common-security-audit is agent-read markdown (skill) from hoangnguyen0403/agent-skills-standard: Probe for hardcoded secrets, injection surfaces, unguarded routes, business logic flaws, and platform-specific weaknesses across backend (Node, Go, Java, Python, Rust), frontend (React, Angular, Vue), and mobile (iOS, Android, Flutter) codebases. Use when performing security audits, vulnerability scans, secrets detection, or penetration testing..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Security Audit
## **Priority: P0 (CRITICAL)**
## 1. Scan for Hardcoded Secrets
See [implementation examples](references/implementation.md) for secrets scanning commands.
Covers: Backend source, frontend bundles (`REACT_APP_`, `NEXT_PUBLIC_`, `VITE_`), mobile configs (`BuildConfig`, iOS configurations, `strings.xml`).
## 2. Detect Data Leakage in Logs
See [implementation examples](references/implementation.md) for log leakage scanning commands across Node, Go, Dart, Java, Swift.
## 3. Map Injection Surfaces & Auth Coverage
See [implementation examples](references/implementation.md) for injection detection and auth coverage measurement.
## 4. Run Dependency CVE Scans
- **Node/Python/Rust**: `npm audit --audit-level=high` | `pip-audit` | `cargo audit`
- **Go/Dart**: `go list -m -u all` | `dart pub outdated --json`
- **Java/Mobile**: `mvn dependency:list` / `./gradlew dependencies` | `pod audit` / Gradle scan
## 5. Infrastructure & Adversarial Entry Points
See [implementation examples](references/implementation.md) for RCE/SSRF/Path Traversal and infrastructure hardening (Docker/K8s).
## 6. Frontend-Specific Audit
…
Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
GET https://markdownregistry.com/api/v1/artifacts/art_arlo5tfsrj5npvgp
GET https://markdownregistry.com/api/v1/resolve?ref=hoangnguyen0403/agent-skills-standard/common-security-audit
GET https://markdownregistry.com/api/v1/blob/b9ed3c2704e2b4b9df14693b2059a5b47f7fea7446a0157a245524eb58e0ff5b
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
hoangnguyen0403/agent-skills-standard · .agents/skills/caveman-compress/SKILL.md · Compress natural language memory files (CLAUDE.md, todos, preferences) into caveman format to save input tokens…
hoangnguyen0403/agent-skills-standard · .agents/skills/caveman-review/SKILL.md · Ultra-compressed code review comments. Cuts noise from PR feedback while preserving the actionable signal. Each comment…
hoangnguyen0403/agent-skills-standard · .agents/skills/caveman/SKILL.md · Ultra-compressed communication mode. Cuts token usage ~75% by speaking like caveman while keeping full technical…
hoangnguyen0403/agent-skills-standard · .agents/skills/common/common-architecture-diagramming/SKILL.md · Draw architecture diagrams as editable draw.io files with a fixed house style, C4 levels, and evidence-tagged shapes…
hoangnguyen0403/agent-skills-standard · .agents/skills/common/common-business-requirements/SKILL.md · Standardize BRD and BRD-lite discovery for business goals, stakeholder impact, current-to-future state, and measurable…
hoangnguyen0403/agent-skills-standard · .agents/skills/common/common-dast-tooling/SKILL.md · Standardize dynamic application security testing for backend APIs, frontend web apps, and mobile clients. Covers ZAP…
hoangnguyen0403/agent-skills-standard · .agents/skills/common/common-debugging/SKILL.md · Troubleshoot systematically using the Scientific Method. Use when debugging crashes, tracing errors, diagnosing…
hoangnguyen0403/agent-skills-standard · .agents/skills/common/common-documentation/SKILL.md · Write effective code comments, READMEs, and technical documentation following intent-first principles. Use when adding…