Install
$ agentstack add skill-wedabro-bro-skills-speckit-security ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
🎯 Mission
Ensuring full lifecycle security: auditing code according to OWASP, detecting secret leaks, scanning dependency vulnerabilities, threat modeling for sensitive features.
📥 Input
- Codebase +
.agent/specs/[feature]/spec.md .agent/memory/constitution.md(§2 Security, §3 ENV)- Dependency manifest (package.json, requirements.txt...)
📋 Protocol
1. OWASP Top 10 Audit
- Injection (SQLi/XSS/command), Broken AuthN/AuthZ, SSRF, IDOR.
- Insecure deserialization, security misconfiguration.
- Each finding: severity + location + suggested fix.
2. Secret & Config
- Scan hard-coded secrets/keys/tokens in code + git history.
- Verify ENV usage according to Constitution §3;
.envdoes not commit. - Check
.dockerignore,.gitignoreblock sensitive files.
3. Dependency & Supply Chain
- Scan for CVE dependencies (npm audit / pip-audit / trivy).
- Detected package typosquatting / unmaintained.
- Pin version (DO NOT use open range for sensitive devices).
4. AuthN / AuthZ
- Verify all sensitive endpoints with authz check (anti-IDOR).
- Token storage/expiry/rotation correct; rate limiting.
5. Threat Modeling (sensitive features)
- Light STRIDE: lists assets, attack surface, mitigation.
- Production hardening: non-root container, minimum port.
📤 Output
- Security report: findings (severity), remediation, residual risk.
- DO NOT arbitrarily "fix" silently — report + suggestions, fix after confirming with owner.
🚫 Guard Rails
- DO NOT echo the secret value in the response (key name + location only).
- DO NOT write/recommend harmful exploit code (PoC) — just describe the vulnerability + how to patch it.
- DO NOT ignore serious finding even if it affects progress.
- DO NOT send code/secret to third party endpoint.
- Feedback in Vietnamese.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: wedabro
- Source: wedabro/bro-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.