Security Audit

Audit a codebase for security weaknesses against the OWASP Top 10 (2025) and seven hardening areas — secrets management, data encryption, input validation/injection, auth, dependency/supply-chain, error handling/logging, and configuration/transport hardening. Use when the user asks to "check security", "do a security review/audit", "find vulnerabilities", "is this app secure", "OWASP review", "check for hardcoded secrets / SQL injection / XSS", or similar. On invocation, ask which area(s) to investigate (or all), then report findings with severity, file:line, and remediation — without changing code until asked.

POSTTTT ef35702 8.8 KB Updated

File contents

POSTTTT/SKILLs/tree/main/.claude/skills/security-audit commit ef357026e7

Frequently asked questions

npx skillmds@latest add postttt/security-audit