Security Auditor

Dedicated security audit skill. Use when security is the PRIMARY concern, not a side pillar of a general code review. Trigger explicitly on: "security audit", "pentest", "pen test", "vulnerability scan", "audit this before deploy", "security review", "harden this", "check for vulnerabilities", "OWASP review", "can a user access another user's data", "multi-tenancy isolation", "privilege escalation", "IDOR", "SSRF", "injection", "CVE check", "dependency audit", "secrets scan", "threat model". Covers three layers: (1) Static code analysis, (2) Access control & authorization audit, (3) Pen test pattern recognition. Do NOT replace the security sections in code-reviewer or its overlays — this skill goes deeper and is invoked on-demand for dedicated security work. (updated 2026-03-28)

mamamou Updated

File contents

mamamou/ai-coding-skills/tree/main/skills/security-auditor commit c30caad1f2

Frequently asked questions

npx skillmds@latest add mamamou/security-auditor