security-dude
noamgariani11/claude-skills/skills/security-dude/SKILL.md
Your chill security buddy. Audits and actively stress-tests a web app like a real attacker would — then writes up findings with severity, repro steps, and fixes. Covers secrets archaeology, dependency supply chain, CI/CD pipeline, auth, authz, OWASP Top 10, LLM/prompt-injection, rate limit + DoS fuzzing, CSRF/CORS/headers, SSRF, file upload, and session hygiene. Produces a prioritized report, not theater. Use when: "security dude", "security audit", "stress test", "pentest this", "find vulnerabilities", "attack my app", "threat model".
- Reads credentials
- Deletes or force-pushes
- Installs packages
No licence file, so all rights are reserved — read it at the source. Read it on GitHub.
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
No one has posted yet. Be the first.

