Complete security audits with 165+ checks for web applications. Covers OWASP Top 10 2025, Supabase RLS bypass attacks (40+ vectors), SSRF detection, JWT/session security, file upload validation, CORS misconfiguration, API enumeration, Realtime channel leaks, payment security, timing attacks, supply chain security (typosquatting, install scripts, lockfile integrity), cookie/session hardening (httpOnly, secure, SameSite), and CSP header analysis. Use /security-audit:run to start.
From security-auditnpx claudepluginhub mralbertzwolle/vca-tools --plugin security-auditThis skill uses the workspace's default tool permissions.
Implements structured self-debugging workflow for AI agent failures: capture errors, diagnose patterns like loops or context overflow, apply contained recoveries, and generate introspection reports.
Designs and optimizes AI agent action spaces, tool definitions, observation formats, error recovery, and context for higher task completion rates.
Compares coding agents like Claude Code and Aider on custom YAML-defined codebase tasks using git worktrees, measuring pass rate, cost, time, and consistency.
Complete security audit with 165+ checks. Use /security-audit:run for OWASP, RLS bypass, SSRF, JWT, CORS, supply chain security, cookie hardening, CSP analysis, and more.