Security Audit — security audit pipeline
security auditof vulnerability→codeanalysis→penetrationtestreport→improvement inthisbefore teamthis to in count.
execution
inthisbefore team — 5peoplethis SendMessageas direct and verification.
inthisbefore setup
| inthisbefore |
day |
role |
type |
| vulnerability-scanner |
.claude/agents/vulnerability-scanner.md |
CVE, dependency, configurationerror |
general-purpose |
| code-analyst |
.claude/agents/code-analyst.md |
SAST, queue, patterndetection |
general-purpose |
| pentest-reporter |
.claude/agents/pentest-reporter.md |
attack, PoC, impactanalysis |
general-purpose |
| security-consultant |
.claude/agents/security-consultant.md |
improvement, asmap, frameworkmapping |
general-purpose |
| audit-reviewer |
.claude/agents/audit-reviewer.md |
verification, risketc., finalreport |
general-purpose |
workflow
Phase 1: (this direct count)
- user from :
- audit upper: code , infrastructure, this URL
- audit scope: before/minutes, included/excluded item
- ** stack**: language, framework, , DB
- ** requiredmatter** (optional): GDPR, itemsinformation, before
- existing report (optional): thisbefore audit report, vulnerability
_workspace/ project rootin creation
- to
_workspace/00_input.mdin
- audit upper code analysis scope
- existing daythis
_workspace/in and corresponding Phase cases
- request scopein execution decision
Phase 2: team setup and execution
team setupand . between of and :
|
|
responsible |
of |
|
| 1a |
vulnerability |
scanner |
|
_workspace/01_vulnerability_scan.md |
| 1b |
code security analysis |
analyst |
|
_workspace/02_code_analysis.md |
| 2 |
penetration test report |
pentest |
1a, 1b |
_workspace/03_pentest_report.md |
| 3 |
improvement |
consultant |
1a, 1b, 2 |
_workspace/04_remediation_plan.md |
| 4 |
audit review |
reviewer |
1a, 1b, 2, 3 |
_workspace/05_audit_report.md |
1a()and 1b(codeanalysis) parallel execution. initial ofthis as in startto count .
team between :
- scanner completed → analystto CWE mapping before, pentestto attack possible vulnerability before
- analyst completed → pentestto data ·attack before
- pentest completed → consultantto business impact·urgentalso before
- consultant completed → reviewerto before improvement plan before
- reviewer all verification. 🔴 required modification corresponding inthisbeforeto modification request → → verification (maximum 2)
Phase 3: integrated and final
reviewerof report as final :
_workspace/ within all day confirmation
- review reportof 🔴 required modificationthis confirmation
- final userto report:
- vulnerability —
01_vulnerability_scan.md
- code analysis —
02_code_analysis.md
- penetration test —
03_pentest_report.md
- improvement —
04_remediation_plan.md
- final audit report —
05_audit_report.md
per
| user request pattern |
execution |
inthisbefore |
| "security audit before count" |
** audit** |
5people before |
| "this code security analysis" |
**code analysis ** |
analyst + reviewer |
| "vulnerability " |
** ** |
scanner + reviewer |
| "security improvement only" (existing report) |
**consulting ** |
consultant + reviewer |
| "this security report " |
**review ** |
reviewer |
data before as
| strategy |
|
foralso |
| day |
_workspace/ |
week and shared |
| message |
SendMessage |
real-time core information before, modification request |
|
TaskCreate/TaskUpdate |
in progress upper tracking, of |
daypeople : {}_{inthisbefore}_{}.{extension}
error
| error type |
strategy |
| code provided |
userto code as request, day security list provided |
| CVE DB impossible |
as analysis, " " |
| stack people |
code extension/import from automatic detection also |
| inthisbefore failure |
1 retry → failure corresponding this in progress, review reportin people |
| reviewfrom 🔴 |
corresponding inthisbeforein modification request → → verification (maximum 2) |
test
normal
****: "this Node.js Express codethisin about before security audit count"
** result**:
- : npm dependency CVE , detection, configuration
- codeanalysis: OWASP Top 10 criteria vulnerability(XSS, SQL Injection, CSRF etc.), modification code included
- penetrationtest: 3~5items attack , MITRE ATT&CK mapping, PoC procedure
- improvement: NIST CSF analysis, ·· asmap
- review: beforeitem confirmation
existing day for
****: "thisbefore audit report as improvement in progress upper and addition " + thisbefore report
** result**:
- thisbefore report
_workspace/in
- consulting : consultant + reviewer
- thisbefore vulnerability resolution tracking +
error
****: "security , code in "
** result**:
- code day-based security audit listand framework mapping provided
- "code provided after detailed analysis possible" people
- infrastructure/configuration count item within
inthisbeforeper extension
|
as |
-ize upper inthisbefore |
role |
| owasp-testing-guide |
.claude/skills/owasp-testing-guide/skill.md |
code-analyst, pentest-reporter |
OWASP Top 10 vulnerabilityper test , modification guide |
| cve-analysis |
.claude/skills/cve-analysis/skill.md |
vulnerability-scanner |
CVSS count , dependency also, detection |
| threat-modeling |
.claude/skills/threat-modeling/skill.md |
security-consultant, pentest-reporter |
STRIDE, DREAD, Attack Tree, attack analysis |
