Artifact: Security audit report
A vulnerability and threat-model assessment of a change: input handling / injection vectors, authentication & authorization (including IDOR), data protection and secrets, dependency CVEs, scored against the OWASP Top 10. Prioritizes practical, exploitable issues over theoretical risk, each with a recommended mitigation.
Produced by (backlinks)
-
addy-security — the security-and-hardening skill.
-
addy-security-auditor — the Security-Engineer persona (also in the
/shipfan-out). -
ce-security-sentinel — Compound Engineering’s attacker-minded security auditor (also mines security lessons for ce-compound).
-
gstack-cso — gstack’s Chief Security Officer: OWASP Top 10 + STRIDE audit with concrete exploit scenarios.
See Also
- artifact-review-report · artifact-perf-audit — the sibling reports merged at
/ship. - stage-review — the stage this artifact gates.