When auditing security ($ARGUMENTS):
Scan for OWASP Top 10:
- Injection (SQL, NoSQL, command, LDAP)
- Broken authentication
- Sensitive data exposure
- XXE, XSS, CSRF
- Insecure deserialization
- Security misconfiguration
Check for secrets:
- Hardcoded API keys, tokens, passwords
- .env files committed to git
- Credentials in logs or error messages
Dependency audit:
- Run
npm auditor equivalent - Check for known CVEs
- Identify outdated packages
- Run
Code patterns:
- Input validation and sanitization
- Proper use of crypto/hashing
- Secure HTTP headers
- CORS configuration
- Rate limiting
Report findings with severity levels:
- CRITICAL: Immediate exploitation risk
- HIGH: Significant vulnerability
- MEDIUM: Potential risk under certain conditions
- LOW: Best practice improvement