Security Audit
Conducts comprehensive security assessments and vulnerability remediation for PHP applications following OWASP guidelines and CVSS risk scoring.
The source repository doesn't declare a license. Check its terms before reusing the code.
Key features
- CVSS v3.1 risk scoring and prioritization methodology
- Comprehensive security hardening checklists for authentication and data protection
- OWASP Top 10 vulnerability detection patterns
- Context-aware output encoding and input validation strategies
- Secure PHP coding patterns for SQLi, XSS, and XXE prevention
Use cases
- Calculating CVSS scores for identified vulnerabilities to prioritize remediation efforts
- Performing a security audit on legacy or modern PHP codebases
- Implementing secure input validation and output encoding to prevent XSS and SQLi
FAQ
How does this skill improve my security workflow?
It transforms Claude into a security-first pair programmer. Instead of just finding bugs, the skill helps you calculate risk impacts using standardized CVSS scores and provides immediate, context-aware remediation code snippets.
When should I use this skill?
Use this skill during code reviews, before deploying new features, or when auditing legacy PHP codebases. It is particularly effective for identifying complex logic flaws and ensuring compliance with modern security standards.
Does it support modern PHP versions?
Yes, the skill includes patterns for PHP 8.0+ security improvements, such as updated libxml handling and type-safe data processing, as well as secure usage of frameworks like Doctrine and Twig.
What does the Security Audit skill do?
This skill equips Claude Code with expert patterns to identify security vulnerabilities in PHP applications. It follows OWASP guidelines to detect issues like SQL injection, XSS, and XXE while providing CVSS v3.1 risk scoring for prioritization.
What specific vulnerabilities can this skill detect?
The skill focuses on the OWASP Top 10, including XML External Entity (XXE) injection, Cross-Site Scripting (XSS), SQL injection (SQLi), CSRF protection flaws, and insecure session management patterns.
Related skills
Claude Configuration Validator
Validates Claude Code configuration files for security vulnerabilities, structural integrity, and prompt engineering quality.
Security Testing12312 ptsReact Native Security Audit
Identifies security vulnerabilities, sensitive data leaks, and insecure implementation patterns in React Native applications across both JavaScript and native code layers.
Security Testing12 pts