Verified Agent Skill record
Security Audit · Security Audit Skill
Security guidance and vulnerability review Skill for codebases, APIs, services, CLI tools, libraries, and daemons. It defaults to guidance mode for security questions, focused reviews, methodology, triage, vulnerability research, and investigation of specific findings, and runs the complete six-phase workflow with written artifacts only when the user explicitly requests a codebase audit or pen test, a full, comprehensive, or end-to-end review, or report artifacts. A candidate finding without a concrete affected principal, resource, or security outcome is not confirmed.
Tasks
- Answer security questions and perform focused reviews, methodology help, triage, or investigation of specific findings in guidance mode, using only the relevant parts of the Skill
- Run a full codebase security audit or pen test in full audit mode, running all six phases and writing the defined report artifacts
- Carry prior audit runs forward: read prior coverage-ledger.json and findings.json, compare against current source, revalidate changed findings, and re-open prior needs_validation, deferred, blocked, or out_of_scope work
- Execute scoped runs covering named paths, one subsystem, one companion domain, or the diff between two source refs, recording everything else as out_of_scope
- Plan and enforce a cost budget expressed as a maximum number of agent invocations, reserving reconnaissance, critic, and verifier calls before any hunting
Inputs
- User request, which determines guidance versus full audit mode; an ambiguous request triggers one focused question before files are created or the complete workflow starts
- Target repository root as an absolute path, plus the reviewed source ref and whether the worktree is dirty
- Optional user budget recorded as a maximum number of agent invocations across all phases
- Optional scope: named paths, one subsystem, one companion domain, or the diff between two source refs
- Prior compatible coverage-ledger.json and findings.json files, when prior runs exist
- The absolute skill directory containing SKILL.md
Outputs
- Guidance-mode responses return results to the current task; no output directory is created and no audit artifacts are written
- run-metadata.json with at least run_id, repo, target, source_ref, profile, scope_paths, budget, execution_policy, selected companion files, prior-run paths, shared-file owners, and run_status
- architecture.md
- coverage-ledger.json
- findings.json
- REPORT.md, FINDINGS-DETAIL.md, and NEEDS-VALIDATION.md
- Per-agent directories under <output-dir>/agents/<agent-id>/ with separate scratch/ working directories and parent-promoted retained artifacts/ files
Limitations and checks
- Loading the Skill does not authorize the complete audit workflow or file creation; full audit mode requires an explicit codebase audit or pen-test request, a full, comprehensive, or end-to-end review request, or a request for report artifacts
- No one pass is complete; a run must never imply it exhausts the target, and scoped or quick runs must present themselves as partial coverage
- If every sandbox control cannot be enforced, target code must not be executed; the missing capability is reported as a needs-validation blocker with a safe validation plan
- Decisive facts outside source or the sandboxed fixture are reported as needing validation rather than resolved
- Profiles change breadth and redundancy, never the evidence bar; the candidate gate, the source/local execution boundary, needs_validation discipline, schema validation, and independent verification of confirmed records cannot be scaled away
- A strict total-agent budget can still be exceeded by an unexpectedly large candidate set or by a material Phase 5 replacement needing another independent verifier
- The supplied source document ends mid-sentence in the cost-budget section, so the remaining budget-exceedance rules are not available from it
- Confirm the operating mode before acting: full audit mode only for an explicit audit or pen-test request, a full, comprehensive, or end-to-end review, or a request for report artifacts; otherwise stay in guidance mode with no output directory and no audit artifacts
AI Search
Find projects, verify facts, compare options, or turn a complex need into an actionable plan
Try a searchA click only fills the search box; you stay in control
Project Details
0