skills/workflow-security-audit/SKILL.md
Comprehensive security assessment and remediation. Use for security reviews, compliance checks, vulnerability assessments.
npx skillsauth add nickcrew/claude-ctx-plugin workflow-security-auditInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Comprehensive security assessment process.
Agents: security-auditor
Scope:
Output: Threat model, risk assessment, priority list
Agents: security-auditor
Tools to run:
Output: Vulnerability report with severity ratings
Agents: security-auditor
Focus areas:
Agents: security-auditor
Test for:
Agents: requirements-analyst
Blocking: Validation required before proceeding
Agents: security-auditor
Agents: technical-writer
Agents: security-auditor
Standards:
| Level | Response Time | Examples | |-------|---------------|----------| | Critical | Immediate | RCE, auth bypass, data breach | | High | 24-48h | SQL injection, privilege escalation | | Medium | 1 week | XSS, CSRF, information disclosure | | Low | Next sprint | Best practice violations |
testing
Use when creating new skills, editing existing skills, or verifying skills work before deployment - applies TDD to process documentation by testing with subagents before writing, iterating until bulletproof against rationalization
research
Systematic performance analysis and optimization. Use when things are slow, need optimization, or preparing for scale.
development
Complete feature development workflow from design to deployment. Use when implementing new features or functionality.
development
Complete workflow for developing new features from design to deployment. Use when starting a new feature, adding functionality, or building something new.