Security Audit Sweep
$2.99OfficialUse when auditing a codebase or diff for security defects: map attack surface, hunt OWASP-class bugs, and rate each finding by real exploit path.
securitysecurityowaspcode-reviewvulnerabilityappsecauditยท by SkillingMain
What you get
- โ10-step procedure
- โ1 ready-to-run code block
- โ10-point quality checklist
- โ10 pitfalls to avoid
- โInstalls into 6 tools
- Version
- v1 โ
- Last updated
- today
- Length
- 8 min read
- Requires
- Best with a strong model (Claude Sonnet 4)
Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes ยท Handles multi-file projects
Preview
When to use
Invoke when the task is to find security defects in existing code, not to fix a known bug. Typical triggers:
- Pre-release or pre-merge review of a service, API, or web application.
- A request to find vulnerabilities, check OWASP coverage, or harden a codebase.
- Post-incident work where the goal is to find sibling bugs of a known exploit.
- First contact with an unfamiliar codebase that handles authentication, payments, PII, or file uploads.
Prefer a different skill when the work is dependency CVE triage, leaked-credential cleanup, or design-stage analysis before code exists.
Inputs to gather
Determine these from the repository where possible; ask the user only for w
โฆ
๐ Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.