security-audit
Use when conducting security assessments — OWASP Top 10 / API / LLM, CWE Top 25, CVSS scoring — auditing PHP/TYPO3, APIs, frontend, Terraform/K8s/Docker IaC, AWS cloud, AI agent configs, or scanning dependencies.
How do I install this agent skill?
npx skills add https://github.com/netresearch/security-audit-skill --skill security-auditIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill is a comprehensive security auditing toolkit designed for assessing various programming ecosystems and cloud configurations. It contains educational examples of vulnerabilities and scanning scripts that use standard system utilities. No malicious behavior was detected.
- Socketwarn
1 alert: gptAnomaly
- Snykpass
Risk: LOW · No issues
- Runlayerfail
21/24 files flagged
- ZeroLeakspass
Score: 93/100 · 2 sections analyzed
What does this agent skill do?
Security Audit Skill
Security audit patterns (OWASP Top 10, LLM Top 10 2025, CWE Top 25 2025, CVSS v4.0), cloud/IaC, GitHub security. 80+ PHP/TYPO3 checkpoints (v14.3 LTS in typo3-security.md).
Expertise Areas
- Vulnerabilities: XXE, SQLi, XSS, CSRF, command injection, path traversal, file upload, deserialization, SSRF, SSTI, JWT, type juggling
- Standards: OWASP Top 10 / API / LLM (2025), CWE Top 25, CVSS v3.1/v4.0, OWASP ASVS
- Cloud & IaC: AWS; Terraform, Kubernetes, Docker, Helm
- API & Frontend: REST/GraphQL authZ, rate limits, mass assignment, CSP, DOM-XSS
- AI Agents: SKILL.md/AGENTS.md/CLAUDE.md/mcp.json/hooks.json audit; prompt injection; excessive agency
Reference Files (in references/, .md implied)
- Core: owasp-top10, cwe-top25, xxe-prevention, cvss-scoring, api-key-encryption
- Prevention: deserialization-prevention, path-traversal-prevention, file-upload-security, input-validation, error-message-sanitization, ssh-forced-command-hardening
- Architecture: authentication-patterns, security-headers, security-logging, cryptography-guide, security-invariants, indistinguishability-defences
- Language features (
*-security-features): php, python, javascript-typescript, nodejs, go - Frameworks (
*-security): typo3, typo3-fluid, typo3-typoscript, symfony, react, vue - Cloud & IaC: aws-security, iac-security
- API & Frontend: api-security, frontend-security
- AI Agent: llm-security (OWASP LLM Top 10 2025)
- Threats: modern-attacks, cve-patterns
- DevSecOps: ci-security-pipeline, supply-chain-security, automated-scanning, gha-security, git-history-secrets
- Incident: supply-chain-incident-response
Security Checklist
-
semgrep/opengrep,trivy fs --severity HIGH,CRITICAL,gitleaksclean - bcrypt/Argon2 passwords, CSRF on state changes, TLS 1.2+
- Server-side input validation; parameterized SQL; XML entities off
- Output encoding + CSP; no unserialize() on user input
- API keys encrypted; exception messages sanitized
- Secrets out of VCS; audit logging on
- Uploads validated, renamed, outside web root
- Headers HSTS + X-Content-Type-Options; dependencies scanned
GitHub Actions Security
- NEVER interpolate
${{ inputs.* }}/${{ github.event.* }}inrun:— useenv: - Dependency triage: upgrade > override > dismiss. Full patterns:
references/gha-security.md.
Verification
./scripts/security-audit-dispatcher.sh /path/to/project # auto-detect stack
./scripts/security-audit.sh /path/to/project # PHP-only
./scripts/github-security-audit.sh owner/repo # GH repo
Dispatcher detects the stack from indicator files and runs matching scripts/scanners/*.sh (13 ecosystems; see references/ index).
Contributing: https://github.com/netresearch/security-audit-skill
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/netresearch/security-audit-skill/security-audit">View security-audit on skillZs</a>