Project overview
Use the skill in audit, scan, guide, or harden mode to review a backend project. It detects the stack, maps the attack surface, traces untrusted input to dangerous sinks, checks dependencies and configuration, and reports verified findings with file locations, severity, and fix guidance. Its coverage is anchored to OWASP and ASVS, but it is not runtime testing, a professional penetration test, or a compliance program, and it does not edit code without approval.
Repository facts
- Primary language
- Not detected
- License
- MIT
- Repository updated
- Jul 7, 2026
- Default branch
- main
Resource types
PluginGeneral skill
Use cases
Security and privacyBackend development
Platforms
Claude CodeCursorGitHub CopilotCodex
Capabilities
Verification and evals
Audience
Security engineers