security-audit

$npx mdskill add Fr-e-d/GAAI-framework/security-audit

Detect and report security vulnerabilities in codebases and configurations

  • Identifies common security issues such as injection flaws, broken authentication, and XSS attacks.
  • Uses integration with external vulnerability scanning tools to analyze code and configuration files.
  • Evaluates compliance against predefined security rules and standards for accurate reporting.
  • Generates a detailed report of vulnerabilities ranked by severity along with actionable remediation steps.

SKILL.md

.github/skills/security-auditView on GitHub ↗
---
name: security-audit
description: Detect security vulnerabilities and governance violations across delivered code, configurations, and deployed environments. Activate after implementation or periodically as a governance check.
license: ELv2
compatibility: Works with any filesystem-based AI coding agent
metadata:
  author: gaai-framework
  version: "1.0"
  category: cross
  track: cross-cutting
  id: SKILL-SECURITY-AUDIT-001
  updated_at: 2026-02-26
  status: experimental
inputs:
  - codebase
  - configuration_files
  - deployed_environment_metadata  (optional)
  - contexts/rules/**  (security rules)
outputs:
  - vulnerability_report
  - severity_scores
  - compliance_status
  - remediation_actions
---

# Security Audit

## Purpose / When to Activate

Activate:
- After implementation as a security gate
- Periodically on active projects
- When security rules are added or updated

Enforces security as a system rule, not a human task.

---

## Process

1. Scan code and configs for common vulnerability patterns
2. Detect secrets exposure and unsafe patterns
3. Validate authentication and authorization flows
4. Check compliance against project security rules
5. Produce severity-ranked vulnerability report with concrete remediation steps

---

## Outputs

- Vulnerability list with severity (critical / high / medium / low)
- Compliance pass/fail report per security rule
- Concrete remediation steps per vulnerability
- Audit trail for governance

---

## Quality Checks

- All findings include severity and remediation steps
- Compliance status is explicit per rule
- No false positives reported without evidence
- Output is actionable, not just informational

---

## Non-Goals

This skill must NOT:
- Fix vulnerabilities (use `remediate-failures` for that)
- Make architectural decisions
- Replace dedicated security tooling

**Prevents high-impact production failures. Security as governance, not afterthought.**

More from Fr-e-d/GAAI-framework

SkillDescription
abort-safe-handlerOrchestrator-level Stage 4 entry gate for /gaai:bootstrap. Presents a pre-loop "Skip Q&A entirely" option, delegates to qa-loop-ui when the user proceeds, and returns a unified abort_safe_result with telemetry on every path. Guarantees no partial state on skip or abort.
ambiguity-detectorTakes surface scan results, optional LLM synthesis open-question entries, and optional tree-sitter AST signals to score project ambiguities (1-10). Outputs structured ambiguity_feed for smart-question-generator. Pure heuristic — no LLM calls. Designed for Stage 3.5 of the /gaai:bootstrap pipeline (between LLM synthesis and Q&A).
approach-evaluationResearch industry standards and best practices, identify viable approaches for a given technical or architectural problem, and produce a structured factual comparison against project-specific constraints. Reports options — does not decide.
architecture-extractConvert raw project structure into clear architectural understanding — module boundaries, data flows, service relationships, and architectural patterns. Activate after codebase-scan during Bootstrap.
bootstrap-llm-synthesisConstruct the LLM synthesis prompt from project surface scan + optional tree-sitter context + optional Q&A answers. Call the LLM. Parse and validate the response into 6-8 structured memory entries with clarity tags and source traceability. Used as Stage 3 of the /gaai:bootstrap pipeline.
bootstrap-memory-ingest-cloudWrite structured memory entries to the Cloud workspace via gaai_memory.store MCP tool with source='bootstrap'. Loops over entries from bootstrap-llm-synthesis, calls the tool per entry, collects success/fail counts. Used as Stage 5 of the /gaai:bootstrap pipeline (Cloud path only).
browser-journey-testValidate user stories by simulating real user journeys in a live browser against deployed application. Activate after implementation to verify actual user experience against acceptance criteria, not just code logic.
build-agents-indexScan all agent and sub-agent definition files in .gaai/core/agents/, extract YAML frontmatter, merge with specialists.registry.yaml, and generate a derived agents-index.yaml at .gaai/core/agents/agents-index.yaml. Activate after adding, modifying, or removing any agent, sub-agent, or specialist entry.
build-skills-indexScan SKILL.md files in .gaai/core/skills/ and .gaai/project/skills/, extract YAML frontmatter, and regenerate separate skills indices for each layer. Core index ships with the OSS framework; project index is project-specific.
ci-watch-and-fixWatch GitHub Actions CI after PR creation, detect failures, extract logs, apply minimal fixes, and re-push — keeping the delivery session alive until CI resolves or escalating after 3 cycles. Activate immediately after gh pr create and before marking the story done.