AI Agent Hub
Back to skills
🔒

Security Audit & DevSecOps Expert

IT Ops & Security Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please follow https://skillhub.cn/install/skillhub.md to install @org-02qudk26/security-auditor-zh.

About this skill

Problem

Many security reviews stop at “scan the app”: tools generate reports, but teams still need asset scope, business impact, remediation priority, and an evidence trail. Security controls are often scattered across architecture, pipelines, cloud configuration, and compliance documentation, making unified assessment difficult. This skill is aimed at engineers and turns security auditing, DevSecOps, and compliance review into an executable analysis workflow.

How it works

It starts by confirming scope, assets, and compliance requirements, then reviews architecture, threat models, and existing controls. Key capabilities include:

  • Security pipelines: integrating SAST, DAST, IAST, dependency scanning, and container scanning in CI/CD
  • Identity and authorization: reviewing OAuth 2.0/2.1, OpenID Connect, JWT, RBAC/ABAC, and zero-trust controls
  • Vulnerability and risk: prioritizing findings with OWASP Top 10, CVSS, threat modeling, and business impact
  • Cloud and compliance: checking AWS/Azure/GCP posture, data protection, and requirements such as GDPR, SOC 2, and NIST

The main sequence is: confirm scope → review architecture and threat models → run targeted scans and manual validation in high-risk areas → rank fixes by severity and business impact → verify remediation and archive residual risk.

Boundaries

It fits security audits, risk assessments, SDLC security control reviews, and mitigation design. It is not intended for unauthorized intrusive testing, legal advice, formal compliance certification, or unattended quick scanning. In production, obtain written approval before invasive tests and protect sensitive data such as keys in reports.

Use Cases

  • Audit API gateway auth and rate limiting pre-launch.
  • Review static, dynamic, and container scan configs in CI/CD.
  • Model threats in a container cluster and check Pod security.
  • Assess data processing against GDPR and privacy-by-design.

Best For

  • DevOps engineer securing CI/CD: configure SAST, DAST, dependency, and container scanning.
  • Backend engineer leading app security review: check OAuth, JWT, RBAC, and API rate limiting.
  • Platform engineer managing cloud-native compliance: model Kubernetes threats and review security policies.
  • Security compliance specialist preparing SOC 2 or ISO 27001: organize evidence, residual risk, and fixes.