with one click
security-audit
Security audit: check secrets, XSS, auth, rate limits
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Menu
Security audit: check secrets, XSS, auth, rate limits
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Based on SOC occupation classification
Debug frontend vanilla JS issues - console errors, rendering bugs, SPA navigation, WebSocket
Automates the process of setting up the first admin user or adding new admins via the bootstrap endpoint. Includes a Python script for easy execution.
Push to remote and wait for CI to pass. If CI fails, read logs, fix bugs, and re-push. Repeat until green.
Use when building or debugging LangGraph multi-agent systems - eval-first execution, task decomposition, model routing by complexity, and cost discipline
Use when AI agent modifies API routes or backend logic - catch systematic blind spots where the same model writes and reviews code
Use when making or recording significant architectural decisions - capture context, alternatives, and rationale as structured ADRs
| name | security-audit |
| description | Security audit: check secrets, XSS, auth, rate limits |
rg -i "password|api_key|secret|token|credential" --type py -l
rg "sk-|ghp_|gho_|xoxb-" --type-add 'env:.env*' -l
Verify no secrets in code. Check .gitignore includes .env*.
Search for string concatenation in SQL:
rg "f\".*SELECT|f\".*INSERT|f\".*UPDATE|f\".*DELETE" --type py
All queries should use parameterized (%s) placeholders.
Search for innerHTML with user data:
rg "innerHTML.*\+" web/js/ --type js
User-provided content must go through escapeHtml().
Depends(get_current_user)TEST_MODE guards in dev-only coderg "@limiter.limit" api/routers/ --type py -l
Critical endpoints (login, payment, message send) must be rate-limited.
rg "allow_origins|CORSMiddleware" api_server.py
Production should NOT use * for allowed origins.
pip-audit
pip-audit --desc
rg -i "chmod|777|666" --type py
No overly permissive file operations.