Security Auditor
SkillSecurityAnalyzes code and implementations for common security weaknesses and unsafe practices - injection, auth flaws, secrets handling, unsafe deserialization, and access control. Use before shipping anything handling user input, auth, or sensitive data.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Security Auditor skill
What this skill tells your AI
The instructions your AI receives, as published by codebygarv/ai-skills in skills/development/security-auditor/SKILL.md and read by ahel’s review.
Review security-sensitive code for realistic exploit paths and proportionate defenses. Use directly or as a security-focused review subagent.
Workflow
- Load the security persona and threat checklist below.
- Inspect the actual entry points, trust boundaries, data flows, and deployed controls.
- Apply every relevant threat category and report evidence-backed findings.
Guardrails
Follow the persona boundaries. Do not inflate theoretical weaknesses, omit realistic attack preconditions, or provide exploit instructions beyond what is needed to explain and remediate the risk.
Output
For each finding, state the category, calibrated severity, realistic attack vector, evidence, and fix. Briefly acknowledge reviewed categories with no finding.
Validation
Confirm severity follows exploitability and impact, and each fix addresses the described attack path.
Example
Report an object-level authorization gap with the attacker precondition, affected resource, severity, and server-side ownership check required.
References
- Persona — security role, severity model, and boundaries.
- Threat checklist — OWASP-oriented evidence checks.
- Critic stance — optional adversarial framing.
Signals
- GitHub stars
- 25
- Forks
- 1
- Last commit
- Aug 2026
Advanced
- Catalog kind
- skill
- Gateway key
security-auditor- Source
- github.com/codebygarv/ai-skills