ai-assist-security-audit
16-dimension security posture assessment with adaptive activation, health scoring, and remediation plan. Covers application security, infrastructure, auth, crypto, privacy, supply chain, and more. Use when assessing security posture, auditing code for vulnerabilities, reviewing c
Asset-Profil
Recherche und Wissensarbeit
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Szenario
Recherche-Agents
I need my agent to research a topic, compare sources, and produce a concise report.
Agent-Fit
Claude Code + CLI + Codex
Geeignet für Codex, Claude Code, Cursor, CLI oder benutzerdefinierte Agents.
Installieren
Bereit
npx skills add jparkerweb/ai-assist-skills --skill ai-assist-security-audit
Wartung
Aktuell
2 Tage seit dem letzten Push
Risiko
Prüfung nötig
Lizenz ist unklar
GitHub-Qualität
88
61/100 Qualität · 64/100 Vertrauen
Abdeckungs-Tags
Review-Notizen
Lizenz ist unklar · Dependency or permission surface needs review
Agent-Adoptionskarte
Vertrauen, Audit und Installationsbereitschaft auf einen Blick
Diese Werte kombinieren öffentliche Repository-Metadaten, OpenAgentSkill-Reviewsignale, Wartungsaktualität und Installationsbereitschaft. Sie helfen bei der Vorauswahl, ersetzen aber keine menschliche Prüfung.
Qualität
VielversprechendUseful candidate, but compare it with alternatives before adopting.
Vertrauen
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Audit
Prüfung nötigMaschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.
OpenAgentSkill Trust Score v5
Menschliche Prüfung vor Installation
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
88 GitHub-Stars
Repository-Aktivität
88 Stars und 12 Forks
Wartung
2 Tage seit dem letzten Push
Lizenz
Unbekannt
Installieren
npx skills add jparkerweb/ai-assist-skills --skill ai-assist-security-audit
Installationssicherheit
Standard-Paket- oder Laufzeit-Installationspfad
Berechtigungsfläche
shell or command execution, filesystem or document access
Agent-Ergebnisse
Noch keine Agent-Ergebnisdaten
Dokumentation
Usable metadata, review docs
Risikoübersicht
Vor Produktion prüfen
- Repository license is unknown; consider adding an explicit open-source license to the repository to clarify usage rights.
- Financial research output is not financial advice; require human review before any live investment decision.
- Lizenz ist unklar
- Quality score needs review
Installationsbereitschaft
Installationspfad verfügbar
- Installationspfad ist verfügbar
- Repository-Belege sind verfügbar
- Lizenz ist unklar
- Noch keine Agent-Proven-Ergebnisbelege
Agent-lesbare Metadaten
Maschinenlesbare Entscheidungsdaten für diesen Skill.
Nutze diesen Block oder das eingebettete JSON, um zu entscheiden, ob ein Agent diesen Skill installieren, eine Alternative wählen oder zuerst menschliche Prüfung anfordern soll.
Geeignete Aufgaben
- Research-Agent-Workflows
- Claude-Code-Teams
- builders willing to evaluate younger projects
- Suchquellen
Geeignete Agents
Installationsentscheidung
- Befehl
- npx skills add jparkerweb/ai-assist-skills --skill ai-assist-security-audit
- Richtlinie
- Blockieren
- Menschliche Prüfung
- Ja
Vertrauen und Risiko
- Vertrauen
- 56/100
- Audit
- 71/100
- Risikoebene
- Prüfung nötig
Ergebnis-Loop
- Endpoint
- /api/agent/outcome
- Event-ID
- resolve
- Ergebnisse
- 5
Installationsbefehl
npx skills add jparkerweb/ai-assist-skills --skill ai-assist-security-auditNicht verwenden, wenn
- Teams, die ein vom Anbieter unterstütztes SLA benötigen
- production agents without a repository review
- Repository license is unknown; consider adding an explicit open-source license to the repository to clarify usage rights.
- Hinweise auf Hochrisiko-Berechtigungen: Shell or command execution, Secrets or environment access
- Lizenz ist unklar
Agent-Sicherheit v2
27/100 · Automatische Installation vermeiden
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
Hoch
Shell- oder Befehlsausführung
Die Skill-Metadaten verweisen auf Terminal-, CLI-, Shell-, Subprozess- oder Befehlsausführungs-Workflows.
