Skip to main content

security-audit

Authorized, defensive security audit engine. Use whenever the user wants to find security vulnerabilities in a target they own or are authorized to test — a live URL/domain, an API, or a source-code repository/directory. Triggers on: "security scan", "security audit", "find vulnerabilities", "pentest my site", "is my app secure", "check for vulns", "OWASP", "CVE", "dependency audit", "secret scan", "SAST", and Turkish equivalents ("güvenlik taraması", "açık tara", "zafiyet", "güvenli mi", "sızma testi"). Runs a phased methodology (passive recon → attack-surface mapping → known-CVE & dependency research → OWASP web/API tests → source review → infra) using installed tools when available (semgrep, trivy, osv-scanner, gitleaks, testssl.sh) and falling back to LLM analysis otherwise. Produces a prioritized, remediation-focused report. Defaults to safe/passive; active testing requires explicit authorization. Active-only tools (e.g. nuclei, ZAP) are gated behind the authorization prompt, not run by default.

Ir a la instalación

Datos de origen

Repositorio
mtvrkan/secaudit
Última actividad en el origen
20 de agosto de 2026 a las 21:05
Idioma detectado de SKILL.md
inglés
Estrellas
0
Forks
0

Opciones de instalación

De forma predeterminada está seleccionado el prompt que primero revisa el origen. Puedes cambiar a un comando directo o descargar una copia local.

Revisa los archivos de origen

Lee SKILL.md y los archivos complementarios que muestra SkillsMP antes de decidir si quieres instalarlo.