examples/security-auditor/.claude/skills/owasp-top-10/SKILL.md
# OWASP Top 10 Security Audit Checklist Use this checklist when performing security audits. Check each category systematically against the codebase. ## A01:2021 — Broken Access Control - [ ] Missing authorization checks on endpoints - [ ] Insecure direct object references (IDOR) - [ ] Missing function-level access control - [ ] CORS misconfiguration allowing unauthorized origins - [ ] Path traversal via user-controlled file paths - [ ] JWT token manipulation or missing validation ## A02:2021
npx skillsauth add tomascupr/sandstorm examples/security-auditor/.claude/skills/owasp-top-10Install this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this checklist when performing security audits. Check each category systematically against the codebase.
os.system(), subprocess.shell=Truedevelopment
# OWASP Top 10 Review Checklist Use this checklist when auditing application code, configuration, and deployment surfaces. ## Focus areas - Broken access control - Cryptographic failures - Injection - Insecure design - Security misconfiguration - Vulnerable and outdated components - Identification and authentication failures - Software and data integrity failures - Security logging and monitoring failures - Server-side request forgery ## Audit guidance For each relevant category: 1. Identi
documentation
Presentation creation, editing, and analysis. When Claude needs to work with presentations (.pptx files) for: (1) Creating new presentations, (2) Modifying or editing content, (3) Working with layouts, (4) Adding comments or speaker notes, or any other presentation tasks
tools
Comprehensive PDF manipulation toolkit for extracting text and tables, creating new PDFs, merging/splitting documents, and handling forms. When Claude needs to fill in a PDF form or programmatically process, generate, or analyze PDF documents at scale.
development
Comprehensive document creation, editing, and analysis with support for tracked changes, comments, formatting preservation, and text extraction. When Claude needs to work with professional documents (.docx files) for: (1) Creating new documents, (2) Modifying or editing content, (3) Working with tracked changes, (4) Adding comments, or any other document tasks