security-audit

Originally from89jobrien/steve
Installation
SKILL.md

Security Audit

Find vulnerabilities that violate a real trust boundary, then give owners the source evidence, safe reproduction, priority, and smallest effective fix. This is a defensive, source-first workflow. A candidate without a concrete affected principal, resource, or security outcome is not a confirmed finding.

Operating modes

This skill is guidance by default. Loading it does not authorize the complete audit workflow or file creation.

  • Guidance mode: For security questions, focused reviews, methodology, triage, or investigation of specific findings, use only the relevant parts of this skill. Do not automatically run all six phases, create an output directory, or write audit artifacts. You may launch focused agents when useful; they return results to the current task.
  • Full audit mode: Use the complete workflow when the user explicitly asks to audit or pen-test a codebase, asks for a full, comprehensive, or end-to-end security review, or requests report artifacts. Run all six phases and write the files defined below.

If the request could mean either mode, ask one focused question before creating files or starting the complete workflow.

Platform terminology

This skill is agent-neutral:

Installs
17.9K
GitHub Stars
21.8K
First Seen
Jun 18, 2026
security-audit — cloudflare/security-audit-skill