Web Security Audit

Read-only, production-safe security audit for web apps and vibecoded projects. Use for security audits, OWASP reviews, pentests, secret-leak checks, GDPR/RGPD reviews and pre-deploy verification. Covers 21 checks: client/server trust boundaries, auth and authorization, input validation, expensive-call ordering, rate limits, secrets/PII logs, dependencies, CORS, SQL injection, XSS, security headers, URL sinks, authenticated installers/updates, resource bounds, fail-closed parsing and container least privilege. Framework-agnostic across JavaScript/TypeScript and mixed stacks. Apply judgment to avoid false positives; the optional offline-first script only produces candidates and never replaces code review. Do not load-test, brute-force, fuzz production, trigger metered providers or run untrusted code.

buffalodebile 1f85bf3 9 files · 60.3 KB Updated

File contents

buffalodebile/vibecoding-security-audit/tree/main/ commit 1f85bf32f6

Frequently asked questions

npx skillmds@latest add buffalodebile/web-security-audit