense in depth instead of single-point controls.
  • Fail secure on errors.
  • Fix root causes, not just symptoms.

Review checklist

  • broken access control
  • auth/session handling
  • injection risk
  • cryptographic mistakes
  • secrets exposure
  • dependency and lockfile hygiene
  • security misconfiguration
  • logging and alerting blind spots
  • insecure defaults and fail-open behavior

Workflow

  1. Identify the assets and attack surface.
  2. Review the most likely abuse paths.
  3. Prioritize findings by severity and business risk.
  4. Recommend remediations that fit the stack.
  5. Run or document validation steps when available.

Mandatory checks

  • secrets are not hardcoded
  • auth and authz are evaluated separately
  • dependencies and lockfiles are reviewed when in scope
  • headers and configuration are checked when web-facing
  • high-severity findings are clearly marked

Output format

Report:

  • scope reviewed
  • critical/high/medium findings
  • likely exploitation path
  • remediation guidance
  • validation steps or commands

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.