Skip to main content

security-audit

Use when conducting security assessments — OWASP Top 10 / API / LLM, CWE Top 25, CVSS scoring — auditing PHP/TYPO3, APIs, frontend, Terraform/K8s/Docker IaC, AWS cloud, AI agent configs, or scanning dependencies.

معلومات المصدر

المستودع
dirnbauer/webconsulting-skills
آخر نشاط في المصدر
٢٧ يوليو ٢٠٢٦ في ٠٦:٠٤
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٣٣
التفرعات
٦

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.

مستكشف الملفات
88 ملفات

عرض SKILL.md

SKILL.md
تعليمات المصدر · معاينة للقراءة فقط
name
security-audit
description
Use when conducting security assessments — OWASP Top 10 / API / LLM, CWE Top 25, CVSS scoring — auditing PHP/TYPO3, APIs, frontend, Terraform/K8s/Docker IaC, AWS cloud, AI agent configs, or scanning dependencies.
# Security Audit Skill Security audit patterns (OWASP Top 10, LLM Top 10 2025, CWE Top 25 2025, CVSS v4.0), cloud/IaC, GitHub security. 80+ PHP/TYPO3 checkpoints (v14.3 LTS in `typo3-security.md`). ## Expertise Areas - **Vulnerabilities**: XXE, SQLi, XSS, CSRF, command injection, path traversal, file upload, deserialization, SSRF, SSTI, JWT, type juggling - **Standards**: OWASP Top 10 / API / LLM (2025), CWE Top 25, CVSS v3.1/v4.0, OWASP ASVS - **Cloud & IaC**: AWS; Terraform, Kubernetes, Docker, Helm - **API & Frontend**: REST/GraphQL authZ, rate limits, mass assignment, CSP, DOM-XSS - **AI Agents**: SKILL.md/AGENTS.md/CLAUDE.md/mcp.json/hooks.json audit; prompt injection; excessive agency ## Reference Files (in `references/`, `.md` implied) - **Core**: owasp-top10, cwe-top25, xxe-prevention, cvss-scoring, api-key-encryption - **Prevention**: deserialization-prevention, path-traversal-prevention, file-upload-security, input-validation, error-message-sanitization - **Architecture**: authentication-patterns, security-headers, security-logging, cryptography-guide, security-invariants - **Language features** (`*-security-features`): php, python, javascript-typescript, nodejs, go - **Frameworks** (`*-security`): typo3, typo3-fluid, typo3-typoscript, symfony, react, vue - **Cloud & IaC**: aws-security, iac-security - **API & Frontend**: api-security, frontend-security - **AI Agent**: llm-security (OWASP LLM Top 10 2025) - **Threats**: modern-attacks, cve-patterns - **DevSecOps**: ci-security-pipeline, supply-chain-security, automated-scanning, gha-security, git-history-secrets - **Incident**: supply-chain-incident-response ## Security Checklist - [ ] `semgrep`/`opengrep`, `trivy fs --severity HIGH,CRITICAL`, `gitleaks` clean - [ ] bcrypt/Argon2 passwords, CSRF on state changes, TLS 1.2+ - [ ] Server-side input validation; parameterized SQL; XML entities off - [ ] Output encoding + CSP; no unserialize() on user input - [ ] API keys encrypted; exception messages sanitized - [ ] Secrets out of VCS; audit logging on - [ ] Uploads validated, renamed, outside web root - [ ] Headers HSTS + X-Content-Type-Options; dependencies scanned ## GitHub Actions Security - **NEVER** interpolate `${{ inputs.* }}` / `${{ github.event.* }}` in `run:` — use `env:` - Dependency triage: upgrade > override > dismiss. Full patterns: `references/gha-security.md`. ## Verification ```bash ./scripts/security-audit-dispatcher.sh /path/to/project # auto-detect stack ./scripts/security-audit.sh /path/to/project # PHP-only ./scripts/github-security-audit.sh owner/repo # GH repo ``` Dispatcher detects the stack from indicator files and runs matching `scripts/scanners/*.sh` (13 ecosystems; see `references/` index). --- > Contributing: https://github.com/netresearch/security-audit-skill --- ## Credits & Attribution This skill is based on the excellent work by **[Netresearch DTT GmbH](https://www.netresearch.de/)**. Original repository: https://github.com/netresearch/security-audit-skill **Copyright (c) Netresearch DTT GmbH** — Methodology and best practices (MIT / CC-BY-SA-4.0) Special thanks to [Netresearch DTT GmbH](https://www.netresearch.de/) for their generous open-source contributions to the TYPO3 community, which helped shape this skill collection. Adapted by webconsulting.at for this skill collection
عرض على GitHub