a11y-audit
Run a Maestro-style accessibility audit for WCAG compliance, ARIA usage, keyboard navigation, and screen reader compatibility
Run a Maestro-style security assessment for authentication, authorization, data exposure, secret handling, and exploitability risks
$ npx -y skills add josstei/maestro-orchestrate --skill security-audit --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/security-auditContext preview
The summary Claude sees to decide when to auto-load this skill.
Run a Maestro-style security assessment for authentication, authorization, data exposure, secret handling, and exploitability risks
name: security-audit description: Run a Maestro-style security assessment for authentication, authorization, data exposure, secret handling, and exploitability risks
Call `get_skill_content` with resources: ["architecture"].
Before delegating, call `get_skill_content` with resources: ["delegation"] and follow the returned methodology.
1. Define the audit scope from the user request and relevant code paths 2. Trace trust boundaries, auth flows, secret handling, and data exposure paths 3. Review for exploitable flaws, unsafe defaults, OWASP Top 10 vulnerabilities, and high-risk dependencies 4. Classify findings by severity (CVSS-aligned) with file references and exploitability assessment 5. Provide remediation guidance with the highest-risk issues first
Maestro is a multi-agent development orchestration platform with 39 specialists, an Express path for simple work, a 4-phase standard workflow for medium and complex work, persistent session state, and standalone
Repo: josstei/maestro-orchestrate
Run a Maestro-style accessibility audit for WCAG compliance, ARIA usage, keyboard navigation, and screen reader compatibility
Archive the active Maestro session while preserving the shared state layout
Standalone code review methodology for structured, severity-classified code assessment
Run a Maestro-style regulatory compliance review for GDPR/CCPA, cookie consent, data handling, and licensing
Agent delegation best practices for constructing effective subagent prompts with proper scoping