Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment processing, user data handling, API endpoint creation, file upload handling, database queries, external API integration. Skip when: read-only operations on public data, internal development tooling, static documentation, styling changes.
57
65%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Fix and improve this skill with Tessl
tessl review fix ./.agents/skills/security-audit/SKILL.mdComprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement.
Run comprehensive security analysis on the codebase
npx @claude-flow/cli security scan --depth fullExample:
npx @claude-flow/cli security scan --depth full --output security-report.jsonCheck for input validation issues
npx @claude-flow/cli security scan --check input-validationExample:
npx @claude-flow/cli security scan --check input-validation --path ./src/apiCheck for path traversal vulnerabilities
npx @claude-flow/cli security scan --check path-traversalCheck for SQL injection vulnerabilities
npx @claude-flow/cli security scan --check sql-injectionCheck for cross-site scripting vulnerabilities
npx @claude-flow/cli security scan --check xssScan dependencies for known CVEs
npx @claude-flow/cli security cve --scanExample:
npx @claude-flow/cli security cve --scan --severity highGenerate full security audit report
npx @claude-flow/cli security audit --reportExample:
npx @claude-flow/cli security audit --report --format markdown --output SECURITY.mdRun threat modeling analysis
npx @claude-flow/cli security threats --analyzeCheck for hardcoded secrets
npx @claude-flow/cli security validate --check secrets| Script | Path | Description |
|---|---|---|
security-scan | .agents/scripts/security-scan.sh | Run full security scan pipeline |
cve-remediate | .agents/scripts/cve-remediate.sh | Auto-remediate known CVEs |
| Document | Path | Description |
|---|---|---|
Security Checklist | docs/security-checklist.md | Security review checklist |
OWASP Guide | docs/owasp-top10.md | OWASP Top 10 mitigation guide |
b14c79e
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.