security-audit
emaraschio/cursor-commands/.cursor/skill-contracts/security-audit/SKILL.md
Security audit of codebase or change
Skill9 starsChanged 55 days ago
---
name: security-audit
description: Security audit of codebase or change
user-invocable: false
---
## Overview
Comprehensive security review to identify and fix vulnerabilities in the
codebase.
## Steps
1. **Dependency audit**
- Check for known vulnerabilities
- Update outdated packages
- Review third-party dependencies
2. **Code security review**
- Check for common vulnerabilities
- Review authentication/authorization
- Audit data handling practices
3. **Infrastructure security**
- Review environment variables
- Check access controls
- Audit network security
## Security Checklist
- [ ] Dependencies updated and secure
- [ ] No hardcoded secrets
- [ ] Input validation implemented
- [ ] Authentication secure
- [ ] Authorization properly configured
## Guardrails
- Triage dependency CVEs by severity and reachability; never ignore a known CVE.
- Redact live secrets in findings and cite only their location; never paste the value.
- Keep the audit read-first: do not commit, merge, push, or run production scripts without explicit consent.Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
Posts are public.Sign in to post
No one has posted yet. Be the first.

