Setup & Installation
What This Skill Does
Runs a multi-phase security audit across a codebase. Covers secrets in git history, dependency supply chains, CI/CD pipeline risks, LLM-specific vulnerabilities, OWASP Top 10, and STRIDE threat modeling. Produces a findings report with exploit scenarios, severity ratings, and remediation guidance. Two modes: daily (8/10 confidence gate, zero noise) and comprehensive (2/10 bar, surfaces more candidates).
Manually checking 14 attack surface categories across git history, CI configs, dependencies, and application code takes hours and most teams skip the archaeology entirely — this covers all of it in one pass with confidence-gated filtering that cuts noise before it reaches your report.
When to use it
- Scanning git history for leaked AWS keys and OAuth tokens before a repo goes public
- Auditing GitHub Actions workflows for pull_request_target misuse and unpinned third-party actions
- Checking webhook handlers for missing HMAC signature verification across the entire codebase
- Running LLM feature audits to trace user input paths that reach system prompts
- Tracking security posture trends across audit runs before a SOC 2 or compliance review