Security Audit

Security audit of codebase or change

emaraschio e463d8e 4 files · 4.0 KB Updated

File contents

Overview

Comprehensive security review to identify and fix vulnerabilities in the codebase.

Steps

  1. Dependency audit
    • Check for known vulnerabilities
    • Update outdated packages
    • Review third-party dependencies
  2. Code security review
    • Check for common vulnerabilities
    • Review authentication/authorization
    • Audit data handling practices
  3. Infrastructure security
    • Review environment variables
    • Check access controls
    • Audit network security

Security Checklist

  • Dependencies updated and secure
  • No hardcoded secrets
  • Input validation implemented
  • Authentication secure
  • Authorization properly configured

Guardrails

  • Triage dependency CVEs by severity and reachability; never ignore a known CVE.
  • Redact live secrets in findings and cite only their location; never paste the value.
  • Keep the audit read-first: do not commit, merge, push, or run production scripts without explicit consent.

emaraschio/cursor-commands/tree/main/.cursor/skill-contracts/security-audit commit e463d8e343

Frequently asked questions

npx skillmds@latest add emaraschio/security-audit