Skip to content
Back to skills

Security Audit

ASecurity

Evidence-driven security audit protocol with Hunter/Verifier context isolation, coverage ledger, and sandbox validation gate (cloudflare/security-audit-skill profile).

  • 6 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 26, 2026
ai-agentsnodedockergitsecurity

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 26, 2026

npx -y skills add TQSY114514/Aether --skill security-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Audit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/tqsy114514-security-audit/badge)](https://www.skillsdirectory.com/skills/tqsy114514-security-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: security-audit
description: Evidence-driven security audit protocol with Hunter/Verifier context isolation, coverage ledger, and sandbox validation gate (cloudflare/security-audit-skill profile).
permissions: read, write, execute, git
---

# Security Audit Skill (Aether Curated Pack)

## Operating Modes
- **Guidance Mode (Default)**: Produces threat model, capability profile (`READ/WRITE/EXECUTE/NETWORK/GIT/EXTERNAL`), and coverage ledger without unverified vulnerability claims.
- **Full Audit Mode (Explicit)**: Runs isolated **Hunter** (`finder_id`) and **Verifier** (`verifier_id`) passes to produce `findings.json` and `coverage-ledger.json`.

## Hard Protocol Invariants
1. **Finder != Verifier**: Every finding in `findings.json` MUST have `finder_id !== verifier_id`. Verifier operates in an isolated context without Hunter reasoning notes.
2. **Source Trace Required**: `status: "confirmed"` requires a non-empty `source_trace` array (`{ file, line, snippet }`) pointing to existing workspace lines.
3. **No OS Sandbox -> needs_validation**: Dynamic execution findings (`verification_method: "execution"`) MUST be downgraded to `status: "needs_validation"` (`validation_reason: "no_os_sandbox_available"`) when Docker/OS sandbox is unavailable.
4. **Validators**: Validate output via `node scripts/validate-findings.cjs <findings.json>` and `node scripts/validate-coverage-ledger.cjs <coverage-ledger.json>`.

Files in this skill

  • SKILL.md1.4 KB
  • references/01-capability-axes.md147 B
  • references/02-operating-modes.md139 B
  • references/03-finder-verifier-isolation.md125 B
  • references/04-coverage-ledger-spec.md113 B
  • references/05-sandbox-confirmation-gate.md123 B
  • references/06-command-injection.md127 B
  • references/07-sql-injection.md112 B
  • references/08-ssrf-and-network.md115 B
  • references/09-path-traversal.md121 B
  • references/10-secrets-and-credentials.md106 B
  • references/11-deserialization-and-eval.md122 B
  • references/12-auth-and-ipc-boundaries.md118 B
  • references/13-race-conditions-toctou.md101 B
  • references/14-supply-chain-and-deps.md116 B
  • references/15-crypto-misuse.md103 B
  • references/16-prompt-injection-taint.md109 B
  • references/17-remediation-verification.md99 B
  • schemas/coverage-ledger.schema.json273 B
  • schemas/findings.schema.json234 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…