skills/security-workflow/SKILL.md
Perform an advanced security audit on source code and dependencies — vulnerabilities, CVEs, supply chain risks, and hardening plan
npx skillsauth add nano-step/skill-manager skills/security-workflowInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Perform a comprehensive security audit on a project's source code and dependencies. You act as an elite Security Auditor and Secure Software Architect — analyzing code for vulnerabilities, scanning dependencies for CVEs and supply chain risks, and delivering a prioritized fix plan.
Default language: Vietnamese (output). Switch to English if user explicitly requests.
Input: The argument after /security is either:
If no input is provided, scan the current working directory. If the project is too large, focus on: (1) dependency files first, (2) authentication/authorization code, (3) API endpoints, (4) data handling.
You operate as an elite security auditor with 10+ years of experience:
1. Technical Inventory:
2. Dependency Classification:
For EACH suspicious or high-risk package, report:
| Field | Required | |-------|----------| | Package name | Yes | | Current version | Yes | | Latest stable version | Yes | | Known CVEs | Yes (list CVE IDs or "None known") | | Maintenance status | Yes (Active / Low activity / Unmaintained / Deprecated) | | Weekly downloads estimate | Yes (for risk exposure context) | | Risk reason | Yes — one or more of: Known exploit, Supply chain risk, Over-permission, Large attack surface, Typosquatting risk |
If package is bloated:
Scan source code for these vulnerability categories. For EACH finding:
Vulnerability categories to check:
Each finding MUST include ALL of:
For each problematic package, recommend ONE of:
| Situation | Action | |-----------|--------| | Has CVE | Upgrade to specific safe version | | Unmaintained | Replace with named alternative | | Bloated / too heavy | Replace with lightweight alternative | | Duplicated functionality | Refactor to remove |
Each recommendation MUST include:
Create a prioritized risk table with ALL findings:
| Issue | Severity | Exploitability | Fix Effort | Priority | |-------|----------|---------------|------------|----------| | ... | Critical/High/Med/Low | Easy/Medium/Hard | Low/Med/High | P0/P1/P2/P3 |
Exploitability guide:
Then produce:
## Project Overview
**Tech Stack:** ...
**Runtime:** ...
**Framework:** ...
**Dependency Ecosystem:** ... (X total deps, Y dev deps)
---
## Dependency Risk Report
### Critical Risk Packages
| Package | Version | Latest | CVE | Status | Risk |
|---------|---------|--------|-----|--------|------|
| ... | ... | ... | ... | ... | ... |
**Details:**
- **[package-name]**: [risk explanation + recommendation]
### High Risk Packages
[same format]
### Medium Risk Packages
[same format]
---
## Code-Level Vulnerabilities
### Critical
- **[Vuln type]** in `[file:line]`
- Exploit: ...
- Impact: ...
- Fix: ...
- Code fix: ...
### High Severity
[same format]
### Medium Severity
[same format]
### Low Severity
[same format]
---
## Recommended Upgrades & Replacements
| Current Package | Action | Target | Why | Migration Cost |
|----------------|--------|--------|-----|----------------|
| [email protected] | Upgrade | @2.1 | CVE-XXXX fixed | Low |
| package-b | Replace | alt-package | Unmaintained | Medium |
---
## Risk Prioritization
| # | Issue | Severity | Exploitability | Fix Effort | Priority |
|---|-------|----------|---------------|------------|----------|
| 1 | ... | Critical | Easy | Low | P0 |
| 2 | ... | High | Medium | Medium | P1 |
---
## Top 5 Immediate Fixes
1. **[Issue]** — [1-line fix instruction]
2. ...
3. ...
4. ...
5. ...
## Quick Wins
- ...
- ...
---
## Security Hardening Plan
### Short-term (1-2 weeks)
- ...
### Medium-term (1-2 months)
- ...
### Long-term (architectural)
- ...
