security-audit
Run a repository-wide security audit and own the shared doctrine — severity, evidence, triage, suppression, reporting — that the other security skills restate. Use for a deep audit of a whole codebase or a large subsystem, for turning scanner output into evidence-backed findings, and for producing a security report. Do not use for a pull-request diff (use security-review), for running the toolchain alone (use security-scan), or for dependency, CI, threat-model, smart-contract, or AI-system questions that have their own skill.
Pinned to revision 6335fa80c2f6, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/security-audit/SKILL.md
- skills/security-audit/assets/finding-intake.template.json
- skills/security-audit/assets/patch-gap-scorecard.template.md
- skills/security-audit/assets/trust-boundary-SECURITY.template.md
- skills/security-audit/references/llm-assisted-review.md
- skills/security-audit/references/security-context-and-knowledge-base.md
- skills/security-audit/references/severity-and-reporting.md
- skills/security-audit/references/triage-and-false-positives.md
- skills/security-audit/references/vulnerability-lifecycle.md
Every link opens the file at its source, pinned to the revision this page describes.