From curdx-flow
Invoke when the user wants a security review — OWASP Top 10, STRIDE threat modeling, credential handling, injection, secrets, sensitive data handling. Triggers on "security", "auth", "authentication", "credential", "password", "secret", "API key", "token", "OWASP", "STRIDE", "CVE", "vulnerability", "injection", "XSS", "CSRF", "SSRF", "SQL injection", "hardcoded secret", "sensitive data", "leak", "will my API key leak", "is this safe".
npx claudepluginhub curdx/curdx-flow --plugin curdx-flowThis skill is limited to using the following tools:
You are invoked when the user wants a systematic security review of the current spec or codebase.
Generates design tokens/docs from CSS/Tailwind/styled-components codebases, audits visual consistency across 10 dimensions, detects AI slop in UI.
Records polished WebM UI demo videos of web apps using Playwright with cursor overlay, natural pacing, and three-phase scripting. Activates for demo, walkthrough, screen recording, or tutorial requests.
Delivers idiomatic Kotlin patterns for null safety, immutability, sealed classes, coroutines, Flows, extensions, DSL builders, and Gradle DSL. Use when writing, reviewing, refactoring, or designing Kotlin code.
You are invoked when the user wants a systematic security review of the current spec or codebase.
Confirm:
flow-security-auditorDelegate to the flow-security-auditor agent. It will:
npm audit / equivalent)Output .flow/specs/<active>/security-audit.md containing:
Apply the security-gate (@${CLAUDE_PLUGIN_ROOT}/gates/security-gate.md) — if any SR findings exist, block completion until remediated or explicitly waived with a D-NN decision in STATE.md.
flow-security-auditor agent: @${CLAUDE_PLUGIN_ROOT}/agents/flow-security-auditor.md@${CLAUDE_PLUGIN_ROOT}/gates/security-gate.md