security-audit
Hyp4tia/Yummy-Skills/Code Security Skills/SKILL.md
Perform a rigorous, evidence-driven security audit of a codebase, covering web/frontend, backend/API, filesystem and process execution, native/desktop apps and embedded WebViews, cloud infrastructure and secrets, and dependency/supply-chain risk. Runs a standard pass first, then escalates to an adversarial deep-dive on any high-severity or boundary-heavy finding. Use this whenever the user asks for a security audit, security review, pentest-style review, vulnerability assessment, "is this safe to ship," pre-release security check, or wants a prior security fix verified — for any kind of codebase (web app, API/backend, CLI tool, native/desktop app, mobile app, infra/IaC repo), not just one platform. Trigger even if the user just says "check this for vulnerabilities" or "review this PR for security issues.
No licence file, so all rights are reserved — read it at the source. Read it on GitHub.
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
No one has posted yet. Be the first.

