Back to skills
SKILL.md
Security Audit
ASecurityEvidence-driven security audit protocol with Hunter/Verifier context isolation, coverage ledger, and sandbox validation gate (cloudflare/security-audit-skill profile).
- 6 stars
- 0 votes
- 0 copies
- 0 views
- Added September 26, 2026
Security analysis
100/100Pro scans all 20 files and shows the line behind each finding
npx -y skills add TQSY114514/Aether --skill security-audit --agent claude-codeAre you the author of Security Audit?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/tqsy114514-security-audit)---
name: security-audit
description: Evidence-driven security audit protocol with Hunter/Verifier context isolation, coverage ledger, and sandbox validation gate (cloudflare/security-audit-skill profile).
permissions: read, write, execute, git
---
# Security Audit Skill (Aether Curated Pack)
## Operating Modes
- **Guidance Mode (Default)**: Produces threat model, capability profile (`READ/WRITE/EXECUTE/NETWORK/GIT/EXTERNAL`), and coverage ledger without unverified vulnerability claims.
- **Full Audit Mode (Explicit)**: Runs isolated **Hunter** (`finder_id`) and **Verifier** (`verifier_id`) passes to produce `findings.json` and `coverage-ledger.json`.
## Hard Protocol Invariants
1. **Finder != Verifier**: Every finding in `findings.json` MUST have `finder_id !== verifier_id`. Verifier operates in an isolated context without Hunter reasoning notes.
2. **Source Trace Required**: `status: "confirmed"` requires a non-empty `source_trace` array (`{ file, line, snippet }`) pointing to existing workspace lines.
3. **No OS Sandbox -> needs_validation**: Dynamic execution findings (`verification_method: "execution"`) MUST be downgraded to `status: "needs_validation"` (`validation_reason: "no_os_sandbox_available"`) when Docker/OS sandbox is unavailable.
4. **Validators**: Validate output via `node scripts/validate-findings.cjs <findings.json>` and `node scripts/validate-coverage-ledger.cjs <coverage-ledger.json>`.
Files in this skill
- SKILL.md
- references/01-capability-axes.md
- references/02-operating-modes.md
- references/03-finder-verifier-isolation.md
- references/04-coverage-ledger-spec.md
- references/05-sandbox-confirmation-gate.md
- references/06-command-injection.md
- references/07-sql-injection.md
- references/08-ssrf-and-network.md
- references/09-path-traversal.md
- references/10-secrets-and-credentials.md
- references/11-deserialization-and-eval.md
- references/12-auth-and-ipc-boundaries.md
- references/13-race-conditions-toctou.md
- references/14-supply-chain-and-deps.md
- references/15-crypto-misuse.md
- references/16-prompt-injection-taint.md
- references/17-remediation-verification.md
- schemas/coverage-ledger.schema.json
- schemas/findings.schema.json
Attribution
Comments
Loading comments…