A professional security audit framework that covers 55+ vulnerability types across nine languages, backed by 88,000+ real-world cases from WooYun. This runs three scan modes: quick for CI/CD pipelines, standard for OWASP Top 10 coverage, and deep for full penetration testing prep with multi-agent parallel execution. The execution controller enforces mandatory checkpoints at each phase to prevent both false positives and confirmation bias, two problems that plague automated security tools. It uses LSP-enhanced taint analysis and includes Docker sandbox verification for exploitability confirmation. The checklist system is notable for being verification-driven rather than search-driven, meaning it audits first then checks coverage gaps instead of just pattern matching known vulnerabilities. Serious tooling for teams that need reproducible security assessments.
npx -y skills add 3stonebrother/code-audit --skill code-audit --agent claude-codeInstalls to .claude/skills
Select a file.
giuseppe-trisciuoglio/developer-kit