# OWASP security audit (/security--security-audit)

/security--security-audit is a Claude Code skill in the Code section. Audits your codebase against the OWASP Top 10 and returns each finding with severity, file and line, a description and a fix.

- Web version: https://skills.sgomez.dev/en/s/security--security-audit
- Section: [Code](https://skills.sgomez.dev/en/code.md)
- Author: Santiago Gómez de la Torre
- License: MIT
- Source: https://github.com/sgomez-dev/claude-skills/blob/main/skills/security/security-audit.md
- Updated 26 Mar 2026

## Use it when

- You want a general security review of a project before launch
- You need to know whether there are access control, injection or misconfiguration flaws
- You want to spot dependencies with known CVEs alongside other risks

## Not for

- Replacing a professional audit or an external pentest
- Testing the deployed app: it reviews the repository's code

## What you get

A list of findings, each with severity (critical, high, medium or low), file and line, a description and a fix.

## How to ask for it

- `/security--security-audit run a full security audit on my app`
- `/security--security-audit check my API against the OWASP Top 10`
- `/security--security-audit what common vulnerabilities does this project have?`

## Install

macOS · Linux:

```
curl -fsSL https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.sh | bash
```

Windows:

```
irm https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.ps1 | iex
```

Claude Code plugin:

```
/plugin marketplace add sgomez-dev/claude-skills
/plugin install security-skills@claude-skills-collection
```

## Permissions

- Reads: `**/*`
- Writes: —
- Runs: —
- Network: No
- Destructive: No

## Author's description

Comprehensive security audit scanning for OWASP Top 10 and common vulnerabilities

## Pairs well with

- [Full code review (/code-quality--review)](https://skills.sgomez.dev/en/s/code-quality--review.md): Reviews your changed files or the ones you name, rating issues in correctness, security, performance and maintainability by severity with fix suggestions.
- [Unit tests for your code (/testing--test-gen)](https://skills.sgomez.dev/en/s/testing--test-gen.md): Reads a file and writes unit tests covering normal use, edge cases and errors in your existing framework, then runs them to check they pass.
- [Smart commit message (/git--commit)](https://skills.sgomez.dev/en/s/git--commit.md): Analyzes your staged changes and writes a Conventional Commits message, then creates the commit once you approve it.
- [Complete pull request (/git--pr-create)](https://skills.sgomez.dev/en/s/git--pr-create.md): Builds a pull request from your commits and diff, with a title, summary, test plan and labels, pushes the branch and returns the PR URL.
- [Leaked secrets scan (/security--secrets-scan)](https://skills.sgomez.dev/en/s/security--secrets-scan.md): Scans your code, config files and recent git history for API keys, tokens, passwords and private keys, and explains how to remediate each.
- [Dependency vulnerability check (/security--dependency-vuln)](https://skills.sgomez.dev/en/s/security--dependency-vuln.md): Runs your package manager's audit and lists each vulnerable dependency with its CVE, severity, fixed version and a remediation plan.
- Recipe: [/pipeline--feature-complete](https://github.com/sgomez-dev/claude-skills/blob/main/pipelines/feature-complete.yaml): Feature Complete
- Recipe: [/pipeline--security-hardening](https://github.com/sgomez-dev/claude-skills/blob/main/pipelines/security-hardening.yaml): Security Hardening

## Questions about this skill

### Which OWASP Top 10 categories does it cover?

All ten, from A01 (broken access control) to A10 (SSRF), including injection, cryptographic failures, misconfiguration and logging gaps.

### Does it tell me what to fix first?

Yes: every finding carries a severity (critical, high, medium or low), its file and line, a description and a proposed fix.

### Does it replace a pentest?

No. It is a code review against a list of known risks. To prepare for an external pentest, use /security--pentest-prep.


- [How we review this](https://skills.sgomez.dev/en/methodology.md)
