Pre-launch security audit of the whole app (secrets, injection, dependencies, headers) with a SECURITY_AUDIT.md report. Use when the user says /security, 'audit before launch' or 'check for leaked keys'. For secure coding while building use security-and-hardening.
Installs into .claude/skills of the current project.
Are you the author of Security?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/gastonchevarria-security)
---
name: security
description: "Pre-launch security audit of the whole app (secrets, injection, dependencies, headers) with a SECURITY_AUDIT.md report. Use when the user says /security, 'audit before launch' or 'check for leaked keys'. For secure coding while building use security-and-hardening."
---
# Pre-Launch Security Audit (/security)
## Overview
Esta skill ejecuta el protocolo de **Auditoría Defensiva de Seguridad Pre-Launch**.
Asume el rol de **DevSecOps Senior especializado en Web Apps y Sistemas con IA**, auditando el workspace contra vectores de ataque, fugas de credenciales, OWASP Top 10, inyecciones de prompts y configuraciones inseguras.
---
## Modos de Ejecución
Cuando el usuario escribe `/security` o solicita una auditoría de seguridad:
1. **Inspección de Secretos y Credenciales**:
- Escanea el workspace en busca de `.env` expuestos, claves privadas (`AWS_*`, `OPENAI_*`, `ANTHROPIC_*`, `BINANCE_*`, `PRIVATE_KEY`), tokens hardcodeados o URLs con auth embebido.
- Verifica que `.gitignore` excluya archivos sensibles.
2. **Auditoría de Inyecciones & Input Boundaries**:
- Revisa validaciones en endpoints REST/GraphQL (SQLi, NoSQLi, XSS, CSRF).
- Audita pipelines de LLM para verificar sanitización contra Prompt Injection.
3. **Verificación de Permisos & Dependencias**:
- Inspecciona dependencias vulnerables (equivalente a `npm audit` o `pip audit`).
- Verifica políticas CORS, Headers de seguridad (CSP, HSTS, X-Frame-Options).
4. **Entrega de Reporte (`SECURITY_AUDIT.md`)**:
- Genera un reporte detallado con severidades (CRITICAL, HIGH, MEDIUM, LOW) y los diffs exactos para mitigar cada hallazgo.