From nickcrew-claude-ctx-plugin
Executes multi-phase security audits: threat modeling, automated scans (npm audit, semgrep, trufflehog), manual reviews, pentesting, remediation, and OWASP/GDPR compliance checks.
npx claudepluginhub nickcrew/claude-cortexThis skill uses the workspace's default tool permissions.
Comprehensive security assessment process.
Audits code for security vulnerabilities including OWASP Top 10, auth flaws, injection, data exposure, and dependency risks using STRIDE threat modeling and phased reviews.
Orchestrates parallel security audits with dependency scanning (pip-audit, npm audit), SAST pattern detection, and auth/config reviews. Consolidates into OWASP-mapped severity reports.
Identifies security vulnerabilities in code and infrastructure, generates structured audit reports with severity ratings and remediation guidance. Use for SAST scans, pen testing, secrets scanning, DevSecOps, and compliance checks.
Share bugs, ideas, or general feedback.
Comprehensive security assessment process.
Agents: security-auditor
Scope:
Output: Threat model, risk assessment, priority list
Agents: security-auditor
Tools to run:
Output: Vulnerability report with severity ratings
Agents: security-auditor
Focus areas:
Agents: security-auditor
Test for:
Agents: requirements-analyst
Blocking: Validation required before proceeding
Agents: security-auditor
Agents: technical-writer
Agents: security-auditor
Standards:
| Level | Response Time | Examples |
|---|---|---|
| Critical | Immediate | RCE, auth bypass, data breach |
| High | 24-48h | SQL injection, privilege escalation |
| Medium | 1 week | XSS, CSRF, information disclosure |
| Low | Next sprint | Best practice violations |