security-audit
Run a self-contained security audit workflow for web applications and APIs, covering scoping, reconnaissance, manual testing, API review, hardening, and reporting.
What this skill does
# Security Audit Standalone workflow for reviewing a web application or API without depending on other skills. ## When to Use Use this skill when: - auditing a web application or API for security issues - reviewing authentication, authorization, or session handling - checking input validation, injection risk, or data exposure - performing a structured hardening and reporting pass before release ## Scope and Safety - Confirm the target, authorized boundaries, and whether testing is read-only or allows active probing. - Do not run destructive checks, high-volume fuzzing, or denial-of-service style traffic unless explicitly authorized. - Record assumptions, environment limits, and access level before starting. - Prefer reproducible evidence over broad claims. ## Audit Workflow ### Phase 1: Scope and Reconnaissance 1. Identify the in-scope domains, apps, APIs, jobs, and background workers. 2. Map the attack surface: - routes and entry points - authentication flows - admin surfaces - file upload or import paths - third-party callbacks and webhooks 3. Note the framework, hosting model, data stores, and external integrations. 4. Build a simple asset inventory before testing. ### Phase 2: Baseline Review 1. Check dependency versions, known exposure areas, and obvious misconfigurations. 2. Review environment and deployment assumptions: - secret handling - logging - debug mode - CORS - cookie flags - security headers 3. Identify areas where automated scanning would be useful, but keep the workflow self-contained: describe the scan you would run and why. ### Phase 3: Manual Web Application Testing Check: - injection risk in query params, forms, search, filters, uploads, and template rendering - XSS risk in stored, reflected, and DOM-driven flows - broken authentication, weak session handling, and insecure password reset flows - broken access control and IDOR patterns across user, team, and admin scopes - CSRF exposure on state-changing requests - path traversal, file handling, and unsafe object access - sensitive data exposure in UI, logs, client storage, and error messages For each finding, capture: - entry point - required privileges - reproduction steps - observed impact - fix direction ### Phase 4: API Security Review Check: - endpoint inventory and undocumented routes - authn/authz coverage on every state-changing endpoint - tenant isolation and object-level authorization - rate limiting and abuse resistance - request validation and schema enforcement - unsafe defaults in error responses - webhook signature verification and replay handling Where useful, describe the exact request variants that should be tested: - missing auth - low-privilege auth - cross-tenant identifiers - malformed payloads - boundary values - repeated requests ### Phase 5: Hardening Review Review: - password and token lifecycle - MFA or step-up auth where appropriate - least-privilege roles and admin separation - audit logging for privileged actions - secrets management and rotation - SSRF, open redirect, and outbound request controls - file upload validation and storage isolation - backup, recovery, and incident response readiness ### Phase 6: Reporting Produce a report with: 1. Executive summary 2. Scope and methodology 3. Findings ordered by severity 4. Reproduction notes and evidence 5. Remediation guidance 6. Residual risks and follow-up checks ## Security Checklist ### Web - [ ] Authentication flows reviewed - [ ] Authorization boundaries reviewed - [ ] Session handling reviewed - [ ] Input validation reviewed - [ ] Injection risk reviewed - [ ] XSS risk reviewed - [ ] CSRF protection reviewed - [ ] Error handling and data exposure reviewed ### API - [ ] Endpoint inventory captured - [ ] Auth coverage checked per endpoint - [ ] Object-level authorization checked - [ ] Rate limiting reviewed - [ ] Validation and schema handling reviewed - [ ] Webhook verification reviewed ### Operations - [ ] Secrets handling reviewed - [ ] Logging and audit trail reviewed - [ ] Security headers and cookie settings reviewed - [ ] Dependency posture reviewed - [ ] Recovery and incident readiness reviewed ## Output Standard Every finding should include: - title - severity - affected surface - reproduction steps - impact - remediation - confidence level ## Limits - This skill structures the audit; it does not replace environment-specific testing or specialist review. - If access, authorization, or rules of engagement are unclear, stop and clarify before continuing.
