
Security
Comprehensive security audits detecting vulnerabilities and verifying fixes
What You Can Do
Run comprehensive security audits on sensitive code before deployment. Claude scans for OWASP Top 10 vulnerabilities including injection attacks, broken authentication, data exposure, and misconfigurations, then verifies that fixes are properly implemented. You get detailed reports with severity levels, exact locations, and remediation guidance.
Features
identifies SQL injection, command injection, XSS, and LDAP injection vulnerabilities
catches broken authentication, session issues, privilege escalation, and insecure access patterns
detects hardcoded secrets, missing encryption, insecure cryptography, and sensitive data exposure
flags default credentials, verbose error messages, missing security headers, and configuration weaknesses
identifies known vulnerable packages, outdated libraries, and supply chain risks
categorizes findings as CRITICAL, HIGH, MEDIUM, or LOW with exact file and line references
confirms that identified vulnerabilities are properly remediated before deployment
provides actionable steps to fix each vulnerability, not just identification
Example Output
Input: Review authentication code for security vulnerabilities
Output:
SECURITY AUDIT REPORT
[CRITICAL] Hardcoded Database Credentials (auth.js:15)
- Issue: Database password stored in plaintext
- Remediation: Move to environment variables
[HIGH] Missing CSRF Protection (login.js:42)
- Issue: Form submission not validated with CSRF tokens
- Remediation: Implement token validation middleware
[MEDIUM] Weak Password Hashing (user.js:8)
- Issue: Using md5 instead of bcrypt
- Remediation: Replace with bcrypt with 12+ salt rounds
VERIFICATION REPORT
✓ Credentials moved to .env
✓ CSRF middleware implemented
✓ Password hashing upgraded to bcrypt
What's Included
- security.md: Complete workflow instructions with agent sequence and execution details
- OWASP Top 10 checklist: Comprehensive vulnerability categories and detection patterns
- Vulnerability report template: Structured format with severity levels, locations, and remediation steps
- Dependency scanning framework: Process for identifying known vulnerable packages
- Fix verification checklist: Testing and validation steps to confirm remediation
Who It's For
- Security engineers — conducting comprehensive security audits and vulnerability assessments
- DevSecOps engineers — integrating security checks into CI/CD pipelines before deployment
- Backend developers — reviewing authentication, authorization, and data protection code
- Full-stack developers — auditing sensitive features handling user data or payments
- Engineering leads — pre-deployment security reviews before production releases
Best For
- Security code reviews of authentication and authorization systems
- Vulnerability scanning in payment processing or financial code
- Dependency audit and supply chain risk assessment
- Pre-deployment security validation for sensitive features
- OWASP compliance checking and remediation verification







