Studio Edition
Code Security Audit Pro
Audit a codebase like a security reviewer: threat model, scan, checklists, report
Code Security Audit Pro gives your coding agent a repeatable method for reviewing an application's source code for security weaknesses, and a kit of templates so the result reads like a professional audit rather than a chat transcript. It is for developers, tech leads and small teams preparing for a launch, a customer security questionnaire or an external penetration test.
How it works
The agent agrees the scope and rules of engagement, maps entry points, assets and trust boundaries, and builds a STRIDE threat model that decides where review time goes. A bundled, read-only Python scanner (standard library only) flags leads such as eval, shell=True, string-built SQL, innerHTML and other raw HTML sinks, unsafe deserialization, weak hashes and ciphers, disabled TLS checks, risky CI and IaC settings, and hardcoded secrets, always with values redacted. The agent then works through six checklists (authentication and sessions, access control and business logic, injection and XSS, file upload and SSRF, crypto, secrets and logging, supply chain, cloud and containers), verifies each issue in the code, rates it with a simple impact x likelihood rubric and maps it to the OWASP Top 10 (2021, with a crosswalk to the 2025 edition).
What you get
- SKILL.md workflow with three depths: quick check, standard audit, full audit
- 10 templates: scope, system inventory, threat model, coverage matrix, finding, findings register (CSV), remediation plan, executive summary, full report, retest checklist
- Severity rubric, OWASP map, scanner triage guide, code review playbook
- Two worked examples on fictional apps
Important: a source review supports, and does not replace, a professional penetration test. It does not certify compliance, and a pattern scanner cannot prove the absence of vulnerabilities.
Highlights
- Scope, STRIDE threat model, review, rating, report and retest workflow
- Six ASVS-style checklists from authentication to cloud IaC
- Stdlib Python pattern scanner, JSON output, secret values redacted
- 10 fill-in templates: findings register, remediation plan, exec summary
- Two worked examples: a full audit and a multi-tenant threat model
Example
We launch our invoicing API in three weeks. Do a proper security audit of this repo and give me something I can show the team.
Security audit - tallyhook-api @ 4be91c2 Depth: Standard Posture: solid foundations, but customer data and a live payment key are exposed. Findings: 2 Critical, 3 High, 2 Medium, 1 Low (0 need confirmation) Fix first: 1. [F-01] Live Stripe key in config/default.js:14 (sk_live_[REDACTED 32 chars]) - rotate today, load from secret manager 2. [F-03] IDOR on GET /invoices/:id/pdf (src/invoices/routes.js:57) - query has no account_id condition; scope by session account, add cross-account tests 3. [F-02] SQL injection in report search (src/reports/search.js:22) - template literal in ILIKE; use a bound parameter Not reviewed: front-end SPA, cloud console | Files: security-audit/ (scope, threat model, coverage matrix, findings register, remediation plan, executive summary, report) Note: source review supports, does not replace, a penetration test.
Before we build file sharing between firms and their clients, threat model it. Django, Celery, S3, LibreOffice thumbnails.
| ID | Boundary | STRIDE | Threat | Gap | Rating | |---|---|---|---|---|---| | T1 | Firm A <-> Firm B | I | Client of firm A downloads firm B's document by UUID | DownloadView uses File.objects.get(pk=...) instead of the tenant-scoped for_user() | High 9 | | T5 | Worker -> thumbnailer | E | Crafted Office file exploits the converter | Worker runs as root with write access to every firm's files, no timeout | High 8 | | T6 | Worker -> webhook URLs | I/E | Firm admin points a webhook at the cloud metadata IP | Only an https:// prefix check; redirects followed | Medium 6 | Review plan: about 40% of the time on tenant isolation (route-by-route permission table), then worker hardening and SSRF controls.
Run your security scanner on this repo and tell me which hits actually matter.
sec_scan: 23 hits (1 critical, 7 high, 9 medium, 6 low). After reading each High/Critical in context: Real: - SECRET-STRIPE-KEY config/default.js:14 sk_live_[REDACTED 32 chars] -> Critical, rotate first - SQL-TEMPLATE src/reports/search.js:22 -> req.query.q reaches ILIKE unparameterized -> High - SSRF-USER-URL src/branding/logo.js:31 -> user URL fetched with no IP checks -> High Not issues: - SQL-TEMPLATE x3 in src/reports/columns.js -> table names from a constant map - CMD-NODE-EXEC x2 in scripts/ -> fixed build commands, no input - CRYPTO-WEAK-HASH x4 -> MD5 for ETags, not a security use The scanner finds patterns, not access-control bugs; next I am checking every route's authorization guard by hand.
What's inside
code-security-audit-pro/ ├── agents/ │ └── openai.yaml ├── examples/ │ ├── 01-worked-audit-node-express-api.md │ └── 02-worked-threat-model-django-saas.md ├── references/ │ ├── checklists/ │ │ ├── 01-authentication-and-session.md │ │ ├── 02-access-control-and-business-logic.md │ │ ├── 03-input-validation-and-injection.md │ │ ├── 04-file-upload-and-ssrf.md │ │ ├── 05-crypto-secrets-and-logging.md │ │ └── 06-supply-chain-cloud-and-containers.md │ ├── code-review-playbook.md │ ├── owasp-top-10-map.md │ ├── scanner-rules-and-triage.md │ └── severity-rubric.md ├── scripts/ │ └── sec_scan.py ├── templates/ │ ├── 01-scope-and-rules-of-engagement.md │ ├── 02-system-inventory-and-data-flows.md │ ├── 03-threat-model-stride.md │ ├── 04-coverage-matrix.csv │ ├── 05-finding.md │ ├── 06-findings-register.csv │ ├── 07-remediation-plan.md │ ├── 08-executive-summary.md │ ├── 09-security-audit-report.md │ └── 10-retest-checklist.md ├── LICENSE.txt ├── README.md └── SKILL.md
Install by unzipping into your agent's skills folder. Install guide →