Artifact: Security audit report

A vulnerability and threat-model assessment of a change: input handling / injection vectors, authentication & authorization (including IDOR), data protection and secrets, dependency CVEs, scored against the OWASP Top 10. Prioritizes practical, exploitable issues over theoretical risk, each with a recommended mitigation.

  • addy-security — the security-and-hardening skill.

  • addy-security-auditor — the Security-Engineer persona (also in the /ship fan-out).

  • ce-security-sentinel — Compound Engineering’s attacker-minded security auditor (also mines security lessons for ce-compound).

  • gstack-cso — gstack’s Chief Security Officer: OWASP Top 10 + STRIDE audit with concrete exploit scenarios.

See Also