Security Audit
Run a thorough, whole-project security audit — fingerprint the application type, map every applicable attack surface, credit what's already mitigated with evidence, identify open vulnerabilities, deliver an inline audit report, and (after one confirmation) file each finding as a scoped, pipeline-ready GitHub issue. Use this skill WHENEVER the user asks for a security assessment of a project as a whole: \"security audit\", \"how secure is this app\", \"find vulnerabilities\", \"map the attack surface\", \"pentest prep\", \"is this safe to launch\", \"harden this app\". This is the whole-codebase, point-in-time audit — distinct from code-review (which checks one diff's security as it ships) and dependency-maintenance (which remediates the dependency graph; this audit covers it as one surface). Strictly read-only: it never fixes code and never runs exploits — remediation flows through the filed issues into the normal plan → PR → review pipeline.
Works with: Claude Code (native) · Cursor, Codex CLI (manual)
native: this artifact type is that client's own format
Category: Security — see all ranked ›
Install (Claude Code):
cp -r security-audit ~/.claude/skills/- tashan score: 50.0
- Adoption: 2 repos
- Upkeep: 98.0
- Freshness: 95.0
- Evidence coverage: 84% of the inputs this score can use — the rest are unknown, and the score is discounted for it
- Health: active
- Contributors: 3
Security audit
Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.
source ↗ · skill:eblouin-development/security-audit
Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›
Measured 2026-08-09 · scorer s5 · how · something wrong here?