Mittel
Netzwerkzugriff
Die Skill ruft wahrscheinlich Remote-Seiten, APIs, Repositories oder externe Dienste ab.
Mittel
Dateisystemzugriff
Die Skill kann Projektdateien, Dokumente, generierte Artefakte oder den lokalen Arbeitsbereich lesen oder schreiben.
Hoch
Secrets or environment access
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
- Hinweise auf Hochrisiko-Berechtigungen: Shell or command execution, Secrets or environment access
- Lizenz ist unklar
Installationsziele
Diesen Skill im Agent-Workflow installieren
Über den öffentlichen Endpunkt erhältst du Befehl, Sicherheitscheckliste, Ziel-Prompts und kanonische Links.
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install jparkerweb-ai-assist-security-auditAgent-Auflösungsplan
Lass einen Agent die Eignung vor der Installation prüfen.
Die Resolve API liefert die beste Skill, Alternativen, Sicherheitsrichtlinien, Auditnotizen, Installationsziel und einen direkt nutzbaren Prompt.
JSON öffnen
/api/agent/resolve?task=Use%20ai-assist-security-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve-Text
/api/agent/resolve?task=Use%20ai-assist-security-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Installationsübergabe
/api/skills/jparkerweb-ai-assist-security-audit/install
Agent sollte prüfen
- Task fit and alternatives from Resolve API.
- Audit score, trust score, and safety policy warnings.
- Install target compatibility for Codex, Claude Code, Cursor, or CLI.
Prompt kopieren
Task: Use ai-assist-security-audit in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20ai-assist-security-audit%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/jparkerweb-ai-assist-security-audit/install
Install command: npx skills add jparkerweb/ai-assist-skills --skill ai-assist-security-audit
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent-Übergabe
Gib dem Agent den Installationspfad, nicht noch ein Verzeichnis.
Über den öffentlichen Endpunkt erhältst du Befehl, Sicherheitscheckliste, Ziel-Prompts und kanonische Links.
Installationsübergabe
/api/skills/jparkerweb-ai-assist-security-audit/install
LLM-Textformat
/api/skills/jparkerweb-ai-assist-security-audit/install?format=text
Alternativen finden
/api/skills/search?q=ai-assist-security-audit&limit=3
Agent-Prompt
Use ai-assist-security-audit for this task. Review https://www.openagentskill.com/api/skills/jparkerweb-ai-assist-security-audit/install, then install with: npx skills add jparkerweb/ai-assist-skills --skill ai-assist-security-auditRegistry-Metadaten
Agent-lesbares Profil für die automatische Skill-Auswahl.
Die Registry API stellt Entscheidungs-, Vertrauens-, Audit-, Use-Case- und Installationssignale ohne UI-Scraping bereit.
Manifest
/api/registry/manifest/jparkerweb-ai-assist-security-audit
LLM-Text
/api/registry/manifest/jparkerweb-ai-assist-security-audit?format=text
Installationsalias
/api/registry/install/jparkerweb-ai-assist-security-audit
Empfehlen
/api/registry/recommend?task=Use%20ai-assist-security-audit%20in%20an%20agent%20workflow&limit=3
Agent-Fit
Recherche-Agents
Use-Case-Tags
Plattformen
Claude Code
Audit-Bericht
Prüfung nötig · 71/100
Maschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.
Agent-Entscheidungspanel
Fallback candidate for Research agents
Prototype with this skill first; keep a fallback candidate ready.
Rolle im Stack
Fallback-Kandidat
Primäre Eignung
Recherche-Agents
Vertrauenslabel
Zuerst prototypisieren
Installationspfad
Befehl bereit
Verwenden wenn
- Research-Agent-Workflows
- Claude-Code-Teams
- builders willing to evaluate younger projects
Evidenz
- recent repository activity
- install command or GitHub repo available
- Qualitätsprofil 61/100
- 7 OpenAgentSkill-Interaktionen
zuerst prüfen
- Repository license is unknown; consider adding an explicit open-source license to the repository to clarify usage rights.
Implementierungspfad
- 1Installieren Sie es in einem Sandbox-Agent und führen Sie eine Recherche-Agents-Aufgabe vollständig aus.
