← Back to list

security-audit
by xingxerx
⭐ 0🍴 0📅 Jan 21, 2026
SKILL.md
name: security-audit description: Includes sub-skills for OWASP Top 10 checks and ethical hacking heuristics.
Security Audit Skill
This skill allows the agent to perform basic security auditing and vulnerability scanning on the codebase.
OWASP Top 10 Checklist
When auditing, check for:
- Injection: SQLi, NoSQLi, Command Injection. (Look for concatenated strings in queries).
- Broken Auth: Weak passwords, missing tokens, exposed session IDs.
- Sensitive Data Exposure: Keys in code, PII logging, weak crypto.
- XXE: XML External Entities.
- Broken Access Control: IDOR, missing role checks.
Heuristics
- "Never trust user input."
- "Sanitize early, escape late."
- "Least Privilege principle."
Action
- If you find a vulnerability, flag it with
[SECURITY CRITICAL]. - Suggest a remediation (e.g., "Use parameterized queries").
Score
Total Score
60/100
Based on repository quality metrics
✓SKILL.md
SKILL.mdファイルが含まれている
+20
✓LICENSE
ライセンスが設定されている
+10
○説明文
100文字以上の説明がある
0/10
○人気
GitHub Stars 100以上
0/15
○最近の活動
3ヶ月以内に更新がある
0/10
○フォーク
10回以上フォークされている
0/5
✓Issue管理
オープンIssueが50未満
+5
✓言語
プログラミング言語が設定されている
+5
○タグ
1つ以上のタグが設定されている
0/5
Reviews
💬
Reviews coming soon