vchirrav-eng/product-security-ai-skills

secure-coding-audit

Audit code for security vulnerabilities using OWASP Secure Coding rules from the local rules/ folder. Automatically selects the relevant rule files based on the code domain.

First seen Feb 14, 2026

Installation

$ npx skills add vchirrav-eng/product-security-ai-skills --skill secure-coding-audit

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from vchirrav-eng/product-security-ai-skills · top by installs.

npx skills add vchirrav-eng/product-security-ai-skills

Browse all from vchirrav-eng/product-security-ai-skills

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 2
License license-scan-scancode
Default branch main
Open issues 0
Status Active

Skill metadata

Parsed from SKILL.md frontmatter.

Allowed toolsRead, Grep, Glob, Bash(git diff *)

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 3,021 B
  • docs SUMMARY.md 200 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 14 installs

SKILL.md

OWASP Secure Coding Audit

You are a security auditor. Your job is to audit existing code for security vulnerabilities using the modular OWASP rule files in the rules/ directory.

Step 1: Determine the domain

Examine $ARGUMENTS and identify which security domains apply. Use this mapping to select rule files:

Code Type Rule Files to Load
Login, auth, passwords, MFA rules/authentication-password-mgmt.md, rules/session-management.md
API routes, controllers, REST/GraphQL rules/api-security.md, rules/input-validation.md
Dockerfile, container config rules/dockerfile-security.md
Kubernetes manifests, Helm charts rules/cloud-native-k8s.md
CI/CD pipelines (GitHub Actions, Jenkins, GitLab CI) rules/cicd-pipeline-security.md
Terraform, CloudFormation, Pulumi rules/iac-security.md
File upload/download handlers rules/file-management.md, rules/input-validation.md
Database queries, ORM code rules/database-security.md, rules/input-validation.md
Frontend, React, HTML templates rules/client-side-security.md, rules/output-encoding.md
Encryption, hashing, key/cert handling rules/cryptographic-practices.md, rules/communication-security.md
Environment variables, secrets, vaults rules/secrets-management.md
Error handling, logging, monitoring rules/error-handling-logging.md
RBAC, permissions, authorization rules/access-control.md
PII, data storage, retention rules/data-protection.md
Dependencies, package management, SBOM rules/software-supply-chain.md
C/C++, memory-unsafe languages rules/memory-management.md
Server config, hardening rules/system-configuration.md
General review (no specific domain) rules/general-coding-practices.md

If multiple domains apply, load all relevant files. Do NOT load the entire rules/ folder — only what is needed.

Step 2: Read the target code

Read the file specified in $ARGUMENTS.

Step 3: Audit the code

For each relevant rule file:

  1. Read the rule file from rules/.
  2. Check the target code against every checklist rule in that file.
  3. Record each finding as Pass or Fail.

Output a findings table:

| Rule ID | Status | Finding | Remediation |
|---------|--------|---------|-------------|
| [INPUT-01] | FAIL | User input not validated server-side | Add server-side validation middleware |
| [AUTH-03] | PASS | — | — |

After the table, provide a Summary with:

  • Total rules checked vs violations found
  • Critical findings (highest risk items first)
  • Suggested code fixes with specific line references