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
Vertrauensprofil
Do not auto-install
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub-Akzeptanz
Prüfen88 GitHub-Stars
Star-/Fork-Aktivität
Prüfen88 Stars und 12 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbar
Aktuelle Wartung
Bestanden2 Tage seit dem letzten Push
Lizenzklarheit
PrüfenUnbekannt
Positive Signale
- KI-Prüfung genehmigt
- Installationspfad ist verfügbar
- Repository-Belege sind verfügbar
- Kürzlich gewartetes Repository
- Der Installationsbefehl weist kein offensichtliches Hochrisikomuster auf
- Ergebniszyklus ist bereit, benötigt aber den ersten echten Agent-Lauf
Vor Installation prüfen
- Repository license is unknown; consider adding an explicit open-source license to the repository to clarify usage rights.
- Financial research output is not financial advice; require human review before any live investment decision.
- Lizenz ist unklar
- Quality score needs review
- Permission surface needs review: shell or command execution, filesystem or document access
- GitHub adoption: 88 GitHub stars
- Stars/forks activity: 88 stars, 12 forks; issue activity unavailable in current metadata
- License clarity: Unknown
- Dependency/runtime risk: command execution surface, network or browser surface
- Permission surface: shell or command execution, filesystem or document access
- Noch keine echten Agent-Ergebnisberichte
- Vor unbeaufsichtigter Installation ist menschliche Prüfung erforderlich
Empfohlene Aktion
Choose a stronger alternative or inspect the source manually before any install attempt.
Qualitätsprofil
Vielversprechend Kandidat für Agent-Workflows
Useful candidate, but compare it with alternatives before adopting.
Workflow-Eignung
Diese Skill in diesen Szenarien nutzen
Investigate faster
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Search private knowledge
RAG and knowledge
I need my agent to build a RAG workflow over documents and retrieve reliable context.
Manage repositories
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Workflow-Eignung
Zum vollständigen Workflow hinzufügen
Find, compare, and synthesize
Research report agent
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Ingest, retrieve, and cite
RAG knowledge base
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Alternativen-Shortlist
Vor Installation vergleichen
Similar skills that may fit this task.
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
Übersicht
--- name: ai-assist-security-audit description: "16-dimension security posture assessment with adaptive activation, health scoring, and remediation plan. Covers application security, infrastructure, auth, crypto, privacy, supply chain, and more. Use when assessing security posture, auditing code for vulnerabilities, reviewing compliance, or preparing for security reviews." argument-hint: "[focus areas] [scope]" ---
# SECURITY AUDIT
**Objective:** Produce a severity-ranked, CWE-referenced security posture assessment with health score and actionable remediation plan. **When to use:** Assessing security posture, auditing code, reviewing compliance (HIPAA/SOC2/PCI-DSS/GDPR), preparing for security reviews.
Start all responses with '🔐 [Security Audit Step X: Name]'
## Role
Senior security engineer conducting a full-spectrum posture assessment. Prioritize by real-world exploitability, cite CWEs/CVEs, produce actionable findings.
## Context
**AGENTS.md check:** If `./AGENTS.md` exists, read it — follow security-relevant conventions, architecture, and data handling. If missing, warn and proceed with standard practices.
**Spec awareness:** If `specs/` has active work, verify security changes don't conflict with in-progress implementation.
**Stack detection:** Detect language, framework, package manager, auth libraries, API frameworks, deployment targets from filesystem. Research current CVEs and best practices for the detected stack.
**Input:** `$ARGUMENTS` — optional focus areas and scope. Default: full audit, all activated dimensions.
## Rules
1. **Always-current standards.** Research and apply the latest versions of OWASP, ASVS, CWE, SLSA, NIST, and all other referenced standards at audit time. Never assume a specific version is current. Use the full standard, not just "Top 10" or "Top 25" subsets. 2. **Run audit tools first.** `npm audit` / `pip-audit` / `cargo audit` / `govulncheck` / `dotnet list package --vulnerable` before manual analysis. 3. **Map attack surface first.** Inputs, outputs, auth boundaries, data flows, integrations. 4. **Severity by exploitability.** Vector reachable? Blast radius? Known exploit/PoC? 5. **Every finding needs evidence.** File:line, CVE/CWE, or tool output. 6. **Remediation must be specific.** Exact code change, library upgrade, or config setting. 7. **All 16 dimensions are the checklist.** Audit every activated dimension. N/A = documented with rationale. 8. **Secrets detection thorough.** Grep for hardcoded keys, tokens, passwords, cloud-specific patterns. 9. **Chat-only output.** All findings in chat. Never create files without explicit user permission.