1---2name: security-audit3description: security auditof vulnerability , code security analysis, penetration test , improvement inthisbefore teamthis to countlower security audit pipeline. 'security audit', 'vulnerability ', 'security ', 'code security analysis', 'penetration test report', 'security vulnerability ', 'OWASP ', 'queue ', 'security improvement ', 'infrastructure security ' etc. security audit beforein this for. code analysisonly necessarylower improvement only necessary inalso supported. , actual network penetration execution, code analysis, SOC operations, real-time security monitoring this of scope .4---56# Security Audit — security audit pipeline78security auditof vulnerability→codeanalysis→penetrationtestreport→improvement inthisbefore teamthis to in count.910## execution 1112**inthisbefore team** — 5peoplethis SendMessageas direct and verification.1314## inthisbefore setup1516| inthisbefore | day | role | type |17|---------|------|------|------|18| vulnerability-scanner | `.claude/agents/vulnerability-scanner.md` | CVE, dependency, configurationerror | general-purpose |19| code-analyst | `.claude/agents/code-analyst.md` | SAST, queue, patterndetection | general-purpose |20| pentest-reporter | `.claude/agents/pentest-reporter.md` | attack, PoC, impactanalysis | general-purpose |21| security-consultant | `.claude/agents/security-consultant.md` | improvement, asmap, frameworkmapping | general-purpose |22| audit-reviewer | `.claude/agents/audit-reviewer.md` | verification, risketc., finalreport | general-purpose |2324## workflow2526### Phase 1: (this direct count)27281. user from :29 - **audit upper**: code , infrastructure, this URL30 - **audit scope**: before/minutes, included/excluded item31 - ** stack**: language, framework, , DB32 - ** requiredmatter** (optional): GDPR, itemsinformation, before33 - **existing report** (optional): thisbefore audit report, vulnerability 342. `_workspace/` project rootin creation353. to `_workspace/00_input.md`in 364. audit upper code analysis scope 375. existing daythis `_workspace/`in and corresponding Phase cases386. request scopein **execution decision**3940### Phase 2: team setup and execution4142team setupand . between of and :4344| | | responsible | of | |45|------|------|------|------|--------|46| 1a | vulnerability | scanner | | `_workspace/01_vulnerability_scan.md` |47| 1b | code security analysis | analyst | | `_workspace/02_code_analysis.md` |48| 2 | penetration test report | pentest | 1a, 1b | `_workspace/03_pentest_report.md` |49| 3 | improvement | consultant | 1a, 1b, 2 | `_workspace/04_remediation_plan.md` |50| 4 | audit review | reviewer | 1a, 1b, 2, 3 | `_workspace/05_audit_report.md` |5152 1a()and 1b(codeanalysis) **parallel execution**. initial ofthis as in startto count .5354**team between :**55- scanner completed → analystto CWE mapping before, pentestto attack possible vulnerability before56- analyst completed → pentestto data ·attack before57- pentest completed → consultantto business impact·urgentalso before58- consultant completed → reviewerto before improvement plan before59- reviewer all verification. 🔴 required modification corresponding inthisbeforeto modification request → → verification (maximum 2)6061### Phase 3: integrated and final 6263reviewerof report as final :64651. `_workspace/` within all day confirmation662. review reportof 🔴 required modificationthis confirmation673. final userto report:68 - vulnerability — `01_vulnerability_scan.md`69 - code analysis — `02_code_analysis.md`70 - penetration test — `03_pentest_report.md`71 - improvement — `04_remediation_plan.md`72 - final audit report — `05_audit_report.md`7374## per 7576| user request pattern | execution | inthisbefore |77|----------------|----------|-------------|78| "security audit before count" | ** audit** | 5people before |79| "this code security analysis" | **code analysis ** | analyst + reviewer |80| "vulnerability " | ** ** | scanner + reviewer |81| "security improvement only" (existing report) | **consulting ** | consultant + reviewer |82| "this security report " | **review ** | reviewer |8384## data before as8586| strategy | | foralso |87|------|------|------|88| day | `_workspace/` | week and shared |89| message | SendMessage | real-time core information before, modification request |90| | TaskCreate/TaskUpdate | in progress upper tracking, of |9192daypeople : `{}_{inthisbefore}_{}.{extension}`9394## error 9596| error type | strategy |97|----------|------|98| code provided | userto code as request, day security list provided |99| CVE DB impossible | as analysis, " " |100| stack people | code extension/import from automatic detection also |101| inthisbefore failure | 1 retry → failure corresponding this in progress, review reportin people |102| reviewfrom 🔴 | corresponding inthisbeforein modification request → → verification (maximum 2) |103104## test 105106### normal 107****: "this Node.js Express codethisin about before security audit count"108** result**:109- : npm dependency CVE , detection, configuration 110- codeanalysis: OWASP Top 10 criteria vulnerability(XSS, SQL Injection, CSRF etc.), modification code included111- penetrationtest: 3~5items attack , MITRE ATT&CK mapping, PoC procedure112- improvement: NIST CSF analysis, ·· asmap113- review: beforeitem confirmation114115### existing day for 116****: "thisbefore audit report as improvement in progress upper and addition " + thisbefore report 117** result**:118- thisbefore report `_workspace/`in 119- consulting : consultant + reviewer 120- thisbefore vulnerability resolution tracking + 121122### error 123****: "security , code in "124** result**:125- code day-based security audit listand framework mapping provided126- "code provided after detailed analysis possible" people127- infrastructure/configuration count item within128129130## inthisbeforeper extension 131132| | as | -ize upper inthisbefore | role |133|------|------|-----------------|------|134| owasp-testing-guide | `.claude/skills/owasp-testing-guide/skill.md` | code-analyst, pentest-reporter | OWASP Top 10 vulnerabilityper test , modification guide |135| cve-analysis | `.claude/skills/cve-analysis/skill.md` | vulnerability-scanner | CVSS count , dependency also, detection |136| threat-modeling | `.claude/skills/threat-modeling/skill.md` | security-consultant, pentest-reporter | STRIDE, DREAD, Attack Tree, attack analysis |