security-audit
gmanch94/claude-code-aidlc-template/.claude/skills/security-audit/SKILL.md
Deep security audit of the current codebase from a hacker/researcher perspective. Spawns a general-purpose agent with a deterministic prompt that enumerates RLS gaps, IDOR, privilege escalation, input validation bypasses, SSRF, auth bypass, and stack-specific attack surfaces. Returns CRITICAL→LOW findings with file+line citations and remediation hints. Use BEFORE multi-PR sprints touching DB/auth, BEFORE production deploy, and AFTER major feature sweeps. Optionally pass a stack hint as $1 (e.g., "supabase", "firebase", "hasura", "express").
No licence file, so all rights are reserved — read it at the source. Read it on GitHub.
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
No one has posted yet. Be the first.

