code-security-audit

Installation
SKILL.md

Code Security Audit Skill

Structured multi-phase security audit for web applications and APIs. The skill discovers the project's stacks and existing tools, augments coverage with Docker-based scanners when needed, and uses the LLM to perform a deep manual review guided by scan findings.

Open-source tools only -- no commercial licenses required.

Before you start

  1. Ask the user whether they want a full audit (all phases) or a scan-only run (Phases 1--4 only, skip Phase 5 manual review).
  2. Agree on scope boundaries upfront: application code, infrastructure config, CI/CD, dependencies, or all.

Phase 1 -- Discovery

Before running any scanners, read the project to understand what stacks are

Related skills

More from sparkfabrik/sf-awesome-copilot

Installs
1
GitHub Stars
1
First Seen
Apr 18, 2026