Tests et qualitésource GitHub
Audit de sécurité
/SKILLAudit de sécurité approfondi portant sur le Top 10 de l'OWASP, l'authentification, l'autorisation, la protection des données, les vulnérabilités liées aux dépendances et l'analyse des secrets. Référé
// contenu du skill
name: security-audit
category: quality-security
description: Deep security audit covering OWASP Top 10, authentication, authorization, data protection, dependency vulnerabilities, and secrets scanning. Delegates to the Centinela (QA) agent.
Security Audit
Performs a deep security audit using the Centinela (QA) agent.
When to Use This Skill
- Before a release to verify security posture
- After significant code changes that touch authentication, authorization, or data handling
- Periodic security review of the codebase
- When adding new dependencies or external integrations
What This Skill Does
- Runs the SIGN IN checklist
- Performs OWASP Top 10 systematic check (A01-A10)
- Scans for hardcoded secrets, API keys, tokens, and connection strings
- Audits dependencies for known CVEs
- Checks smart contracts if Solidity is present (reentrancy, overflow, access control)
- Runs Security Verification and Quality Verification checklists (TIME OUT)
- Issues verdict and writes report to
docs/reviews/security-audit-{date}.md - Prepares findings handoff to Dev agent
How to Use
Basic Usage
/security-auditScoped Audit
/security-audit src/auth/ src/api/Example
User: /security-audit src/payments/
Output: A security audit report at docs/reviews/security-audit-2026-02-23.md with:
- OWASP Top 10 findings organized by severity
- Secrets scan results
- Dependency vulnerability report
- Verdict: APPROVED or CHANGES REQUIRED
- Fix order recommendation for the Dev agent
Tips
- If no scope is specified, the entire
src/directory is audited - Critical findings trigger the Non-Normal emergency checklist
- The agent will never attempt to fix vulnerabilities — only document them
// source originale publique
davepoon/buildwithclaude/plugins/agent-triforce/skills/security-audit/SKILL.md
Licence : MIT License
Projet indépendant, non affilié à Anthropic. Ce skill reste la propriété de son auteur original.