/security-audit
Use when reviewing code security, auditing dependencies for CVEs, checking configuration or secret security, assessing authentication and authorization patterns, identifying OWASP vulnerabilities (injection, XSS, CSRF), or addressing security concerns about implementations.
$ npx -y skills add nicepkg/auto-company --skill security-audit --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/security-audit
Context preview
The summary Claude sees to decide when to auto-load this skill.
Use when reviewing code security, auditing dependencies for CVEs, checking configuration or secret security, assessing authentication and authorization patterns, identifying OWASP vulnerabilities (injection, XSS, CSRF), or addressing security concerns about implementations.
SKILL.md
security-audit.SKILL.mdname: security-audit
agents: [yokay-security-scanner]
description: Use when reviewing code security, auditing dependencies for CVEs, checking configuration or secret security, assessing authentication and authorization patterns, identifying OWASP vulnerabilities (injection, XSS, CSRF), or addressing security concerns about implementations.
Security Audit
Systematic security review for application code, dependencies, and configuration.
**Not a replacement for professional penetration testing.** Identifies common vulnerabilities within scope of code review.
Audit Types
| Type | Focus | When to Use | |------|-------|-------------| | Code Review | OWASP Top 10, injection, auth | New features, PRs, suspicious code | | Dependency | CVEs, outdated packages | Before deploy, periodic, CI/CD | | Configuration | Secrets, permissions, hardening | Infrastructure changes, new envs | | Architecture | Attack surface, data flow | Design phase, major refactors | | API Security | Auth, authz, rate limiting | New endpoints, public APIs |
When NOT to Use
- **Designing new auth flows** — Use `api-design` for designing OAuth2/JWT endpoints from scratch
- **Performance issues** — Use `performance-optimization` even if caused by auth overhead
- **CI/CD pipeline security** — Use `ci-cd` for pipeline hardening (secret management, permissions)
Key Principles
- **Scope first** — Define audit area, depth, and constraints before scanning
- **Classify severity** — Critical (24-48h), High (1 week), Medium (2-4 weeks), Low (backlog)
- **Remediate or track** — Fix critical issues immediately, create ohno tasks for the rest
- **No secrets in code** — Scan for hardcoded credentials, API keys, connection strings
Quick Start Checklist
1. Define audit scope and type (code, dependency, config, architecture, API) 2. Run automated scans (npm audit, grep patterns, secret detection) 3. Review findings and classify severity using decision tree in references 4. Remediate critical/high findings immediately 5. Create ohno tasks for medium/low findings with appropriate priority 6. Document findings in audit report
References
| Reference | Description | |-----------|-------------| | [owasp-top-10.md](references/owasp-top-10.md) | OWASP vulnerabilities with detection and fixes | | [dependency-security.md](references/dependency-security.md) | npm audit, pip-audit, Snyk, CI/CD integration | | [auth-patterns.md](references/auth-patterns.md) | Secure authentication and authorization patterns | | [api-security.md](references/api-security.md) | API-specific security concerns | | [secrets-management.md](references/secrets-management.md) | Handling sensitive configuration |
Read more
name: security-audit agents: [yokay-security-scanner] description: Use when reviewing code security, auditing dependencies for CVEs, checking configuration or secret security, assessing authentication and authorization patterns, identifying OWASP vulnerabilities (injection, XSS, CSRF), or addressing security concerns about implementations.
Security Audit
Systematic security review for application code, dependencies, and configuration.
**Not a replacement for professional penetration testing.** Identifies common vulnerabilities within scope of code review.
Audit Types
| Type | Focus | When to Use | |------|-------|-------------| | Code Review | OWASP Top 10, injection, auth | New features, PRs, suspicious code | | Dependency | CVEs, outdated packages | Before deploy, periodic, CI/CD | | Configuration | Secrets, permissions, hardening | Infrastructure changes, new envs | | Architecture | Attack surface, data flow | Design phase, major refactors | | API Security | Auth, authz, rate limiting | New endpoints, public APIs |
When NOT to Use
- **Designing new auth flows** — Use `api-design` for designing OAuth2/JWT endpoints from scratch
- **Performance issues** — Use `performance-optimization` even if caused by auth overhead
- **CI/CD pipeline security** — Use `ci-cd` for pipeline hardening (secret management, permissions)
Key Principles
- **Scope first** — Define audit area, depth, and constraints before scanning
- **Classify severity** — Critical (24-48h), High (1 week), Medium (2-4 weeks), Low (backlog)
- **Remediate or track** — Fix critical issues immediately, create ohno tasks for the rest
- **No secrets in code** — Scan for hardcoded credentials, API keys, connection strings
Quick Start Checklist
1. Define audit scope and type (code, dependency, config, architecture, API) 2. Run automated scans (npm audit, grep patterns, secret detection) 3. Review findings and classify severity using decision tree in references 4. Remediate critical/high findings immediately 5. Create ohno tasks for medium/low findings with appropriate priority 6. Document findings in audit report
References
| Reference | Description | |-----------|-------------| | [owasp-top-10.md](references/owasp-top-10.md) | OWASP vulnerabilities with detection and fixes | | [dependency-security.md](references/dependency-security.md) | npm audit, pip-audit, Snyk, CI/CD integration | | [auth-patterns.md](references/auth-patterns.md) | Secure authentication and authorization patterns | | [api-security.md](references/api-security.md) | API-specific security concerns | | [secrets-management.md](references/secrets-management.md) | Handling sensitive configuration |
全自主 AI 公司,24/7 不停歇运行 14 个 AI Agent,每个都是该领域世界顶级专家的思维分身。 自主构思产品、做决策、写代码、部署上线、搞营销。没有人类参与。 基于 Claude Code Agent Teams 驱动。 ⚠️ 实验项目 — 还在测试中,能跑但不一定稳定。目前仅支持 macOS。
Other skills on auto-company.
- /agent-browser
Browser automation CLI for AI agents. Use when the user needs to interact with websites, including navigating pages, filling forms, clicking buttons, taking screenshots, extracting data, testing web apps, or automating any browser task. Triggers include requests to "open a
Open skill - /code-review-security
Security-focused code review checklist and automated scanning patterns. Use when reviewing pull requests for security issues, auditing authentication/authorization code, checking for OWASP Top 10 vulnerabilities, or validating input sanitization. Covers SQL injection prevention,
Open skill - /cold-email-sequence-generator
Generate personalized cold email sequences (7-14 emails) with A/B test subject lines, follow-up timing recommendations, and integrated social proof. Creates multi-touch campaigns optimized for response rates. Use when users need outbound email campaigns, sales sequences, or lead
Open skill - /community-led-growth
Expert in community-led growth (CLG) - leveraging user communities to drive acquisition, retention, and expansion. Covers building developer communities, user groups, ambassador programs, and turning customers into advocates. Knows the difference between community as a feature
Open skill - /competitive-intelligence-analyst
Use this skill when users need to analyze competitors, monitor market movements, benchmark features/pricing, identify market gaps, or understand competitive positioning. Activates for "what are competitors doing," market analysis, or differentiation strategy.
Open skill - /content-strategy
When the user wants to plan a content strategy, decide what content to create, or figure out what topics to cover. Also use when the user mentions "content strategy," "what should I write about," "content ideas," "blog strategy," "topic clusters," or "content planning." For
Open skill

