Security Guardian Pro: Full-Stack Security Audit
Paste the following prompt into your AI chat to install this skill:
Please install @user_4b225961/security-guardian-pro according to https://skillhub.cn/install/skillhub.md.
About this skill
Problem
Security Guardian Pro targets developer-owned local code and explicitly authorized systems. It addresses loose audit workflows where finding dangerous functions with Grep is not enough. The skill connects the tech stack, input points, auth middleware, file uploads, CORS, and security headers into a reviewable evidence trail. It also keeps the work inside defensive boundaries, avoiding unauthorized penetration testing, user-data export, or generation of working exploit code.
How It Works
The skill behaves like a defensive application security architect and follows four phases:
- Reconnaissance: use Glob for dependencies, routes, and query patterns; use Grep for weak patterns; if allowed, run gitleaks detect --no-git -v to detect hardcoded credentials.
- Scan and enumerate: if Bash is available, run semgrep --config=auto --json .; then inspect input sources such as req.query, req.body, and @RequestParam one by one.
- Harmless verification: create low-risk checks for SQLi, command injection, SSRF, XSS, and IDOR, such as SELECT version(), whoami, or out-of-band callbacks, and include request/response snippets plus a harmless-use statement.
- Reporting and compliance mapping: identify relevant regulations, risks, and remediation directions; use WebSearch / WebFetch to check CVEs and security advisories for suspicious dependencies.
Boundaries
It fits code review, SAST, credential-leak checks, and DevSecOps validation, but not unauthorized testing. For third-party systems, written authorization must be confirmed first. Real secrets should be masked, such as AKIA****, and users should rotate them. It should not generate exploits, phishing pages, social-engineering scripts, or complete usable attack code.
Use Cases
- Audit a Node backend before launch to find SQLi, IDOR, and CORS misconfiguration risks.
- Scan a Python project with Grep and Semgrep to locate hardcoded secrets and insecure defaults.
- Review a Java Spring service for @RequestParam inputs, auth middleware, and file-upload flaws.
- Use gitleaks to check repo history for leaks and look up CVEs for suspicious dependencies.
Best For
- Node backend engineers handling pre-launch security checks who need a reviewable input-point audit list.
- Ops engineers maintaining Python/Java services who need to find hardcoded credentials, weak hashing, and CVEs.
- Platform engineers implementing DevSecOps who want to combine Semgrep, gitleaks, and compliance mapping in reviews.
- App team leads handling security compliance who need to map risks to GDPR, PCI-DSS, or MLPS clauses.
Related Skills
For independent developers, automates Git weekly reports, prioritized bug tickets, and project health checks into shareable Markdown.
Scan Windows caches, temporary files, and junk files, show space usage and risk levels, and clean selected items to free disk space.
Deploy a WeChat Service Account backend with Hermes AI, Nginx, systemd, and an admin dashboard on an Ubuntu/Debian VM.
Covers Jenkins, GitHub, and automation-related wrap workflows for IT operations and security.