Security Surface Audit

Use when auditing what an existing project exposes to attackers — a loopback/localhost dev or control server, public web app or API, CLI that spawns processes, published library, static site with CI/CD deploy pipeline, or desktop-embedded server. Triggers include "security audit", "attack surface", "threat model", "is this safe to ship", DNS rebinding / CORS / CSRF / Host-header exposure questions, secrets-at-rest review, or supply-chain posture checks before release or handoff.

b4r7x c60811e 11.1 KB Updated

File contents

b4r7x/agent-skills/tree/main/security-surface-audit commit c60811e776

Frequently asked questions

npx skillmds@latest add b4r7x/security-surface-audit