Skip to main content
Back to the directory
ovachiever/droid-tingsSoftware EngineeringFrontend and Design

security-auditor

Automatic detection of OWASP Top 10 vulnerabilities and insecure code patterns across your codebase.

SkillJury keeps community verdicts, source metadata, and external repository signals in separate lanes so ranking data never pretends to be a review.

SkillJury verdict
Pending

No approved reviews yet

Would recommend
Pending

Waiting on enough review volume

Install signal
719

Weekly or total install activity from catalog data

Sign in to review
0 review requests
Install command
npx skills add https://github.com/ovachiever/droid-tings --skill security-auditor
SkillJury does not have enough approved reviews to publish a community verdict yet. Source metadata and repository proof are still available above.
SkillJury Signal Summary

As of May 1, 2026, security-auditor has 719 weekly installs, 0 community reviews on SkillJury. Community votes currently stand at 0 upvotes and 0 downvotes. Source: ovachiever/droid-tings. Canonical URL: https://skills.sh/ovachiever/droid-tings/security-auditor.

Security audits
Gen Agent Trust HubPASS
SocketPASS
SnykWARN
About this skill
Automatic detection of OWASP Top 10 vulnerabilities and insecure code patterns across your codebase. Automatic security vulnerability detection. 1. SQL Injection 2. XSS (Cross-Site Scripting) 3. Authentication Issues 4. Sensitive Data Exposure 5. Broken Access Control I can run security audits on dependencies: Me (Skill): Quick vulnerability pattern detection @code-reviewer (Sub-Agent): Deep security audit with threat modeling Works without sandboxing: ✅ Yes Works with sandboxing: ✅ Yes Optional: For dependency scanning Add company-specific security patterns: - Scans for SQL injection, XSS, hardcoded secrets, weak authentication, broken access control, and insecure deserialization with severity-based alerts - Activates automatically on code file changes, dependency updates, configuration modifications, and before deployments - Provides specific remediation guidance with code examples and references to OWASP and CWE standards - Integrates with dependency auditing tools (npm audit, pip-audit) and pairs with the @code-reviewer sub-agent for deeper threat modeling - ✅ Code files modified (especially auth, API, database) - ✅ User mentions security or vulnerabilities - ✅ Before deployments or commits - ✅ Dependency changes - ✅ Configuration file changes - Insecure Deserialization - Security Misconfiguration - Insufficient Logging - CSRF Protection Missing - CORS Misconfiguration -...

Source description provided by the upstream listing. Community review signal and install context stay separate from this narrative layer.

Community reviews

Latest reviews

No community reviews yet. Be the first to review.

Browse this skill in context
FAQ
What does security-auditor do?

Automatic detection of OWASP Top 10 vulnerabilities and insecure code patterns across your codebase.

Is security-auditor good?

security-auditor does not have approved reviews yet, so SkillJury cannot publish a community verdict.

Which AI agents support security-auditor?

security-auditor currently lists compatibility with Skills CLI.

Is security-auditor safe to install?

security-auditor has been scanned by security audit providers tracked on SkillJury. Check the security audits section on this page for detailed results from Socket.dev and Snyk.

What are alternatives to security-auditor?

Skills in the same category include review-management, conversation-memory, coverage, grimoire-aave.

How do I install security-auditor?

Run the following command to install security-auditor: npx skills add https://github.com/ovachiever/droid-tings --skill security-auditor

Related skills

Alternatives in Software Engineering