Security Audit
Adversarial, authorized red-team / penetration-testing loop for a PHP backend you own — fans out one security-auditor subagent per OWASP/vuln family in parallel, each attacking the RUNNING service (black-box HTTP/GraphQL probing) AND inspecting source (SAST/taint, dependency, secret, config), verifies every candidate by reproducing it against the running service (no false positives), maps it to CWE + OWASP id + CVSS-ish severity, then drives root-cause, suppression-free fixes through php-implementer with a regression test per fix and re-dispatches only still-open families until a clean pass. …
Works with: Claude Code (native) · Cursor, Codex CLI (manual)
native: this artifact type is that client's own format
Category: Security — see all ranked ›
Install (Claude Code):
cp -r security-audit ~/.claude/skills/- tashan score: 50.0
- Adoption: 3 repos
- Upkeep: 95.0
- Freshness: 90.0
- Evidence coverage: 84% of the inputs this score can use — the rest are unknown, and the score is discounted for it
- Health: active
- Contributors: 3
Security audit
Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.
Its own instructions
Its SKILL.md says when to use it, shows worked examples and covers setup.
Read from the capability’s own SKILL.md. This is not a grade and does not compare to the instruction-depth verdict on an MCP server — a skill has no tools to document, so that rubric does not apply to it.
You searched for one. Check the rest of your stack:
npx tashan-cli doctorReads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.
Security Audit scores 50 today. Pro keeps the series, so you can see whether that is a project getting better or one on its way down.
- Every score since we started measuring, for any capability
- The named replacement when something you run is dying — not just that it is
tashan doctorover the config you already have, on your machine
Start a 7-day trial › Everything measured on this page stays free.
source ↗ · skill:VilnaCRM-Org/security-audit
Everything on this page is public evidence and free. What it cannot know is whether you run this — check your whole config, free, in the browser. tashan Pro adds the series behind each row and names a replacement for anything dying.
Already running this? Check your whole config — free, in your browser, nothing installed. Or npx tashan-cli doctor locally, which sends nothing at all.
Measured 2026-08-20 · scorer s5 · how · something wrong here?