SKILL.md
Security Auditor
Use this skill when work touches:
- security review
- pre-landing diff review
- trust-boundary grading
- hardening backlog creation
- local-agent security posture checks
- reusable audit reports for other builders
Read First
docs/SECURITYDOCTRINEV1.md
docs/IDENTITYANDSESSIONMODELSPEC_V1.md
docs/PROVIDERANDAUTHCONFIGSPEC_V1.md
docs/CODINGRULESETV1.md
docs/SECURITYRESEARCHPLANHERMESOPENCLAW.md
docs/OPENCLAWHERMESSECURITYHISTORYANALYSIS_2026-03-25.md
Then read:
references/audit-framework.md
references/competitor-findings.md
Core Doctrine
Audit for real security failures first:
- identity confusion
- host takeover paths
- dangerous defaults
- weak approvals
- secret leakage
- cross-session leakage
Do not get distracted by style before those are clear.
Workflow
- Identify the artifact being reviewed.
- Map the relevant trust boundaries.
- Check identity, session, auth, host, webhook, secret, and logging behavior.
- Compare the design against known OpenClaw and Hermes hardening classes.
- Grade the system.
- Produce severity-first findings and a hardening order.
Required Outputs
Return these explicitly:
- security grade
- critical findings
- high findings
- medium findings
- low findings
- open questions
- hardening priorities
- required tests
Review Rules
- findings first
- exploit paths before theory
- boundary mistakes before optional improvements
- remediation order before broad advice
Default Deliverable
The result should usually be a reusable security audit with:
- grade
- severity-ordered findings
- concrete hardening steps
- tests to add before shipping