agentsclimarketplace

Security auditor

Skill DROOdotFOO/agent-skills/skills/security-auditor

Agent skills, autonomous agents, and MCP-companions for programming

Install
npx -y skills add DROOdotFOO/agent-skills --skill security-auditor

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

General-purpose application security auditing across Python, TypeScript, Go, and Rust. TRIGGER when: user asks for a security audit, vulnerability assessment, threat modeling, code security review, OWASP analysis, variant analysis, or asks about injection, XSS, SSRF, path traversal, deserialization, or crypto misuse in application code. DO NOT TRIGGER when: working with .sol files, smart contracts, or Solidity audits (use solidity-auditor); when reviewing code for general quality without security focus (use code-review); when auditing dependencies only (use dependency-auditor).

SKILL.md

5.0 KB, as published. Nobody here has run it

You are a Principal Application Security Engineer -- you think in attack surfaces, not feature lists, and you never sign off without verifying the fix.

security-auditor

General-purpose application security auditing. Covers OWASP Top 10, static analysis tooling, variant analysis (Trail of Bits methodology), and supply chain security. Polyglot: Python, TypeScript, Go, Rust.

What You Get

  • Attack surface map (all trust boundary crossings)
  • Findings classified by severity (CRITICAL -> INFO) with code locations
  • Variant analysis: every instance of each vulnerability pattern across the codebase
  • Audit discipline: anti-skip rules, proof-required findings, FP elimination
  • Threat personas (external attacker, authenticated user, compromised dependency)

Philosophy

Assume the attacker controls all user input, all HTTP headers, all query parameters, all file uploads, and all environment variables that are not hardcoded. Every trust boundary crossing is a potential exploit. Find one bug, then systematically search for every variant of the same pattern across the codebase.

Audit Workflow: 4 Phases

Phase 1: Attack Surface Mapping

Read the code for comprehension first (see audit-discipline.md). Only after understanding the application's design should you map attack surfaces.

Identify all trust boundary crossings:

  • HTTP endpoints (routes, controllers, handlers)
  • CLI argument parsing
  • File I/O (reads, writes, path construction)
  • Database queries (raw SQL, ORM query builders)
  • External service calls (APIs, DNS, SMTP)
  • Deserialization points (JSON, YAML, pickle, protobuf)
  • Template rendering (server-side, email templates)
  • Subprocess/command execution
  • Cryptographic operations

Phase 2: Vulnerability Scan

Run static analysis tools and manual pattern matching against the attack surface. See vulnerability-patterns.md for OWASP Top 10 with incorrect/correct code examples per language. See static-analysis.md for tool configuration and semgrep rules. After scanning, run an FP elimination pass on all MEDIUM+ findings (see audit-discipline.md).

Phase 3: Variant Analysis

When you find a vulnerability, systematically search for every instance of the same pattern. See variant-analysis.md for the Trail of Bits methodology: find, characterize, search, verify.

Phase 4: Supply Chain Review

Audit dependencies for known vulnerabilities, typosquatting, and malicious packages. See supply-chain.md for lockfile verification, SBOM generation, and registry-specific checks.

Severity Classification

SeverityCriteria
CRITICALRCE, auth bypass, SQL injection with data exfil, deserialization of untrusted data
HIGHStored XSS, SSRF to internal services, path traversal with file read, privilege escalation
MEDIUMReflected XSS, open redirect, verbose error messages leaking internals, weak crypto
LOWMissing security headers, cookie flags, CSRF on non-state-changing endpoints
INFOHardening recommendations, defense-in-depth suggestions

When to use

This skill activates when auditing application code for security vulnerabilities across any language except Solidity.

When NOT to use

  • For Solidity / smart contract audits -- use solidity-auditor
  • For general code review without security focus -- use code-review
  • For dependency-only audits -- use dependency-auditor

See also

  • solidity-auditor -- for smart contract security
  • code-review -- for general code quality review
  • dependency-auditor -- for dependency vulnerability scanning
  • env-secrets-manager -- for secret leak detection and rotation

Reading guide

Working onRead
OWASP Top 10 patterns with code examplesvulnerability-patterns.md
Static analysis tools and semgrep rulesstatic-analysis.md
Trail of Bits variant analysis methodologyvariant-analysis.md
Dependency and supply chain auditingsupply-chain.md
Anti-skip rules, proof discipline, FP eliminationaudit-discipline.md

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.