name: qa-security description: Perform a security audit based on OWASP. Use when the user wants to verify security, look for vulnerabilities, or before a production deployment. allowed-tools:
- Read
- Grep
- Glob
- Bash context: fork model: opus argument-hint: "[scope-or-module]"
Security Audit
Objective
Identify security vulnerabilities based on OWASP Top 10.
Instructions
1. Automated scan
# npm dependency audit
npm audit --audit-level=moderate
# Secret search
npx secretlint "**/*"
# Static security analysis
npx eslint --plugin security src/
2. OWASP Top 10 Checklist
A01 - Broken Access Control
- [ ] Authorization checks on every endpoint
- [ ] No IDOR (direct access via predictable IDs)
- [ ] CORS correctly configured
- [ ] Principle of least privilege
A02 - Cryptographic Failures
- [ ] Sensitive data encrypted (at rest + in transit)
- [ ] No secrets in code
- [ ] Secure hash algorithms (bcrypt, argon2)
- [ ] TLS/HTTPS enforced
A03 - Injection
- [ ] SQL: Parameterized queries / ORM
- [ ] XSS: HTML output escaping
- [ ] Command injection: No shell with user input
- [ ] NoSQL: Query validation
A04 - Insecure Design
- [ ] Server-side validation (not just client)
- [ ] Rate limiting on sensitive endpoints
- [ ] Environment separation
A05 - Security Misconfiguration
- [ ] Security headers (CSP, X-Frame-Options)
- [ ] No stack traces in production
- [ ] Correct file permissions
A06 - Vulnerable Components
- [ ]
npm auditwith no critical vulnerabilities - [ ] Dependencies maintained and up to date
A07 - Authentication Failures
- [ ] Passwords hashed correctly
- [ ] Protection against brute force
- [ ] Secure sessions (httpOnly, secure, sameSite)
A08 - Data Integrity Failures
- [ ] Validation of incoming data
- [ ] Secure deserialization
A09 - Logging Failures
- [ ] Logs of security events
- [ ] No sensitive data in logs
A10 - SSRF
- [ ] Validation of user URLs
- [ ] Whitelist of allowed domains
3. Search patterns
# Potential secrets
grep -rn "password\s*=" --include="*.ts"
grep -rn "api_key\s*=" --include="*.ts"
grep -rn "secret\s*=" --include="*.ts"
# Potential SQL Injection
grep -rn "query.*\$\{" --include="*.ts"
grep -rn "execute.*\+" --include="*.ts"
# Potential XSS
grep -rn "innerHTML" --include="*.tsx"
grep -rn "dangerouslySetInnerHTML" --include="*.tsx"
# Dangerous eval
grep -rn "eval(" --include="*.ts"
grep -rn "new Function(" --include="*.ts"
4. Recommended security headers
// Express with Helmet
app.use(helmet({
contentSecurityPolicy: {
directives: {
defaultSrc: ["'self'"],
scriptSrc: ["'self'"],
styleSrc: ["'self'", "'unsafe-inline'"],
imgSrc: ["'self'", "data:", "https:"],
}
},
hsts: { maxAge: 31536000, includeSubDomains: true }
}));
Expected output
## Security Report
### Summary
- **Overall risk level**: [Critical/High/Medium/Low]
- **Vulnerabilities found**: X
- **Vulnerable dependencies**: Y
### Critical vulnerabilities
| Severity | Category | File:Line | Description | Remediation |
|----------|----------|-----------|-------------|-------------|
| CRITICAL | A03 | auth.ts:45 | SQL injection | Parameterized query |
### Important vulnerabilities
[...]
### Priority recommendations
1. [Immediate action]
2. [Short term]
3. [Medium term]
### Dependencies to update
| Package | Version | Vulnerability | Severity |
|---------|---------|---------------|----------|
| lodash | 4.17.19 | Prototype pollution | High |
Rules
- IMPORTANT: Check all 10 OWASP categories
- IMPORTANT: Prioritize by severity
- YOU MUST propose concrete remediations
- NEVER ignore critical vulnerabilities
Think hard about every potential attack vector.
See also
Two community sources complement this skill:
agamm/claude-code-owasp(171★, last commit 2026-04-28) — covers OWASP Top 10:2025, ASVS 5.0, and 20 language-specific quirks. Independent author. Adoption is modest at the time of this audit; the value is in pointing to a faithful implementation of the canonical OWASP standard rather than in popularity.semgrepofficial Claude plugin — Semgrep is an independent security company; their plugin integrates the static-analysis engine into Claude Code sessions for automated scanning.
When working on a security audit, install one or both alongside this skill. This skill captures the manual review workflow (when to invoke, what to escalate, blocking criteria); the OWASP skill captures the canonical attack catalogue with current 2025-2026 categories; the Semgrep plugin adds the automated scanner layer.
Install command and full list of validated vendor skills: docs/recipes/recommended-vendor-skills.md. Audit pilot trace: specs/marketplace-audit/qa-skills-pilot-2026-05-06.md.
Auditeur de Securite
Securite
Analyse le code pour detecter les vulnerabilites OWASP Top 10.
Checklist de Sécurité OWASP
Securite
Génère des checklists de sécurité applicative basées sur l'OWASP Top 10.
Modélisation de Menaces
Securite
Génère des documents de modélisation de menaces avec analyse STRIDE.