Security Audit & DevSecOps Expert
Paste the following prompt into your AI chat to install this skill:
Please follow https://skillhub.cn/install/skillhub.md to install @org-02qudk26/security-auditor-zh.
About this skill
Problem
Many security reviews stop at “scan the app”: tools generate reports, but teams still need asset scope, business impact, remediation priority, and an evidence trail. Security controls are often scattered across architecture, pipelines, cloud configuration, and compliance documentation, making unified assessment difficult. This skill is aimed at engineers and turns security auditing, DevSecOps, and compliance review into an executable analysis workflow.
How it works
It starts by confirming scope, assets, and compliance requirements, then reviews architecture, threat models, and existing controls. Key capabilities include:
- Security pipelines: integrating SAST, DAST, IAST, dependency scanning, and container scanning in
CI/CD - Identity and authorization: reviewing OAuth 2.0/2.1, OpenID Connect, JWT, RBAC/ABAC, and zero-trust controls
- Vulnerability and risk: prioritizing findings with OWASP Top 10, CVSS, threat modeling, and business impact
- Cloud and compliance: checking AWS/Azure/GCP posture, data protection, and requirements such as GDPR, SOC 2, and NIST
The main sequence is: confirm scope → review architecture and threat models → run targeted scans and manual validation in high-risk areas → rank fixes by severity and business impact → verify remediation and archive residual risk.
Boundaries
It fits security audits, risk assessments, SDLC security control reviews, and mitigation design. It is not intended for unauthorized intrusive testing, legal advice, formal compliance certification, or unattended quick scanning. In production, obtain written approval before invasive tests and protect sensitive data such as keys in reports.
Use Cases
- Audit API gateway auth and rate limiting pre-launch.
- Review static, dynamic, and container scan configs in CI/CD.
- Model threats in a container cluster and check Pod security.
- Assess data processing against GDPR and privacy-by-design.
Best For
- DevOps engineer securing CI/CD: configure SAST, DAST, dependency, and container scanning.
- Backend engineer leading app security review: check OAuth, JWT, RBAC, and API rate limiting.
- Platform engineer managing cloud-native compliance: model Kubernetes threats and review security policies.
- Security compliance specialist preparing SOC 2 or ISO 27001: organize evidence, residual risk, and fixes.
Related Skills
Detects child climbing, leaning out, or gripping window/balcony edges from surveillance video and outputs tiered alerts with historical reports.
A pre-release security auditor for Skills that statically checks injection, credentials, SSRF, CVEs, and permissions, with scored reports.
For independent developers, automates Git weekly reports, prioritized bug tickets, and project health checks into shareable Markdown.
Scan Windows caches, temporary files, and junk files, show space usage and risk levels, and clean selected items to free disk space.