From spec-driven-workflow
Auditoria de seguranca sistematica. Scan, triage, remediate, re-scan. Cobre OWASP Top 10, dependencias vulneraveis e concerns do projeto. Ativado por: /security-audit, "auditoria seguranca", "vulnerabilidade", "OWASP", "CVE".
npx claudepluginhub souzalemos/spec-driven-workflow --plugin spec-driven-workflowThis skill uses the workspace's default tool permissions.
4 fases com artefatos em .spec/workflows/audits/.
Provides Ktor server patterns for routing DSL, plugins (auth, CORS, serialization), Koin DI, WebSockets, services, and testApplication testing.
Conducts multi-source web research with firecrawl and exa MCPs: searches, scrapes pages, synthesizes cited reports. For deep dives, competitive analysis, tech evaluations, or due diligence.
Provides demand forecasting, safety stock optimization, replenishment planning, and promotional lift estimation for multi-location retailers managing 300-800 SKUs.
4 fases com artefatos em .spec/workflows/audits/.
npm audit / pip audit / equivalente.spec/workflows/audits/SCAN-RESULTS.md com todos os findingsfix(security): [descricao].spec/workflows/audits/AUDIT-REPORT.md: