Security Audit

Run a thorough, defender-first security audit of a codebase, modeled on the Codex/Aardvark pipeline: build/refresh a threat model, scan current code and recent commits for vulnerabilities and serious commit-introduced functional regressions, validate findings, chain exploitable issues, rank by severity, and write `.security/` artifacts. Use whenever the user invokes `/security-audit`, `/sec-audit`, `/sec-review`, or asks to scan/audit/review code they control for vulnerabilities, CVEs, XSS, SQLi, SSRF, RCE, secrets, memory-safety bugs, threat modeling, PR/diff security review, or asks whether code is safe. Defensive assessment of the user's own codebase only.

terion-labs 62e8b79 30 files · 4.5 MB Updated

File contents

terion-labs/skills/tree/main/skills/security-audit commit 62e8b79ba3

Frequently asked questions

npx skillmds@latest add terion-labs/security-audit