Back to skills
SKILL.md
Qa Security
ASecurityPerform a security audit based on OWASP. Use when the user wants to verify security, look for vulnerabilities, or before a production deployment.
- 5 stars
- 0 votes
- 0 copies
- 3 views
- Added May 28, 2026
Works with
Security analysis
100/100Pro scans all 2 files and shows the line behind each finding
npx -y skills add christopherlouet/claude-base --skill qa-security --agent claude-codeAre you the author of Qa Security?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/christopherlouet-qa-security)---
name: qa-security
description: Perform a security audit based on OWASP. Use when the user wants to verify security, look for vulnerabilities, or before a production deployment.
context: fork
background: false
model: opus
argument-hint: "[scope-or-module]"
---
# Security Audit
## Objective
Identify security vulnerabilities based on OWASP Top 10.
## Instructions
### 1. Automated scan
```bash
# npm dependency audit
npm audit --audit-level=moderate
# Secret search
npx secretlint "**/*"
# Static security analysis
npx eslint --plugin security src/
```
### 2. OWASP Top 10 Checklist
#### A01 - Broken Access Control
- [ ] Authorization checks on every endpoint
- [ ] No IDOR (direct access via predictable IDs)
- [ ] CORS correctly configured
- [ ] Principle of least privilege
#### A02 - Cryptographic Failures
- [ ] Sensitive data encrypted (at rest + in transit)
- [ ] No secrets in code
- [ ] Secure hash algorithms (bcrypt, argon2)
- [ ] TLS/HTTPS enforced
#### A03 - Injection
- [ ] SQL: Parameterized queries / ORM
- [ ] XSS: HTML output escaping
- [ ] Command injection: No shell with user input
- [ ] NoSQL: Query validation
#### A04 - Insecure Design
- [ ] Server-side validation (not just client)
- [ ] Rate limiting on sensitive endpoints
- [ ] Environment separation
#### A05 - Security Misconfiguration
- [ ] Security headers (CSP, X-Frame-Options)
- [ ] No stack traces in production
- [ ] Correct file permissions
#### A06 - Vulnerable Components
- [ ] `npm audit` with no critical vulnerabilities
- [ ] Dependencies maintained and up to date
#### A07 - Authentication Failures
- [ ] Passwords hashed correctly
- [ ] Protection against brute force
- [ ] Secure sessions (httpOnly, secure, sameSite)
#### A08 - Data Integrity Failures
- [ ] Validation of incoming data
- [ ] Secure deserialization
#### A09 - Logging Failures
- [ ] Logs of security events
- [ ] No sensitive data in logs
#### A10 - SSRF
- [ ] Validation of user URLs
- [ ] Whitelist of allowed domains
### 3. Search patterns
```bash
# Potential secrets
grep -rn "password\s*=" --include="*.ts"
grep -rn "api_key\s*=" --include="*.ts"
grep -rn "secret\s*=" --include="*.ts"
# Potential SQL Injection
grep -rn "query.*\$\{" --include="*.ts"
grep -rn "execute.*\+" --include="*.ts"
# Potential XSS
grep -rn "innerHTML" --include="*.tsx"
grep -rn "dangerouslySetInnerHTML" --include="*.tsx"
# Dangerous eval
grep -rn "eval(" --include="*.ts"
grep -rn "new Function(" --include="*.ts"
```
### 4. Recommended security headers
```typescript
// Express with Helmet
app.use(helmet({
contentSecurityPolicy: {
directives: {
defaultSrc: ["'self'"],
scriptSrc: ["'self'"],
styleSrc: ["'self'", "'unsafe-inline'"],
imgSrc: ["'self'", "data:", "https:"],
}
},
hsts: { maxAge: 31536000, includeSubDomains: true }
}));
```
## Expected output
```markdown
## Security Report
### Summary
- **Overall risk level**: [Critical/High/Medium/Low]
- **Vulnerabilities found**: X
- **Vulnerable dependencies**: Y
### Critical vulnerabilities
| Severity | Category | File:Line | Description | Remediation |
|----------|----------|-----------|-------------|-------------|
| CRITICAL | A03 | auth.ts:45 | SQL injection | Parameterized query |
### Important vulnerabilities
[...]
### Priority recommendations
1. [Immediate action]
2. [Short term]
3. [Medium term]
### Dependencies to update
| Package | Version | Vulnerability | Severity |
|---------|---------|---------------|----------|
| lodash | 4.17.19 | Prototype pollution | High |
```
## Rules
- IMPORTANT: Check all 10 OWASP categories
- IMPORTANT: Prioritize by severity
- YOU MUST propose concrete remediations
- NEVER ignore critical vulnerabilities
Think hard about every potential attack vector.
## See also
Two community sources complement this skill:
- [`agamm/claude-code-owasp`](https://github.com/agamm/claude-code-owasp) (171★, last commit 2026-04-28) — covers OWASP Top 10:2025, ASVS 5.0, and 20 language-specific quirks. Independent author. Adoption is modest at the time of this audit; the value is in pointing to a faithful implementation of the canonical OWASP standard rather than in popularity.
- [`semgrep` official Claude plugin](https://claude.com/plugins/semgrep) — Semgrep is an independent security company; their plugin integrates the static-analysis engine into Claude Code sessions for automated scanning.
When working on a security audit, install one or both alongside this skill. This skill captures the **manual review workflow** (when to invoke, what to escalate, blocking criteria); the OWASP skill captures the **canonical attack catalogue with current 2025-2026 categories**; the Semgrep plugin adds the **automated scanner** layer.
Install command and full list of validated vendor skills: `docs/recipes/recommended-vendor-skills.md`. Audit pilot trace: `specs/marketplace-audit/qa-skills-pilot-2026-05-06.md`.
Files in this skill
- SKILL.md
- examples/security-example.md
Attribution
Comments
Loading comments…