Security Audit

by ruvnet60de638630abNo license74K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today

Security scanning and vulnerability detection. Use when: authentication, authorization, payment processing, user data. Skip when: read-only operations, internal tooling.

Instructions onlySecurity
AI-generated overview

Security scanning and vulnerability detection for authentication, authorization, payment and user-data code.

What it does
This skill defines a security audit workflow for scanning code and detecting vulnerabilities. It triggers on authentication, authorization, payment processing and user data, and is skipped for read-only operations and internal tooling. It lists commands for a full-depth security scan and an input-validation check, plus general coordination and documentation practices.
When to use it
Use it when reviewing code that handles authentication, authorization, payment processing or user data. Skip it for read-only operations and internal tooling.
Requirements
Instructions only; no scripts are shipped. The listed commands invoke the external @claude-flow/cli package through npx, which requires Node.js and network access to fetch the package.

Security Audit Skill

Purpose

Security scanning and vulnerability detection.

When to Trigger

  • authentication
  • authorization
  • payment processing
  • user data

When to Skip

  • read-only operations
  • internal tooling

Commands

Full Security Scan

Run comprehensive security analysis

bash
npx @claude-flow/cli security scan --depth full

Input Validation Check

Check for input validation issues

bash
npx @claude-flow/cli security scan --check input-validation

Best Practices

  1. Check memory for existing patterns before starting
  2. Use hierarchical topology for coordination
  3. Store successful patterns after completion
  4. Document any new learnings

Source and attribution

Source:ruvnet/rufloinv3/@claude-flow/codex/.agents/skills/security-auditat commit60de638

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal