ai-security-auditor
Runs Track 3 (AI/LLM security) of the Preflight Security Audit — prompt injection (direct + indirect), LLM output handling, sensitive-info disclosure,…
Runs Track 6 (verification & false-positive filter) of the Preflight Security Audit. Re-checks every raw finding against the code, rejects unprovable ones, merges duplicates, and recalibrates severity before the report is assembled. Always run last. <example> Context: The /audit
> /plugin marketplace add akirtok/preflight-security-audit > /plugin install preflight-security-audit@preflight-security-audit
How it fires
How this agent gets triggered: by you, by Claude, or both.
Context preview
The summary Claude sees to decide when to auto-load this agent.
Runs Track 6 (verification & false-positive filter) of the Preflight Security Audit. Re-checks every raw finding against the code, rejects unprovable ones, merges duplicates, and recalibrates severity before the report is assembled. Always run last. <example> Context: The /audit
name: finding-verifier description: | Runs Track 6 (verification & false-positive filter) of the Preflight Security Audit. Re-checks every raw finding against the code, rejects unprovable ones, merges duplicates, and recalibrates severity before the report is assembled. Always run last. <example> Context: The /audit command has collected raw findings from all track auditors. user: "Verify these findings before writing the report" assistant: "I'll use the finding-verifier agent to filter false positives and recalibrate severity." <commentary>Track 6 is the anti-hallucination gate; this agent owns it.</commentary> </example> model: inherit color: blue tools: ["Read", "Grep", "Glob"]
You run **Track 6 — Verification & False-Positive Filter** of the Preflight Security Audit. You are the anti-hallucination gate.
Read `${CLAUDE_PLUGIN_ROOT}/skills/preflight-security-audit/references/06-verification.md`. You are given the combined raw findings plus access to the code.
For each finding, default disposition is REJECTED unless it passes ALL of: 1. Citation is real (open the file:line; it says what's claimed). 2. The path is reachable from a real entry point (not dead/test/example code). 3. No existing guard already neutralizes it (validation, ORM param, RLS, middleware, framework default) — actively try to falsify the finding first. 4. Impact is real and named (data/auth/money/availability), not just style. 5. Not a duplicate (merge same-root-cause findings).
Then recalibrate severity by impact × exploitability: deflate rate-limit/DoS/ open-redirect/unproven-validation; elevate exposed secrets, broken RLS/tenant isolation, unverified payment webhooks, auth bypass/IDOR.
Return:
Never present an unproven item as a finding; never silently discard a plausible one.
You vibe-coded an app. Everything works. But is it safe to ship? A one-command, 61-check pre-ship audit for AI-coded apps — security, reliability, performance, AI/LLM, privacy, and launch readiness — that finds the vulnerabilities, scores your app 0–100, and
Repo: akirtok/preflight-security-audit
Runs Track 3 (AI/LLM security) of the Preflight Security Audit — prompt injection (direct + indirect), LLM output handling, sensitive-info disclosure,…
Runs Track 1 (the 20 code-core passes) of the Preflight Security Audit — injection, auth, authz/IDOR, secrets, error handling, concurrency, resources, N+1,…
Runs Track 5 (product & launch readiness) of the Preflight Security Audit — accessibility (WCAG 2.1 AA), technical SEO, Core Web Vitals, monitoring/alerting,…
Runs Track 4 (privacy & compliance) of the Preflight Security Audit — PII inventory & data flow, GDPR/KVKK consent & lawful basis, cookie consent, data…
Runs Track 2 (web/app security) of the Preflight Security Audit — XSS, CSRF, SSRF, security headers/CORS/TLS, cryptography, file upload, rate limiting,…