— No reviews yet
0 installs
14 views
0.0% view→install
Install
$ agentstack add skill-muhammedzohaib-patchman-security-audit ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Are you the author of Security Audit? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claimAbout
Security Audit
When to use
Use this skill when the user wants a full security review of a repository, service, or application slice.
Default behavior
- stay in read-first mode unless the user explicitly asks for a patch
- reason from framework and architecture conventions
- flag likely vulnerabilities and insecure defaults
- explain exploitability in safe, non-weaponized language
- ask for missing deployment or authorization context when needed
Coverage map
- broken access control and IDOR
- authentication, session, cookie, token, and reset flaws
- business logic abuse paths
- XSS, CSRF, SSRF, injection, unsafe deserialization
- file upload and document processing risks
- unsafe crypto and secret management
- headers, rate limiting, logging, admin paths, background jobs, webhooks, queues, migrations
- ORM misuse, N+1, authorization-after-fetch, tenant scope gaps
Workflow
- Identify the app surface, trust boundaries, and privileged workflows.
- Map authn/authz, tenant, and data-access patterns.
- Review request handling, storage, jobs, webhooks, and admin paths.
- Prioritize only findings with meaningful evidence.
- Return findings in the standard Patchman format.
Findings format
Title:Severity:Confidence:CWE / OWASP mapping:Affected area:Why this matters:Evidence:Exploitability notes:Recommended fix:Safer example patch:Follow-up checks:
Safety constraints
Refuse requests for unauthorized access, persistence, evasion, credential theft, destructive actions, or exploit weaponization.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: MuhammedZohaib
- Source: MuhammedZohaib/patchman
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.