---
name: security-audit
description: "Scan code for security vulnerabilities including eval/exec usage, path traversal, hardcoded secrets, and injection risks. Triggers on: security, vulnerability, audit, scan, CVE, CWE, secrets, injection, eval, exec, OWASP."
---
# Security Audit

**IMPORTANT: Start your response with a context preamble.**

Call `help_lookup(topic="security-audit", mode="preamble")` and
display the returned `preamble` text as a blockquote. Then
tell the user they can say "tell me more" for a step-by-step
guide, or answer the scoping questions below to proceed.

If the MCP call fails, fall back to:

> **Security Audit** — Scans your code for security
> vulnerabilities — eval/exec, path traversal, hardcoded
> secrets, injection risks.

## Scoping

Before running, ask:

1. **Scope**: "Which path should I scan?" Default to the
   project root if the user says "everything."
2. **Focus**: "Any specific concern — secrets, injection,
   dependencies, or a full sweep?"

## Execution

Call the `security_audit` MCP tool with the scoped path:

```
security_audit(path="<user-specified path>")
```

## Output Format

The `security_audit` tool returns structured `findings`, a
`health_score`, and a pre-rendered **`dashboard_html`**.

**Prefer the rich severity dashboard.** Pass the response's
`dashboard_html` straight to `mcp__visualize__show_widget` — it renders
counts-by-severity chips + the health score over a severity-sorted list
of finding cards (severity badge, `file:line`, message, code snippet).
The HTML is display-only and injection-safe (generated by
`attune.workflows.security_audit_dashboard`).

**Fall back to a markdown table** when the widget surface is
unavailable, grouped by severity:

```markdown
## Security Audit Results

**Score:** X/100 | **Files Scanned:** Y | **Issues:** Z

### Critical
| File | Line | Issue | CWE |
|------|------|-------|-----|

### High / Medium / Low
| File | Line | Issue | CWE |
|------|------|-------|-----|
```

Use clickable file links: `[file.py:123](path#L123)`

## What It Checks

- `eval()` and `exec()` usage (CWE-95)
- Path traversal vulnerabilities (CWE-22)
- Hardcoded secrets and API keys
- SQL injection patterns (CWE-89)
- Command injection risks (CWE-78)
- Broad exception handling that masks errors
- Missing input validation

## Help

After presenting results, call:

```
help_lookup(
    topic="security-audit",
    mode="workflow_help"
)
```

If templates are returned, offer: "I have tips about
security audits — want to see them?"

## Follow-Up

After presenting results, offer:

- "Want me to fix the critical issues?"
- "Should I generate security tests for the flagged
  files?"
- "Want a deeper scan of a specific directory?"
