Security Review & Audit Skill

SkillSecurity

Security review skill that lets your agent scan code changes for vulnerabilities, leaked secrets, and insecure patterns.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the Security Review & Audit Skill skill

About this skill

🛡⚔️AI-Powered Penetration Testing Framework with automated vulnerability scanning, multi-agent system, and compliance reporting🛡⚔️

What this skill tells your AI

The instructions your AI receives, as published by shadd0wtaka/zen-ai-pentest in skills/security-review/SKILL.md and read by ahel’s review.

Workflows für PR-Review, Security-Audit, Log-Analyse, Testing, Compliance.

PR Security Review

Automatisierte Checks

# Dependency Scan
trivy fs --severity CRITICAL,HIGH --exit-code 1 ./app
# Secret Scan
trufflehog filesystem --no-verification .
gitleaks detect --source . --verbose
# SAST
semgrep --config=auto --error
# License Check
license-checker --failOn GPL --production

Code Review Checklist

- [ ] Hardcoded secrets/API-Keys? → gitleaks scan
- [ ] SQL Injection? → Präparierte Statements statt String-Concatenation
- [ ] XSS? → Output escaped, CSP Header gesetzt
- [ ] IDOR? → Authorization-Check pro Resource
- [ ] Rate Limiting? → pro Endpoint/User/IP
- [ ] Dependency vulnerabel? → trivy/npm audit
- [ ] Logs enthalten Secrets? → Kein logging von Passwörtern/Tokens
- [ ] HTTPS only? → HSTS Header, Redirect

Log-Analyse

Security Log Patterns

# Failed logins
grep "Failed password" /var/log/auth.log | awk '{print $11}' | sort | uniq -c | sort -rn | head
# Port scans
grep "SYN" /var/log/syslog | awk '{print $NF}' | sort -u
# API Errors
journalctl -u myapp --since "1h ago" | grep -i "error\|denied\|unauthorized"
# Docker Sicherheit
docker logs container 2>&1 | grep -E "ERROR|PANIC|FATAL|SECURITY"

Logging Best Practices

import structlog

logger = structlog.get_logger()
logger.info("user.login", user_id=123, ip="10.0.0.1", mfa=True)
# → {"event": "user.login", "user_id": 123, "ip": "10.0.0.1", "mfa": true}

Pentesting Quick-Start

deep-recon --target example.com --output recon.json
deep-exploit --target example.com --vulnerability-scan
deep-report --scan-id wf-$(date +%s) --format html

Testing Strategy

Test Pyramid

# Unit (schnell, viele)
pytest tests/unit/ -x --cov --cov-fail-under=80
# Integration (API, DB)
pytest tests/integration/ -x --docker-compose=docker-compose.test.yml
# E2E (Browser)
npx playwright test --project=chromium
# Security
zap-cli quick-scan --self-contained http://localhost:3000

CI Security Gates

# .github/workflows/security.yml
name: Security Scan
on: [pull_request]
jobs:
  security:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - run: trivy fs --severity CRITICAL --exit-code 1 .
      - run: gitleaks detect --verbose --redact
      - run: npm audit --audit-level=high

Repo Hygiene

# Git history cleanup
git log --oneline --graph --all
git fsck --full  # integrity check
# Large files
git rev-list --objects --all | git cat-file --batch-check='%(objecttype) %(objectname) %(objectsize) %(rest)' | awk '/^blob/ {print $3,$4}' | sort -rn | head
# Unused branches
git branch --merged main | grep -v "main\|*" | xargs git branch -d

Compliance Checks

# SBOM Generation
syft packages . -o cyclonedx > sbom.json
# Signature
cosign sign-blob --key cosign.key sbom.json
# Attestation
cosign attest --predicate sbom.json --key cosign.key image:tag

Signals

GitHub stars
469
Forks
81
Last commit
Sep 2026
Hacker News mentions
1
Advanced
Item type
skill
Key
security-review-shadd0wtaka
Source
github.com/shadd0wtaka/zen-ai-pentest