Related in Backend & APIs
jfrog
IncludedInteract with the JFrog Platform via the JFrog CLI and REST/GraphQL APIs. Use this skill when the user wants to manage Artifactory repositories, upload or download artifacts, manage builds, configure permissions, manage users and groups, work with access tokens, configure JFrog CLI servers, search artifacts, manage properties, set up replication, manage JFrog Projects, run security audits or scans, look up CVE details, query exposures scan results from JFrog Advanced Security, manage release bundles and lifecycle operations, aggregate or export platform data, or perform any JFrog Platform administration task. Also use when the user mentions jf, jfrog, artifactory, xray, distribution, evidence, apptrust, onemodel, graphql, workers, mission control, curation, advanced security, exposures, or any JFrog product name.
cupynumeric-migration-readiness
IncludedPre-migration readiness assessor for porting NumPy to cuPyNumeric. Use BEFORE substantial porting work begins when the user asks whether code will scale on GPU, whether they should migrate to cuPyNumeric, which NumPy patterns transfer cleanly, what must be refactored before porting, or mentions pre-port assessment, scaling analysis, or refactor planning. Inspect the user's source code, look up NumPy usage, cross-reference the cuPyNumeric API support manifest, and distinguish distributed-scaling-friendly patterns from blockers such as unsupported APIs, scalar synchronization, host round-trips, Python/object-heavy control flow, shape/data-dependent branching, and in-place mutation hazards. Produce a verdict of READY, LIGHT REFACTOR, SIGNIFICANT REFACTOR, or NOT RECOMMENDED, with concrete refactor pointers.
alibabacloud-data-agent-skill
IncludedInvoke Alibaba Cloud Apsara Data Agent for Analytics via CLI to perform natural language-driven data analysis on enterprise databases. Data Agent for Analytics is an intelligent data analysis agent developed by Alibaba Cloud Database team for enterprise users. It automatically completes requirement analysis, data understanding, analysis insights, and report generation based on natural language descriptions. This tool supports: discovering data resources (instances/databases/tables) managed in DMS, initiating query or deep analysis sessions, real-time progress tracking, and retrieving analysis conclusions and generated reports. Use this Skill when users need to query databases, analyze data trends, generate data reports, ask questions in natural language, or mention "Data Agent", "data analysis", "database query", "SQL analysis", "data insights".
token-optimizer
IncludedReduce OpenClaw token usage and API costs through smart model routing, heartbeat optimization, budget tracking, and native 2026.2.15 features (session pruning, bootstrap size limits, cache TTL alignment). Use when token costs are high, API rate limits are being hit, or hosting multiple agents at scale. The 4 executable scripts (context_optimizer, model_router, heartbeat_optimizer, token_tracker) are local-only — no network requests, no subprocess calls, no system modifications. Reference files (PROVIDERS.md, config-patches.json) document optional multi-provider strategies that require external API keys and network access if you choose to use them. See SECURITY.md for full breakdown.
resend-cli
IncludedUse this skill when the task is specifically about operating Resend from an AI agent, terminal session, or CI job via the official resend CLI: installing/authenticating the CLI, sending/listing/updating/cancelling emails, batch sends, domains and DNS, webhooks and local listeners, inbound receiving, contacts, topics, segments, broadcasts, templates, API keys, profiles, or debugging Resend CLI/API failures. Trigger on mentions of Resend CLI, `resend`, `resend doctor`, `resend emails send`, `resend domains`, `resend webhooks listen`, `resend emails receiving`, or agent-friendly terminal automation.
alibabacloud-odps-maxframe-coding
IncludedUse this skill for MaxFrame SDK development and documentation navigation on Alibaba Cloud MaxCompute (ODPS). Helps answer MaxFrame API, concept, official example, and supported pandas API questions; create data processing programs; read/write MaxCompute tables; debug jobs (remote or local); and build custom DPE runtime images. Trigger when users mention MaxFrame, MaxCompute with MaxFrame, ODPS table processing, DPE runtime, MaxFrame docs/examples, DataFrame/Tensor operations, or GPU runtime setup. Works for both English and Chinese queries about Alibaba Cloud data processing with MaxFrame.