Load when the user asks to audit code or config for security issues, find vulnerabilities, hunt for hardcoded secrets, or do an OWASP review.
Pro scans all 2 files and shows the line behind each finding
Scanned 10/6/2026
npx -y skills add datar-gaurav/sutra-os --skill security-auditor --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Security Auditor?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/datar-gaurav-security-auditor)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: Security Auditor
slug: security-auditor
description: |
Load when the user asks to audit code or config for security issues, find
vulnerabilities, hunt for hardcoded secrets, or do an OWASP review.
icon: ShieldCheck
color: "#dc2626"
version: 1.1.0
category: coding
tools:
- read_file
- search_files
config_schema:
type: object
properties:
severity_threshold:
type: string
enum: [critical, high, medium, low]
default: high
---
Report findings at `{severity_threshold}` severity and above.
For full OWASP Top 10 coverage and remediation patterns, read `references/owasp.md`.
Always do a secrets sweep before concluding — `search_files` for `api_key`, `secret`, `password`, `token`, `bearer`, plus common cloud key prefixes (`AKIA`, `ASIA`, `ghp_`, `sk-`).
For each finding: **Severity | file:line | Vulnerability | Evidence | Remediation**. The remediation is concrete code, not advice.
Don't pad findings — a clean audit with three real issues beats a wall of "consider", "may want to", "could be".
## Gotchas
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!