security-audit-skill
View on GitHubA coding-agent skill for multi-phase security audits with independently verified, machine-readable findings
A coding-agent skill that runs a six-phase security audit: reconnaissance, coverage-led hunting, adversarial validation, structured findings.json output, independent verification, and reporting. Install via the Skills CLI; needs a tool-use agent, Node.js, and a sandbox.
Use Cases
Run a multi-phase security audit on a codebase from a coding agentFind vulnerabilities in a repo with isolated hunter and verifier agentsProduce machine-readable findings.json plus Markdown security reportsRe-audit a changed repo additively using prior coverage ledgersHunt attack classes across web, auth, cloud, supply chain, and client-side codeTest LLM-backed targets for prompt injection and agent/tool misuseGet adversarial verification that a reported finding is real before trusting it
Built With
- Language
- JavaScript
- Frameworks
- Node.js · Skills CLI
Tags
security-audit · agent-skill · vulnerability-hunting · multi-agent · adversarial-validation · pentesting · coverage-ledger · machine-readable-findings · security-review · parallel-subagents · prompt-injection · supply-chain · sandbox · json-schema · nodejs