Project overview
kapus-secuaudit checks a codebase or an owner-operated URL for dependency risks, exposed secrets, missing RLS or auth, injection paths, unsafe configuration, and deployment mistakes. It returns a 0–100 score plus P0–P3 findings with locations, impact, and concrete fixes. In fix mode, it shows a file-by-file change plan and waits for approval before editing. The skill is deliberately defensive: it avoids exploitation, brute force, denial-of-service, and audits of sites the user does not control.
Repository facts
- Primary language
- Shell
- License
- MIT
- Repository updated
- Jun 18, 2026
- Default branch
- main
Resource types
General skill
Use cases
Security and privacy
Platforms
Claude Code, Codex, and more
Capabilities
Security guardrailVerification and evals
Audience
Developers