security-audit

Audit dependencies, CI/CD pipelines, and infrastructure for security gaps.

Updated Apr 20, 2026
One-click install
npx skills add https://github.com/sennett-lau/alice --skill security-audit-sennett-lau
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: security-audit
Source: https://github.com/sennett-lau/alice/tree/main/framework/skills/security-audit
Command: npx skills add https://github.com/sennett-lau/alice --skill security-audit-sennett-lau

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Chief Security Officer mode for infrastructure-first security auditing: secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, and skill supply chain scanning. It provides OWASP Top 10, STRIDE threat modeling, and active verification with daily and comprehensive modes to track trends across runs.

Core Features & Use Cases

  • Threat modeling and risk-based security posture assessments across code, pipelines, and infrastructure.
  • Integrated coverage of dependencies, secrets hygiene, CI/CD security, and supply chain integrity.
  • Actionable Security Posture Reports with remediation plans and executive-ready findings.
  • Use Case: A CSO or security engineer runs daily checks to surface high-severity issues before deployment.

Quick Start

Run the security-audit skill to generate a Security Posture Report for your project.

Frequently Asked Questions about security-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a security audit on my codebase and CI/CD pipeline?▼

Run the security audit to generate a Security Posture Report by scanning your dependencies, CI/CD pipelines, and infrastructure, mapping the attack surface and detecting secrets archaeology issues.

What is STRIDE threat modeling and how does it apply to infrastructure security?▼

STRIDE threat modeling is a framework for identifying security threats across code and infrastructure, applied here alongside OWASP Top 10 checks to assess risk posture and prioritize remediation for deployment pipelines.

Can I use this security audit for zero-trust posture and supply chain analysis?▼

Yes, this security audit supports zero-trust posture requirements by performing dependency supply chain analysis, secrets hygiene checks, and CI/CD security checks across your codebase and deployment pipelines.

What's the best way to identify high-severity security gaps before deployment?▼

Run daily security audit checks to surface high-severity issues before deployment, tracking trends across runs with actionable remediation plans and executive-ready findings.

Does this audit cover LLM and AI security vulnerabilities in my stack?▼

Yes, the security audit includes LLM and AI security scanning as part of its comprehensive coverage, alongside skill supply chain scanning and infrastructure-first security checks.

When do I need a comprehensive security posture assessment with OWASP coverage?▼

You need a comprehensive security posture assessment with OWASP coverage when deploying codebases requiring zero-trust posture, mapping attack surfaces, and verifying remediation across phases 0 through 14.