Skip to content
Back to skills

Security Audit

ASecurity

Review code, configuration, permissions, authentication, data handling, and dependencies for exploitable security weaknesses. Use for security reviews, threat analysis, trust boundaries, secrets, authorization, sandboxing, and dangerous command handling.

  • 76 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 3, 2026
ai-agentsrustshellsecurity

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add Miosa-osa/OSA --skill security-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Audit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/miosa-osa-security-audit/badge)](https://www.skillsdirectory.com/skills/miosa-osa-security-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: security-audit
description: Review code, configuration, permissions, authentication, data handling, and dependencies for exploitable security weaknesses. Use for security reviews, threat analysis, trust boundaries, secrets, authorization, sandboxing, and dangerous command handling.
tools:
  - file_read
  - file_grep
  - file_glob
  - shell_execute
triggers:
  - security audit
  - vulnerability
  - threat model
  - authentication
  - authorization
---

# Security Audit

Report concrete attack paths and evidence, not generic checklists.

## Procedure

1. Establish assets, actors, entry points, trust boundaries, and deployment assumptions.
2. Trace untrusted input from ingress to sensitive sinks.
3. Review authentication, authorization, tenancy, and ownership separately.
4. Inspect secret storage, logging, serialization, file paths, commands, and network destinations.
5. Check fail-open behavior, race conditions, replay, confused-deputy paths, and privilege escalation.
6. Validate dependency findings against the versions actually resolved by the project.
7. Rank findings by exploitability and impact.
8. For each finding, provide evidence, an attack scenario, and a specific remediation.
9. Distinguish confirmed vulnerabilities from defense-in-depth recommendations.

## Safety

- Do not run destructive exploitation against real data or external systems.
- Use local fixtures or isolated environments for proof of concept.
- Never expose secrets in logs or reports.
- Do not claim a vulnerability from a pattern match without tracing reachability.

## Report

Order findings by severity.
Include file and line references, affected assumptions, and verification steps for the remediation.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…