本文へ移動
cccskills
無料GitHub で公開

auditing-security

Perform a systematic security audit of a codebase, checking for OWASP Top 10 vulnerabilities, secrets exposure, and insecure patterns.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md2.6 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Security Audit

Use this skill when the user asks to audit security, check for vulnerabilities, review code for security issues, or harden an application.

Steps

  1. Scan for hardcoded secrets — search for API keys, tokens, passwords, and connection strings in source files. Check for patterns like:

    • password=, secret=, token=, api_key=
    • Base64-encoded credentials
    • AWS keys (AKIA...), Stripe keys (sk_live_...), GitHub tokens (ghp_...)
    • Files: .env committed to git, config.json with credentials
  2. Check authentication & authorization

    • Verify all API routes check authentication before processing.
    • Ensure role-based access control is enforced server-side, not just in the UI.
    • Check that password hashing uses bcrypt/argon2 (not MD5/SHA1).
    • Verify session tokens are HTTP-only, secure, and have reasonable expiry.
  3. Check for injection vulnerabilities

    • SQL injection: look for string concatenation in SQL queries instead of parameterized queries.
    • XSS: look for dangerouslySetInnerHTML, innerHTML, or unescaped user input rendered in templates.
    • Command injection: look for exec(), eval(), child_process.exec() with user input.
    • Path traversal: check file operations for unsanitized user input in paths.
  4. Review dependency security

    • Run npm audit or pip audit to check for known vulnerabilities.
    • Flag outdated dependencies with known CVEs.
    • Check for overly permissive dependency ranges.
  5. Check CORS and CSP configuration

    • Verify CORS doesn't use Access-Control-Allow-Origin: * in production.
    • Check for Content Security Policy headers.
    • Verify X-Frame-Options, X-Content-Type-Options, and Strict-Transport-Security headers.
  6. Review data exposure

    • Check API responses for leaking sensitive fields (password hashes, internal IDs, PII).
    • Verify error messages don't expose stack traces or internal details in production.
    • Check logging for sensitive data being written to logs.
  7. Generate report — produce a summary with severity ratings (Critical / High / Medium / Low) for each finding, with the file path, line number, and recommended fix.

Notes

  • This is a code review, not a penetration test. Recommend tools like npm audit, trivy, or snyk for automated scanning.
  • Always check .gitignore to ensure .env, credentials, and key files are excluded.
  • For comprehensive auditing, recommend the OWASP Testing Guide.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Use Cursor's browser aria snapshots to audit a page for accessibility issues — missing labels, broken tab order, contrast, and ARIA misuse.

日本語の概要は準備中です。原文の説明を表示しています。

0xAidan/polymarket-bot-test42026年9月4日 更新

Add PostHog analytics to a web application, including event tracking, page views, feature flags, and session replay.

日本語の概要は準備中です。原文の説明を表示しています。

0xAidan/polymarket-bot-test42026年9月4日 更新

Generate OpenAPI/Swagger documentation for an API, including endpoint schemas, request/response types, and interactive docs UI.

日本語の概要は準備中です。原文の説明を表示しています。

0xAidan/polymarket-bot-test42026年9月4日 更新

Add authentication to a web application using NextAuth.js (Auth.js), including OAuth providers, session management, and protected routes.

日本語の概要は準備中です。原文の説明を表示しています。

0xAidan/polymarket-bot-test42026年9月4日 更新

Dockerize an application with a production-ready Dockerfile, docker-compose setup, and .dockerignore.

日本語の概要は準備中です。原文の説明を表示しています。

0xAidan/polymarket-bot-test42026年9月4日 更新

Set up Playwright end-to-end testing in a project, including test configuration, example tests, and CI integration.

日本語の概要は準備中です。原文の説明を表示しています。

0xAidan/polymarket-bot-test42026年9月4日 更新

0xAidan のスキルをすべて見る

このスキルの問題を報告する