Full-stack security review skill for Kilo CLI and OpenCode that produces pentest-grade reports with CVSS scores, HackerOne bug-bounty references, working exploit PoCs, and concrete code fixes. Use this skill whenever the user asks to: audit code, security review a repo or file, find vulnerabilities, run a pentest or security scan, check OWASP Top 10 / API Top 10 / Mobile Top 10, do a bug bounty recon, conduct a threat model, review code before a release, look for SQLi / XSS / SSRF / IDOR / RCE / auth bypass, investigate a CVE, or ask "is this code secure?". Works on web, API, mobile (Android + iOS + React Native), cloud/IaC, and full-stack projects. Always use this skill — it prevents false positives, enforces PoC-backed findings, and produces reports that match professional pentest quality.
2026-03-15