security-audit
Audit Code for Common Security Vulnerabilities
Security flaws can hide in queries, shell calls, file paths, exception handlers, and rendered output. This skill guides focused reviews and practical remediation across Python and TypeScript.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "security-audit" from https://skillstore.io/skills/consiliency-security-audit.md and its manifest at https://skillstore.io/api/skills/consiliency-security-audit/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "security-audit". Review the user lookup flow for SQL injection.
Expected outcome:
- High: A user identifier is inserted directly into a database query.
- Use a parameterized query supported by the database driver.
- Add a test with hostile input and verify the query structure remains unchanged.
Using "security-audit". Check this Python exception handler.
Expected outcome:
- Medium: The handler catches every exception and suppresses the failure.
- Catch the narrowest expected exceptions and preserve unexpected failures.
- Log useful context without exposing sensitive values.
Using "security-audit". Audit a command that searches application logs.
Expected outcome:
- Critical: Untrusted text reaches a shell command.
- Use a list-form process API without a shell.
- Validate the input and test shell metacharacters as hostile cases.
Security Audit
Medium RiskMost static findings are false positives caused by educational Markdown, detection regular expressions, and intentionally vulnerable examples. The audit confirms a predictable API key fallback and finds missing shell-injection guidance plus active testing instructions without authorization controls.
Confirmed security concerns (2)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
๐ Network access (6)
โ๏ธ External commands (50)
๐ Env variables (10)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/consiliency-security-audit/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/consiliency-security-audit?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/consiliency-security-audit?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/consiliency-security-audit/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/consiliency-security-audit.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
Consiliency. (2026). security-audit security audit report (audit version 9) [Author version unspecified]. Skillstore. https://skillstore.io/skills/consiliency-security-audit/audits/9BibTeX citation
@techreport{consiliency-consiliency-security-audit-2026,
author = {Consiliency},
title = {security-audit security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/consiliency-security-audit/audits/9},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "security-audit security audit report (audit version 9)"
version: "unspecified"
type: report
authors:
- name: "Consiliency"
date-released: "2026-07-13"
url: "https://skillstore.io/skills/consiliency-security-audit/audits/9"
identifiers:
- type: other
value: "skillstore:consiliency-security-audit:audit:9"
description: "Skillstore immutable audit report identifier"
Compare variants
5 installable variantsEach author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.
Why this variant is first
89jobrien-security-audit
2026-09-09
applelamps-security-audit
2026-09-09
cloudflare-security-audit
2026-09-22
consiliency-security-audit
2026-09-09
sickn33-security-audit
2026-09-09
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Review a backend change
Check new database, file, and command-handling code before opening a pull request.
Triage security findings
Classify likely vulnerabilities, explain impact, and propose specific remediations for review.
Add a release security check
Apply a consistent checklist to sensitive changes before deployment approval.
Try These Prompts
Review this file for common security flaws. Explain each finding, assign severity, cite its location, and suggest a safer approach.
Audit the files for this feature. Focus on trust boundaries, database queries, shell calls, paths, secrets, output encoding, and exception handling.
Evaluate these security findings against framework behavior and data flow. Separate confirmed vulnerabilities from false positives, then prioritize concrete fixes.
Map entry points, untrusted inputs, privileged operations, and sensitive data flows. Audit each path, rank exploitability, and propose layered remediation with verification steps.
Best Practices
- Provide the relevant source files, framework versions, trust boundaries, and expected data flow.
- Confirm framework-specific escaping and parameterization behavior before accepting or dismissing a finding.
- Review high-impact findings manually and test each remediation against realistic hostile input.
Avoid
- Do not treat every regular-expression match as a confirmed vulnerability.
- Do not run active scanners against any target without explicit approval and authorization.
- Do not include live credentials, tokens, or sensitive customer data in prompts or reports.
Frequently Asked Questions
Does this skill execute a security scanner?
Which languages receive the strongest coverage?
Can it detect every OWASP vulnerability?
Will it distinguish safe framework features from unsafe interpolation?
Can I use the output as a release gate?
How should active security tests be handled?
Developer Details
Author
ConsiliencyLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Repository
https://github.com/Consiliency/treesitter-chunker/tree/main/.ai-dev-kit/skills/security-auditRef
635f69fb8d2f4e6330ba47a4e5a0fb239c04d110
Maintenance freshness
7/18/2026
Usage
7 downloads ยท 445 views
File structure