Built here
OWASP security audit
/security--security-audit
/security--security-audit is a Claude Code skill in the Code section. Audits your codebase against the OWASP Top 10 and returns each finding with severity, file and line, a description and a fix.
Author's description
Comprehensive security audit scanning for OWASP Top 10 and common vulnerabilities
Use it when
- You want a general security review of a project before launch
- You need to know whether there are access control, injection or misconfiguration flaws
- You want to spot dependencies with known CVEs alongside other risks
Not for
- Replacing a professional audit or an external pentest
- Testing the deployed app: it reviews the repository's code
What you get
A list of findings, each with severity (critical, high, medium or low), file and line, a description and a fix.
How to ask for it
/security--security-audit run a full security audit on my app/security--security-audit check my API against the OWASP Top 10/security--security-audit what common vulnerabilities does this project have?
Install
curl -fsSL https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.sh | bashAfter installing with the script, type /security--security-audit. Using Cursor, Windsurf or Codex? Platform guides
Questions about this skill
- Which OWASP Top 10 categories does it cover?
- All ten, from A01 (broken access control) to A10 (SSRF), including injection, cryptographic failures, misconfiguration and logging gaps.
- Does it tell me what to fix first?
- Yes: every finding carries a severity (critical, high, medium or low), its file and line, a description and a proposed fix.
- Does it replace a pentest?
- No. It is a code review against a list of known risks. To prepare for an external pentest, use /security--pentest-prep.
Demo coming soon
Pairs well with
- Recipe: /pipeline--feature-complete Feature Complete
- Recipe: /pipeline--security-hardening Security Hardening