# Security Audit

> Run a thorough, whole-project security audit — fingerprint the application type, map every applicable attack surface, credit what's already mitigated with evidence, identify open vulnerabilities, deliver an inline audit report, and (after one confirmation) file each finding as a scoped, pipeline-ready GitHub issue. Use this skill WHENEVER the user asks for a security assessment of a project as a whole: \"security audit\", \"how secure is this app\", \"find vulnerabilities\", \"map the attack surface\", \"pentest prep\", \"is this safe to launch\", \"harden this app\". This is the whole-codebase, point-in-time audit — distinct from code-review (which checks one diff's security as it ships) and dependency-maintenance (which remediates the dependency graph; this audit covers it as one surface). Strictly read-only: it never fixes code and never runs exploits — remediation flows through the filed issues into the normal plan → PR → review pipeline.

## Facts
- Page: https://tashan.sh/capability/skill-eblouin-development-security-audit
- tashan id: skill:eblouin-development/security-audit
- Source: https://github.com/eblouin-development/eblouin-plugins
- Type: skill
- Category: security
- tashan score: 50.0 / 100
- Adoption: 14.0
- Upkeep: 98.0
- Freshness: 95.0
- Evidence coverage: 84% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- Official: no

## Install

```sh
cp -r security-audit ~/.claude/skills/
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-08-09 by tashan (https://tashan.sh) from public evidence. Scorer s5.
