Quaere Audit

This skill should be used whenever the user asks for a serious security audit, vulnerability review, bug bounty triage, threat-model-driven code review, protocol/spec conformance audit, auth/authz or tenant-isolation review, exploitability analysis, CVE/advisory impact assessment, or security-sensitive PR review when exploitability or a security property must be proven. It coordinates a property-driven audit: scope and rules of engagement → security properties → attack surface → source/boundary/sink or guard mapping → proof attempt → false-positive gates → severity/confidence → safe repro/report, with companion handoffs for external facts, semantic invariants, evidence-gated claims, and authorized PoC/fix work.

haru0416-dev fae6f62 7 files · 31.7 KB Updated

File contents

haru0416-dev/quaere/tree/main/skills/extensions/quaere-audit commit fae6f6216e

Frequently asked questions

npx skillmds@latest add haru0416-dev/quaere-audit