Skip to content
Built here

OWASP security audit

/security--security-audit

/security--security-audit is a Claude Code skill in the Code section. Audits your codebase against the OWASP Top 10 and returns each finding with severity, file and line, a description and a fix.

Author's description

Comprehensive security audit scanning for OWASP Top 10 and common vulnerabilities

Use it when

  • You want a general security review of a project before launch
  • You need to know whether there are access control, injection or misconfiguration flaws
  • You want to spot dependencies with known CVEs alongside other risks

Not for

  • Replacing a professional audit or an external pentest
  • Testing the deployed app: it reviews the repository's code

What you get

A list of findings, each with severity (critical, high, medium or low), file and line, a description and a fix.

How to ask for it

  • /security--security-audit run a full security audit on my app
  • /security--security-audit check my API against the OWASP Top 10
  • /security--security-audit what common vulnerabilities does this project have?

Install

curl -fsSL https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.sh | bash

After installing with the script, type /security--security-audit. Using Cursor, Windsurf or Codex? Platform guides

Questions about this skill

Which OWASP Top 10 categories does it cover?
All ten, from A01 (broken access control) to A10 (SSRF), including injection, cryptographic failures, misconfiguration and logging gaps.
Does it tell me what to fix first?
Yes: every finding carries a severity (critical, high, medium or low), its file and line, a description and a proposed fix.
Does it replace a pentest?
No. It is a code review against a list of known risks. To prepare for an external pentest, use /security--pentest-prep.

Demo coming soon

Pairs well with

↑↓ move · Enter open · Esc close