## Process
### Step 1: Context & Attack Surface
1. Read AGENTS.md, run `git status`, detect stack 2. Run audit tools (npm/pip/cargo audit) 3. Research current CVEs for detected framework versions 4. Read `references/dimensions.md` for scope detection rules and the STRIDE threat model 5. Map attack surface using STRIDE: entry points, auth boundaries, data flows, config files 6. Parse arguments for focus areas and determine scope (focused/branch/full)
> 🔐 [Security Audit Step 1: Context & Attack Surface] Stack: [tech]. Surface: [X] entry points, [Y] auth boundaries. Scope: [scope]. Activating dimensions.
### Step 2: Activate & Audit Dimensions
Read `references/dimensions.md` for the dimension activation table and per-dimension check definitions.
1. Activate dimensions based on detected project type 2. Audit each activated dimension in priority order (highest risk first): Secrets, Deps, Auth, AppSec, API, Infra, Crypto, BizLogic, Privacy, Network, CI/CD, ClientSide, DoS, Logging, Database, ThirdParty 3. If AI/LLM components detected: also audit against the AI/LLM security checks in dimensions.md
> 🔐 [Security Audit] Activated [X]/16 dimensions. Auditing dimension [N]: [Name]...
### Step 3: Findings Report & Score
Read `references/scoring.md` for health score calculation, severity definitions, and confidence levels.
Read `references/output-template.md` for finding format, summary table, positive observations, improvement plan, fix options, and session-end format.
1. Calculate health score using group weights and N/A redistribution 2. Rank findings by severity (Critical → Warning → Suggestion) 3. Present: stack summary, dimension findings with evidence, summary table, positive observations, health score, improvement plan, fix options
### Self-Verification Checklist
> Canonical version in `references/output-template.md`. Brief version here for quick reference.
- [ ] All activated dimensions audited; N/A dimensions documented - [ ] Audit tools run (or documented why not) - [ ] Every finding has file:line + CWE - [ ] Severity reflects exploitability, not theoretical worst case - [ ] Remediation verified against current framework docs - [ ] No false positives from aspirational standards
### Session End
``` 🔐 [Security Audit Complete]
**Score:** [XX]/100. [X] critical, [Y] warnings, [Z] suggestions across [N] dimensions. ```
**Next steps (ask user — do not auto-execute):** - Save report to `specs/audit-reports/security-<date>.md`? - Fix findings? (use fix options from report) - Related: `/ai-assist-observability-audit`, `/ai-assist-tech-debt`, `/ai-assist-test-audit`
## Recovery
| Issue | Solution | |-------|----------| | No package manifest | Audit code-level security; note deps not assessed | | Audit tool unavailable | Manual CVE search; note limitation | | Monorepo | Audit each workspace; aggregate in summary | | No auth system | Note absence — appropriate for CLI, finding for web service | | N/A dimensions | Document rationale; redistribute health score weights |
## Important Reminders
**Response format:** Every response starts with `🔐 [Security Audit Step X: Name]`
**Hard rules:** Always-current standards — research latest versions at runtime. Run audit tools first. Evidence for every finding. All 16 dimensions are the checklist.
**Process rules:** Attack surface first with STRIDE. Dimension activation is mandatory. Remediation must be specific — exact code changes, not general advice.
**Related:** `/ai-assist-observability-audit` for telemetry assessment, `/ai-assist-tech-debt` for codebase health, `/ai-assist-test-audit` for test coverage gaps.
Technische Details
- Version
- 1.0.0
- Lizenz
- Unknown
- Letzte Aktualisierung
- 21. Aug. 2026
- Veröffentlicht
- 21. Aug. 2026
Entscheidungsübersicht
Fallback-Kandidat
recent repository activity
Audit
Installationsprüfung
Installations- und Adoptionsprüfung
- Sicherheit
- 66/100
- Wartung
- 100/100
- Installieren
- 92/100
Von Agent belegte Evidenz
Von Agent belegte Evidenz
Ergebnisberichte nach Resolve, Prüfung, Installation und einem begrenzten Lauf.
