Agent skill
security-audit
Run a security audit on the project (dependencies, secrets, OWASP)
Install this agent skill to your Project
npx add-skill https://github.com/hivellm/rulebook/tree/main/templates/skills/dev/security-audit
SKILL.md
Perform a comprehensive security audit of this project.
If $ARGUMENTS is provided, focus the audit on that specific area.
Steps:
- Run dependency audit (npm audit, pip-audit, cargo audit, etc.)
- Scan for hardcoded secrets, API keys, and credentials
- Review authentication and authorization patterns
- Check for OWASP Top 10 vulnerabilities in the codebase
- Report findings categorized by severity (critical/high/medium/low)
Recommended Agent Skills
Expand your agent's capabilities with these related and highly-rated skills.
DAG Workflow
Maintain a clean dependency graph (DAG) to prevent circular dependencies and ensure maintainable architecture.
Documentation Rules
All documentation in English. Root README concise, detailed docs in `/docs`.
Quality Enforcement
These rules are NON-NEGOTIABLE and MUST be followed without exception.
Rulebook Task Management
Spec-driven task management for features and breaking changes with OpenSpec-compatible format
Agent Automation
Mandatory workflow that AI agents MUST execute after EVERY implementation.
C
Execute these commands after EVERY implementation (see AGENT_AUTOMATION module for full workflow).
Didn't find tool you were looking for?