Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
89jobrien avatar

Security Audit

  • 44 installs
  • 4 repo stars
  • Updated April 11, 2026
  • 89jobrien/steve

security-audit is a Claude Code skill for security code review and vulnerability assessment using OWASP Top 10, CVSS scoring, CWE mapping, and remediation roadmaps.

About

security-audit is a Claude Code skill for security code review and vulnerability assessment. It runs OWASP Top 10 assessments, scores findings with CVSS, maps them to CWE classifications, audits dependencies, and produces a remediation roadmap. A developer uses it for security reviews before release, compliance audits, or penetration-test preparation.

  • OWASP Top 10 (2021) assessment with CVSS scoring and CWE references
  • Ships an audit-report template and an OWASP checklist reference
  • Covers dependency vulnerability audit and remediation roadmaps

Security Audit by the numbers

  • 44 all-time installs (skills.sh)
  • Ranked #1,378 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 28, 2026 (Skillselion catalog sync)
At a glance

security-audit capabilities & compatibility

Capabilities
security audit · owasp assessment · vulnerability scanning · dependency audit
Use cases
security audit · code review
Pricing
Free
From the docs

What security-audit says it does

Comprehensive security auditing covering code review, vulnerability assessment, OWASP Top 10, dependency analysis, and remediation planning.
SKILL.md
Quick reference for OWASP Top 10 (2021) vulnerability categories.
references/owasp-checklist.md
npx skills add https://github.com/89jobrien/steve --skill security-audit

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs44
repo stars4
Last updatedApril 11, 2026
Repository89jobrien/steve

What it does

Run an OWASP-based security audit of a codebase and produce a severity-ranked findings report.

Who is it for?

Security reviews before release, compliance audits, penetration-test prep, and dependency vulnerability assessment.

Skip if: Designing new security architecture or implementing controls (see security-engineering for that).

When should I use this skill?

Conducting security reviews, analyzing code for vulnerabilities, or performing OWASP assessments.

What you get

Findings are documented by severity with CVSS scores, CWE classification, proof of concept, and a remediation roadmap.

  • security audit report
  • severity-ranked findings
  • remediation roadmap

By the numbers

  • OWASP Top 10 (2021) categories
  • 10+ common CWE references
  • 2 reference files (OWASP checklist + audit template)

Files

SKILL.mdMarkdownGitHub ↗

Security Audit Skill

Comprehensive security auditing covering code review, vulnerability assessment, OWASP Top 10, dependency analysis, and remediation planning.

What This Skill Does

  • Conducts security code reviews
  • Identifies vulnerabilities (CVSS scoring)
  • Performs OWASP Top 10 assessments
  • Audits authentication/authorization
  • Reviews data protection controls
  • Analyzes dependency vulnerabilities
  • Creates remediation roadmaps

When to Use

  • Security reviews before release
  • Compliance audits
  • Penetration test preparation
  • Incident response analysis
  • Dependency vulnerability assessment

Reference Files

  • references/SECURITY_AUDIT.template.md - Comprehensive security audit report format
  • references/owasp_checklist.md - OWASP Top 10 checklist with CVSS scoring and CWE references

Workflow

1. Define scope and methodology 2. Perform static/dynamic analysis 3. Document findings by severity 4. Map to OWASP categories 5. Create remediation roadmap 6. Verify fixes

Output Format

Security findings should include:

  • Severity (Critical/High/Medium/Low)
  • CVSS score and vector
  • CWE classification
  • Proof of concept
  • Remediation steps

Related skills

FAQ

What framework does it use?

OWASP Top 10 (2021), with CVSS scoring and CWE classification for each finding.

When should I use it?

For security reviews before release, compliance audits, penetration-test preparation, or dependency vulnerability assessment.

Securityauditappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.