security-audit is agent-read markdown (skill) from j-star-films-studios/vibecode-protocol-suite: Use when auditing code for security vulnerabilities, verifying auth/payment boundaries, scanning for secret leaks, or doing pre-deployment sanity checks..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Security Audit Skill
A comprehensive, manual deep code audit protocol for security-critical systems. Includes fast "Vibe Coding Guardrails" for the most common AI-assisted development pitfalls.
## When to Use
- Before major releases
- Security review requests
- Auditing authentication/payment flows
- When "audit" or "security" is mentioned
- After scaffolding a new project with AI (vibe coding sanity check)
- Before first deploy of any user-facing app
## Audit Phases
### Phase 0: Scope Definition
Define boundaries:
- **FULL_SCAN**: Entire codebase
- **FEATURE_SCAN**: Specific feature (`docs/features/[Name].md`)
- **DIFF_SCAN**: `git diff --staged` or `git diff HEAD~1`
### Phase 1: The Detective (Static Analysis)
```bash
# 1. Detect package manager & run dependency audit
# Auto-detect: check which lockfile exists
# pnpm-lock.yaml → pnpm audit
# package-lock.json → npm audit
# yarn.lock → yarn audit
# bun.lockb → bun pm audit (or bunx audit)
pnpm audit # ← swap for your package manager
# 2. Secret scanning (use jstar if available)
jstar detect
# 3. Manual grep patterns:
# Secrets
grep -rE "(api_key|secret|password|token)\s*[:=]\s*['\"\`][a-zA-Z0-9_\-\.]{10,}['\"\`]"
…
Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
GET https://markdownregistry.com/api/v1/artifacts/art_5qgbhvg3pvtjszwy
GET https://markdownregistry.com/api/v1/resolve?ref=j-star-films-studios/vibecode-protocol-suite/security-audit
GET https://markdownregistry.com/api/v1/blob/994a003fe69168261e748597af3d8c59919f3d2022bf4362fe9b23f3e26d8f90
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
More from j-star-films-studios/vibecode-protocol-suite
j-star-films-studios/vibecode-protocol-suite · .agents/skill-curator/SKILL.md · Use when adding, importing, reorganizing, renaming, or refactoring skills according to the Lean Unified Skills…
j-star-films-studios/vibecode-protocol-suite · .agents/skills/unslop/SKILL.md · Use when writing any text, chat responses, documentation, UI copy, or skill instructions. Cuts AI tells, filler, and…
j-star-films-studios/vibecode-protocol-suite · assets/.agent/skills/agent-engineering/arena/SKILL.md · Spawn N parallel candidates at the same task, pick a base, graft the strongest parts of the losers into it. Use for…
j-star-films-studios/vibecode-protocol-suite · assets/.agent/skills/agent-engineering/automate-me/SKILL.md · Use for "automate me", "create/update/refresh my -mode skill", "turn/capture my preferences or working style into a…
j-star-films-studios/vibecode-protocol-suite · assets/.agent/skills/agent-engineering/conversation-to-spec/SKILL.md · Turn the current conversation into a spec and publish it to the project issue tracker: no interview, just synthesis of…
j-star-films-studios/vibecode-protocol-suite · assets/.agent/skills/agent-engineering/crafting-effective-readmes/SKILL.md · Use when writing or improving README files. Not all READMEs are the same — provides templates and guidance matched to…
j-star-films-studios/vibecode-protocol-suite · assets/.agent/skills/agent-engineering/create-verification-skill/SKILL.md · Generate a project-local verification skill that drives your app the way a user does — any language, framework, or…
j-star-films-studios/vibecode-protocol-suite · assets/.agent/skills/agent-engineering/domain-modeling/SKILL.md · Build and sharpen a project's domain model. Use when discussing codebase terminology, writing or editing a CONTEXT.md…
j-star-films-studios/vibecode-protocol-suite · assets/.agent/skills/agent-engineering/expert-system-engineer/SKILL.md · Use when engineering knowledge-based expert systems using CommonKADS methodology, MYCIN/EMYCIN rule patterns, certainty…
maxmiksa/auto-company · .claude/skills/security-audit/SKILL.md · Use when reviewing code security, auditing dependencies for CVEs, checking configuration or secret security, assessing…
jellydn/my-ai-tools · configs/amp/plugins/my-ai-tools-skills/skills/security-audit/SKILL.md · Use when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from…