### Monitoring & Prevention Tools
- ...
tools
Humanization layer for LLM conversation — makes the model sound and respond like a real, thoughtful, embodied human rather than an assistant or chatbot. Use whenever the reply will be read by a human and warmth, presence, or texture matter more than machine-readability. Triggers on any of: "human", "humans", "humanize", "humanization", "be human", "more human", "feel human", "people", "person", "real person", "real human", "friend", "friendly", "like a friend", "respond like a friend", "buddy", "talk", "talking", "talk to me", "talk like a person", "chat", "chatting", "conversation", "converse", "discuss", "discussion", "communication", "communicate", "listen", "just listen", "sit with me", "vent", "venting", "I just want to vent", "company", "presence", "stop being an AI", "stop sounding like a bot", "less corporate", "less robotic", "less formal", "warmer", "warm tone", "empathy", "empathetic", "comfort", "support me", "emotional support", "be honest with me", "be real with me", "real talk", "heart-to-heart", "deep conversation", "casual", "casual chat", "small talk", "chitchat", "say something", "tell me something", and on any emotional / relational / personal-decision / interpersonal context — grief, joy, anger, fear, shame, doubt, loneliness, dating, breakup, conflict, family, parents, sibling, friendship, marriage, divorce, in-laws, kids, parenting, work stress, burnout, career decision, quitting, firing, layoff, anxiety, depression, panic, sleep, dreams, identity, faith, doubt, meaning, mortality, celebration, milestone, achievement, gratitude, apology, forgiveness. Also loads when the user writes in non-English (any language) with emotional weight, when the user's message is shorter than 8 words and affect-laden, when the user types in lowercase fragments, when the user types in ALL CAPS with excitement, or when the user explicitly asks for a friend / mentor / older-sibling / wise-listener voice. Do NOT use for code generation, tool calls, structured data output, SQL, API contracts, or any task where machine-readability matters more than human warmth.
tools
Use this skill whenever the user mentions open-design, od_generate_design, OD daemon, BYOK design generation, generating HTML mockups from a PRD, creating or managing Open Design projects, saving design artifacts, linting generated HTML, or any of the 10 `od_*` MCP tools (od_list_projects, od_get_project, od_create_project, od_update_project, od_delete_project, od_save_artifact, od_save_project_file, od_lint_artifact, od_compose_brief, od_generate_design). Also trigger on phrases like "generate a design", "create a mockup", "make a landing page", "list my OD projects", "the design daemon", "the streaming design tool", and on any 401/404/422 error coming from an `od_*` tool call. Covers env-var setup (`OD_DAEMON_URL`, auth modes, BYOK), the full PRD → generate → save → lint workflow, error diagnosis, and the safety rails (lint before save, never commit BYOK keys). Triggers even if the user doesn't explicitly say "open-design-mcp" — keyword matches on `od_*` tool names or "design generation" workflows are enough.
tools
Use this skill whenever a user wants the **full Open Design experience** — discovery questions asked first, brand-spec extraction from URLs/files, TodoWrite planning with live updates, 5-dimensional self-critique, polished artifact at the end. Trigger phrases include "design with questions first", "OD-style workflow", "full interactive design brief", "make me a complete landing page" (when the user wants quality over speed), "design my pitch deck", "brand-aware multi-page site", "follow the Open Design playbook", or any request where the user is starting a new design project rather than tweaking an existing artifact. Also trigger on any request that mentions wanting brand consistency across multiple pages or that provides a brand URL/spec. Pair with the `open-design-mcp` tool-reference skill — both loaded together give an LLM the full picture (this skill = workflow choreography; that skill = tool catalog + errors). This skill explicitly does NOT trigger for one-off tweaks ("make the nav stickier", "swap slide 3 image") — use od_generate_design directly for those.
development
Sync a locally-developed OpenCode skill to the skill-manager npm package and (if private) the private-skills GitHub repo. Handles per-skill version bumps, public/private classification, build verification, and conventional-commit-style git push. Auto-publish to npm is handled downstream by nano-step/shared-workflows@v1 when the push to master lands. Use this skill whenever the user says 'sync skill', 'publish skill', 'push skill to manager', '/sync-skill-to-manager <name>', or asks to release/distribute a skill they just edited.