Skip to main content

security-audit

Authorized, defensive security audit engine. Use whenever the user wants to find security vulnerabilities in a target they own or are authorized to test — a live URL/domain, an API, or a source-code repository/directory. Triggers on: "security scan", "security audit", "find vulnerabilities", "pentest my site", "is my app secure", "check for vulns", "OWASP", "CVE", "dependency audit", "secret scan", "SAST", and Turkish equivalents ("güvenlik taraması", "açık tara", "zafiyet", "güvenli mi", "sızma testi"). Runs a phased methodology (passive recon → attack-surface mapping → known-CVE & dependency research → OWASP web/API tests → source review → infra) using installed tools when available (semgrep, trivy, osv-scanner, gitleaks, testssl.sh) and falling back to LLM analysis otherwise. Produces a prioritized, remediation-focused report. Defaults to safe/passive; active testing requires explicit authorization. Active-only tools (e.g. nuclei, ZAP) are gated behind the authorization prompt, not run by default.

インストールへ移動

ソース情報

リポジトリ
mtvrkan/secaudit
ソースの最終更新活動
2026年8月20日 21:05
検出された SKILL.md の言語
英語
スター
0
フォーク
0

インストール方法

デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。

ソースファイルを確認

インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。