Comprehensive security auditing skill leveraging the security-auditor persona. Use for vulnerability scanning, OWASP compliance checks, and security reviews.
Scanned 9/8/2026
Install to Claude Code
npx -y skills add agisota/old-one --skill octopus-security-audit --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Octopus Security Audit?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/agisota-octopus-security-audit)More formats (shields.io, HTML) on the badges page.
---
name: octopus-security-audit
description: |
Comprehensive security auditing skill leveraging the security-auditor persona.
Use for vulnerability scanning, OWASP compliance checks, and security reviews.
---
# Security Audit Skill
Invokes the security-auditor persona for thorough security analysis during the `ink` (deliver) phase.
## Usage
```bash
# Via orchestrate.sh
./scripts/orchestrate.sh spawn security-auditor "Scan for SQL injection vulnerabilities"
# Via auto-routing (detects security intent)
./scripts/orchestrate.sh auto "security audit the payment processing module"
```
## Capabilities
- OWASP Top 10 vulnerability detection
- SQL injection and XSS scanning
- Authentication/authorization review
- Secrets and credential detection
- Dependency vulnerability assessment
- Security configuration review
## Persona Reference
This skill wraps the `security-auditor` persona defined in:
- `agents/personas/security-auditor.md`
- CLI: `codex-review`
- Model: `gpt-5.2-codex`
- Phases: `ink`
- Expertise: `owasp`, `vulnerability-scanning`, `security-review`
## Example Prompts
```
"Scan for hardcoded credentials in the codebase"
"Check for CSRF vulnerabilities in form handlers"
"Review the API authentication implementation"
"Analyze the encryption at rest configuration"
```
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.
Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.
Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.