// "Performs comprehensive security and code quality audits. Use when asked to 'audit the codebase', 'check for vulnerabilities', or 'run security scan'."
| name | audit-agent |
| description | Performs comprehensive security and code quality audits. Use when asked to 'audit the codebase', 'check for vulnerabilities', or 'run security scan'. |
| version | 1.0.0 |
| tags | ["security","audit","quality","scanning"] |
This skill performs comprehensive security and code quality audits across your codebase.
This skill is automatically invoked when you ask:
package.json, requirements.txt, go.modUser Request:
"Run a security audit on the backend API"
Skill Actions:
backend/ directory for security issuesrequirements.txtOutput Format:
# Security Audit Report
## Summary
- ๐ด Critical: 2
- ๐ High: 5
- ๐ก Medium: 8
- ๐ข Low: 12
## Critical Findings
### 1. Hardcoded API Key Detected
**File:** `backend/app/config.py:23`
**Issue:** API key hardcoded in source code
**Risk:** Credential exposure if code is leaked
**Fix:** Move to environment variable or Secret Manager
### 2. SQL Injection Vulnerability
**File:** `backend/app/api/users.py:45`
**Issue:** Unsanitized user input in SQL query
**Risk:** Database compromise
**Fix:** Use parameterized queries
No configuration required. The skill automatically:
security-analyst - Deep security architecture reviewproject-health-checker - Overall project health validationdependency-updater - Automated dependency updates