Audit Security

Prove with evidence whether the running system upholds the spec's STRIDE-lite threat model and trust boundaries: secrets in code and git history, authn/authz on every protected path, injection, the lethal trifecta, insecure data handling, dependency exposure, row-level security, rate limits on paid endpoints,. Use in the release phase (run by release-product) or standalone. Read-only: it probes, reproduces and ranks, but never edits code and never configures a provider — code holes become rework tasks, a production gap is reported as setup-production-environment's. Never prints a secret's value. Writes .dev-skills/release/security-audit.md.

a-v-ershov c135f4d 11.9 KB Updated

File contents

a-v-ershov/buildloop/tree/main/skills/audit-security commit c135f4d1d1

Frequently asked questions

npx skillmds@latest add a-v-ershov/audit-security