Xerj Security Audit

Coverage-guaranteed whitebox security audit of a codebase using XERJ + tree-sitter AST. Use when the user wants to security-review PHP (or other-language) code with a provable "we enumerated every dangerous call" guarantee, or asks to run the WordPress-style sink census / audit. Drives an index-once, query-read-reason loop; proves zero gaps against grep; enriches findings into a queryable ledger.

xerj-org c2e7c6e 2 files · 8.0 KB Updated

File contents

xerj-org/xerj/tree/main/docs/case-studies/wordpress-security-audit/skill commit c2e7c6e5d6

Frequently asked questions

npx skillmds@latest add xerj-org/xerj-security-audit