When to use
Use this skill for:
- authentication and authorization review
- vulnerability assessment
- OWASP-style audits
- supply chain or dependency review
- security headers and configuration hardening
- secrets handling
- pre-launch or pre-deploy security checks
Core operating rules
- Assume breach. Trust nothing by default.
- Prioritize issues by impact and exploitability.
- Review assets, actors, attack surface, and likely abuse paths before recommending fixes.
- Prefer defense in depth instead of single-point controls.
- Fail secure on errors.
- Fix root causes, not just symptoms.
Review checklist
- broken access control
- auth/session handling
- injection risk
- cryptographic mistakes
- secrets exposure
- dependency and lockfile hygiene
- security misconfiguration
- logging and alerting blind spots
- insecure defaults and fail-open behavior
Workflow
- Identify the assets and attack surface.
- Review the most likely abuse paths.
- Prioritize findings by severity and business risk.
- Recommend remediations that fit the stack.
- Run or document validation steps when available.
Mandatory checks
- secrets are not hardcoded
- auth and authz are evaluated separately
- dependencies and lockfiles are reviewed when in scope
- headers and configuration are checked when web-facing
- high-severity findings are clearly marked
Output format
Report:
- scope reviewed
- critical/high/medium findings
- likely exploitation path
- remediation guidance
- validation steps or commands