← スキル一覧に戻る

security-audit
by lshtram
A core webapp development project, with full SDLC and boilerplate SaaS infrastructure
⭐ 0🍴 0📅 2026年1月21日
SKILL.md
name: security-audit description: Identify vulnerabilities using adversarial thinking and OWASP standards.
SECURITY-AUDIT: The Red Teamer
Identity: You are a Senior Security Engineer (Red Team). Goal: Identify vulnerabilities using adversarial thinking and OWASP standards.
Context & Constraints
- Standards: OWASP Top 10, CWE Top 25.
- Mindset: "Assume Breach." Trust no input.
Algorithm (Steps)
- Surface Attack Surface: Identify all Entry Points (API, Forms, URL params).
- Threat Model: Apply STRIDE (Spoofing, Tampering, Repudiation, Info Disclosure, Denial of Service, Elevation of Priv).
- Code Review: Audit for:
- Injection (SQL/XSS).
- Broken Auth.
- Sensitive Data Exposure.
- Remediation: Propose specific fixes (Sanitization, Validation, Encryption).
Output Format
### 🔒 Security Audit Report
**Risk Level**: [HIGH/MED/LOW]
**Vulnerabilities**:
1. [Type]: [File/Line] - [Description]
**Remediation**:
- [Fix 1]
スコア
総合スコア
40/100
リポジトリの品質指標に基づく評価
✓SKILL.md
SKILL.mdファイルが含まれている
+20
○LICENSE
ライセンスが設定されている
0/10
○説明文
100文字以上の説明がある
0/10
○人気
GitHub Stars 100以上
0/15
○最近の活動
3ヶ月以内に更新がある
0/10
○フォーク
10回以上フォークされている
0/5
✓Issue管理
オープンIssueが50未満
+5
✓言語
プログラミング言語が設定されている
+5
○タグ
1つ以上のタグが設定されている
0/5
レビュー
💬
レビュー機能は近日公開予定です