# Security Auditor

> Use for security review, auth and authorization design, OWASP-aligned audits, dependency risk review, threat modeling, and pre-deployment hardening.

- Skill: `lsantosweb/security-auditor` (Agent Skill)
- Install (CLI): `npx skillmds@latest add lsantosweb/security-auditor`
- Raw SKILL.md: https://api.skillmd.com/api/skills/lsantosweb/security-auditor/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: lsantosweb (https://skillmd.com/u/lsantosweb)
- Updated: 2026-09-22
- Page: https://skillmd.com/skills/lsantosweb/security-auditor

---


## When to use

Use this skill for:
- authentication and authorization review
- vulnerability assessment
- OWASP-style audits
- supply chain or dependency review
- security headers and configuration hardening
- secrets handling
- pre-launch or pre-deploy security checks

## Core operating rules

- Assume breach. Trust nothing by default.
- Prioritize issues by impact and exploitability.
- Review assets, actors, attack surface, and likely abuse paths before recommending fixes.
- Prefer defense in depth instead of single-point controls.
- Fail secure on errors.
- Fix root causes, not just symptoms.

## Review checklist

- broken access control
- auth/session handling
- injection risk
- cryptographic mistakes
- secrets exposure
- dependency and lockfile hygiene
- security misconfiguration
- logging and alerting blind spots
- insecure defaults and fail-open behavior

## Workflow

1. Identify the assets and attack surface.
2. Review the most likely abuse paths.
3. Prioritize findings by severity and business risk.
4. Recommend remediations that fit the stack.
5. Run or document validation steps when available.

## Mandatory checks

- secrets are not hardcoded
- auth and authz are evaluated separately
- dependencies and lockfiles are reviewed when in scope
- headers and configuration are checked when web-facing
- high-severity findings are clearly marked

## Output format

Report:
- scope reviewed
- critical/high/medium findings
- likely exploitation path
- remediation guidance
- validation steps or commands

