Full-stack security audit skill for AI coding agents. OWASP WSTG testing + infrastructure, deployment, and privacy checks. Works with Claude Code, Codex, Cursor, Gemini CLI, Copilot.
Dedicated to Ohad Cohen, a brave Israeli soldier who gave his life protecting Kibbutz Be'eri on October 7, 2023.
/plugin marketplace add miclivne/oc-security-audit
/plugin install oc-security-audit
Then run in any project:
/oc-security-audit
or just ask: "run a security audit on this project"
14 categories mapped to OWASP standards. Each answers a plain-language security question:
| # | Category | User question answered | OWASP source |
|---|---|---|---|
| 1 | DDoS / API abuse | Can someone take my app down or run up my bill? | API4:2023, WSTG-DOS |
| 2 | Hosting bypass | Can someone bypass my security layer? | WSTG-CONF-01, CONF-10 |
| 3 | User data exposure | Can someone see data they shouldn't? | API3:2023, ASVS V14 |
| 4 | Broken access control (IDOR) | Can someone access other users' data? | API1:2023, A01:2025 |
| 5 | Code injection (safety net) | Is code safe from injection? | A05:2025, WSTG-INPV |
| 6 | Supply chain | Are dependencies safe? | A03:2025 |
| 7 | Session / auth security | Can someone steal a session? | A07:2025, WSTG-SESS |
| 8 | Secret leakage | Are secrets exposed? | WSTG-CONF-04, CONF-09 |
| 9 | SSRF | Can server be tricked to fetch internal resources? | A01:2025 |
| 10 | AI/LLM risks | Is AI integration leaking user data? | LLM Top 10 2025 |
| 11 | Infrastructure config | Is production configured securely? | A02:2025, WSTG-CONF |
| 12 | Privacy / legal | Am I legally covered for user data? | ASVS V14, GDPR |
| 13 | Error handling | Does the app fail securely? | A10:2025 |
| 14 | Logging & monitoring | Will I know if someone is attacking? | A09:2025 |
The audit runs in 6 steps with progress indicators:
Step 1: DISCOVER Step 2: SELECT TESTS Step 3: SCAN
[shell script] [shel
Mine your Claude Code and Codex logs into a local you.md agent profile.
Local-first AI coding agent for VS Code & Cursor. Ollama, LM Studio & your inference fleet. Cursor-grade agent UX — offline, private, zero token cost.
A self-improving skill for AI coding agents (Claude Code, Cursor, AGENTS.md): recognize a hard-won golden path in a session and harvest it into a reusable skill/rule for next time.
Second brain for Forward Deployed Engineers. Engagement memory + 35 skills across 6 domains, all behind one @fde... Works with any AI coding agent.
Game-development Agent Skills for AI coding agents: install once and a master router loads the right skill for your engine and task. 66 original, version-pinned skills (plus a master router) in the portable SKILL.md format that runs across Claude Code, Cursor, Codex, Copilot, Gemini CLI and more, for Godot, Unity, Unreal, web and beyond.
Honey (I Shrunk the AI) by GreenPT: a cross-tool coding skill that cuts AI coding-agent token usage and LLM API costs — write less code, less prose, and denser agent-to-agent handoffs (−53%, lossless in benchmarks) with no loss of quality. Works with Claude Code, Cursor, GitHub Copilot, Codex, Gemini CLI, Windsurf, Cline & Kiro.
Workflows from the Neura Market marketplace related to this Cursor resource