security-audit

v2026.09.25

Use when reviewing code security, auditing dependencies for CVEs, checking configuration or secret security, assessing authentication and authorization patterns, identifying OWASP vulnerabilities (injection, XSS, CSRF), or addressing security concerns about implementations.

GitHub
安装命令
npx skhub add srstomp/security-audit
Markdown
SKILL.md

Security Audit

Systematic security review for application code, dependencies, and configuration.

Not a replacement for professional penetration testing. Identifies common vulnerabilities within scope of code review.

Audit Types

TypeFocusWhen to Use
Code ReviewOWASP Top 10, injection, authNew features, PRs, suspicious code
DependencyCVEs, outdated packagesBefore deploy, periodic, CI/CD
ConfigurationSecrets, permissions, hardeningInfrastructure changes, new envs
ArchitectureAttack surface, data flowDesign phase, major refactors
API SecurityAuth, authz, rate limitingNew endpoints, public APIs

When NOT to Use

  • Designing new auth flows — Use api-design for designing OAuth2/JWT endpoints from scratch
  • Performance issues — Use observability to diagnose latency and resource problems, even if caused by auth overhead
  • CI/CD pipeline security — Use ci-cd for pipeline hardening (secret management, permissions)

Key Principles

  • Scope first — Define audit area, depth, and constraints before scanning
  • Classify severity — Critical (24-48h), High (1 week), Medium (2-4 weeks), Low (backlog)
  • Remediate or track — Fix critical issues immediately, create ohno tasks for the rest
  • No secrets in code — Scan for hardcoded credentials, API keys, connection strings

Quick Start Checklist

  1. Define audit scope and type (code, dependency, config, architecture, API)
  2. Run automated scans (npm audit, grep patterns, secret detection)
  3. Review findings and classify severity using decision tree in references
  4. Remediate critical/high findings immediately
  5. Create ohno tasks for medium/low findings with appropriate priority
  6. Document findings in audit report

References

ReferenceDescription
owasp-top-10.mdOWASP vulnerabilities with detection and fixes
dependency-security.mdnpm audit, pip-audit, Snyk, CI/CD integration
auth-patterns.mdSecure authentication and authorization patterns
api-security.mdAPI-specific security concerns
secrets-management.mdHandling sensitive configuration

Runtime Notes

  • Claude Code: dispatch yokay-security-scanner via the Task tool with subagent_type: "pokayokay:yokay-security-scanner".
  • Codex: there is no subagent dispatch. Execute the agent's role inline — read the corresponding agents/yokay-<name>.md and follow its Behavioral Defaults, Critical Rules, and Output Contract directly in the current session.
发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.25

发布时间

Sep 25, 2026

分类

未分类

许可证

MIT

源路径

plugins/pokayokay/skills/security-audit

默认分支

master

最新提交

ef6a34d

Tree SHA

7e3eba3