- Erfolgsrate
- —
- Letzter Fehler
- —
- Ergebnisse
- 0
- Ausgabequalität
- —
- Fehlgeschlagen
- 0
- Nicht relevant
- 0
- Installationen
- 0
- Durch Risiko blockiert
- 0
- Einrichtung erforderlich
- 0
- Produktion
- 0
Noch keine Agent-Ergebnisdaten. Der erste Lauf kann Erfolg, Einrichtungsbedarf, Risikoblockaden, Fehler oder Irrelevanz über /api/agent/outcome melden.
Installieren
Zum Agent-Workflow hinzufügen
Kostenlos und Open Source. Bericht vor der Installation in Produktions-Agents prüfen.
Wachstums-Loop
Share-Kit
Szenariobasierter Entwurf für ai-assist-security-audit, bereit für einen manuellen X-Post.
ai-assist-security-audit: 16-dimension security posture assessment with adaptive activation, health scoring, and remedi... 88 stars https://www.openagentskill.com/skills/jparkerweb-ai-assist-security-audit?ref=x
Optionale Antwort mit Installationsbefehl
Listing + install path for ai-assist-security-audit: https://www.openagentskill.com/skills/jparkerweb-ai-assist-security-audit?ref=x Install: npx skills add jparkerweb/ai-assist-skills --skill ai-assist-security-audit
Quelle des Eintrags
Registry-indexiert
Dieser Eintrag wurde aus öffentlichen Quellen indexiert und ist erst nach Genehmigung eines Maintainer-Anspruchs offiziell.
- Ersteller
- jparkerweb
- Indexiert von
- OpenAgentSkill Community-Index
Die Zuordnung verlinkt auf das öffentliche Repository oder Creator-Profil. Creator können den Eintrag beanspruchen, um Eigentümersignale zu aktualisieren.
Diesen Skill beanspruchenEigentümeranspruch
Diesen Skill-Eintrag beanspruchen
Dieser Registry-indexiert-Eintrag wird jparkerweb zugeschrieben, ist aber noch nicht offiziell markiert. Beanspruche ihn, um ein verifiziertes Eigentümersignal hinzuzufügen und künftige Launch-, Installations- und Audit-Updates vertrauenswürdiger zu machen.
Creator-Backlink-Kit
Evidenz-Badges in deine README einfügen
Zeige den kanonischen Eintrag, aktuelle Vertrauens- und Audit-Signale sowie echte Agent-Proven-Evidenz dort, wo Entwickler das Repository bewerten.
[](https://www.openagentskill.com/skills/jparkerweb-ai-assist-security-audit)
[](https://www.openagentskill.com/skills/jparkerweb-ai-assist-security-audit)
[](https://www.openagentskill.com/skills/jparkerweb-ai-assist-security-audit/audit)
[](https://www.openagentskill.com/skills/jparkerweb-ai-assist-security-audit)Autor
jparkerweb
@jparkerweb
Tags
Plattform-Fit
Gesundheitssignale
- GitHub-Stars
- 88
- Qualitätswert
- 37/100
- Letzter GitHub-Push
- 20. Aug. 2026
- Framework-Hinweise
- Unbekannt
- OpenAgentSkill-Aufrufe
- 7
- Installationskopien
- 0
- Externe Klicks
- 0
Community-Signal
Teile mit, ob dieser Skill für deinen Agent-Workflow nützlich ist. Zusammengefasstes Feedback verbessert das Ranking im Laufe der Zeit.
Vertrauen & Sicherheit
Do not auto-install
- GitHub-Akzeptanz88 GitHub-StarsPrüfen
- Star-/Fork-Aktivität88 Stars und 12 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbarPrüfen
- Aktuelle Wartung2 Tage seit dem letzten PushBestanden
- LizenzklarheitUnbekanntPrüfen
- README/SKILL.md-VollständigkeitÖffentliche Metadaten benötigen mehr README/SKILL.md-KontextInfo
- Abhängigkeits-/Laufzeitrisikocommand execution surface, network or browser surfacePrüfen
Ähnliche Skills
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K Stars