raven-investigate

Audit codebases for vulnerabilities across six security domains.

5|Updated Nov 22, 2025
One-click install
npx skills add https://github.com/AutumnsGrove/Lattice --skill raven-investigate
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: raven-investigate
Source: https://github.com/AutumnsGrove/Lattice/tree/main/.claude/skills/raven-investigate
Command: npx skills add https://github.com/AutumnsGrove/Lattice --skill raven-investigate

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill rapidly audits any codebase's security posture by deploying parallel sub-agents across all critical security domains, delivering a comprehensive assessment quickly.

Core Features & Use Cases

  • Parallel Investigation: Simultaneously probes secrets, dependencies, auth, input validation, HTTP security, and dev hygiene.
  • Stack-Adaptive: Detects the tech stack and tailors checks accordingly.
  • Use Case: When you need a fast, thorough security review of an unfamiliar project before integration or deployment, the Raven provides a clear picture of risks.

Quick Start

Run the raven-investigate skill to perform a full security audit on the current codebase.

Frequently Asked Questions about raven-investigate

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a comprehensive codebase security audit?▼

A comprehensive codebase security audit probes vulnerabilities across secrets, dependencies, authentication, input validation, HTTP security, and development hygiene. It adapts checks to your specific tech stack to provide actionable findings and a detailed posture assessment.

What does a vulnerability assessment cover in software engineering?▼

A vulnerability assessment covers six critical domains: secrets, dependencies, authentication, input validation, HTTP security, and development hygiene. It identifies risks and provides a detailed security posture assessment with actionable findings.

Can I run a security audit on an unfamiliar codebase before deployment?▼

Yes, you can run a security audit on an unfamiliar codebase before deployment. The investigation detects the tech stack, tailors checks accordingly, and delivers a clear picture of risks across six critical security domains.

What is the best way to check for secrets and dependency vulnerabilities?▼

The best way to check for secrets and dependency vulnerabilities is deploying parallel sub-agents across all critical security domains. This stack-adaptive approach rapidly delivers a comprehensive assessment of risks and actionable findings.

Does a parallelized security audit work with different tech stacks?▼

A parallelized security audit works with different tech stacks by detecting the stack and tailoring checks accordingly. It simultaneously probes secrets, dependencies, auth, input validation, HTTP security, and dev hygiene for a thorough assessment.

Why should I use parallel sub-agents for penetration testing and code review?▼

You should use parallel sub-agents for penetration testing and code review because they simultaneously probe six critical security domains, delivering a fast, comprehensive assessment of vulnerabilities and actionable findings for any codebase.