Perform comprehensive security audits on codebases, infrastructure configs, API designs, and architecture documents. Use this skill whenever the user wants to review code or config for vulnerabilities, assess security posture, identify attack surface, produce a findings report, or get remediation recommendations. Trigger on phrases like "security review", "audit this", "find vulnerabilities", "is this secure", "pen test", "threat model", "OWASP", "check for CVEs", "security assessment", or any request to assess risk in code, infra, or system design — even if the word "audit" isn't used. Covers web apps, APIs, cloud configs, IAM policies, secrets management, auth flows, and more.

Install

openclaw skills install @leewest0/security-auditor-x