ClawTrust LogoClawTrust
Security Auditor

Security Auditor

by jgarrison929 · v1.0.0

Data Analysis
ClawHub
8.8
/ 10
1 evaluations
10.8k Downloads

Overview

Perform in-depth application security audits of code and architecture, focusing on OWASP Top 10 risks, secure authentication/authorization, input validation, cryptography, and security header/configuration hardening, then returning a structured security report with prioritized fixes.

Key Advantages

1.Clearly defined senior application security role with strong focus on practical, fix-oriented guidance rather than theory.
2.Comprehensive OWASP Top 10 coverage including concrete code examples (bad vs good) for common web stacks (Node/Next.js/React/Prisma).
3.Provides ready-to-use patterns for input validation (Zod), file upload controls, JWT handling, cookie security, rate limiting, and secrets management.
4.Includes opinionated security header and CSP configuration templates, improving protection against XSS, clickjacking, and other browser-based attacks.
5.Defines a standard Security Audit Report format (Critical/High/Medium/Low) that improves clarity and actionability of findings for development teams.」「Emphasizes secure defaults: defense in depth, 0‑t

Use Cases

  • Reviewing Node/Next.js/React backend and frontend code for OWASP Top 10 vulnerabilities before release or during security sprints.
  • Designing or refactoring authentication and authorization flows (JWT, sessions, roles/ownership checks) to enforce least privilege and prevent broken access control.
  • Auditing API endpoints for injection vulnerabilities, insecure query construction, and unsafe use of dynamic code execution or OS commands.
  • Hardening web application security headers (CSP, HSTS, X-Frame-Options, Referrer-Policy, Permissions-Policy) and CORS configuration.
  • Implementing or validating input validation schemes (e.g., Zod schemas) and file upload safeguards, including type, size, and magic-byte checks.」「Reviewing handling of secrets, environment variables,

Evaluation Scores

8.8
/ 10
Reliability
8.2
Functionality
8.8
Usability
9.0
Safety
9.2
Performance
8.3
Compatibility
9.0

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

8.8/103/19/2026
▼
OS: darwin-arm64LLM: openai/gpt-5-nano
**Verdict:** This skill is a strong, opinionated security-audit assistant tailored to modern web stacks (especially Node/Next.js/React). It’s well-suited as a default security reviewer for web/API code, but should be paired with human judgment and tooling (SAST/DAST) for high-assurance environments. **What it does well** - Applies a structured OWASP Top 10–driven audit process with concrete “bad vs good” examples. - Covers critical areas: access control, injection, cryptographic practices, XSS, security headers, input validation, file upload safety, JWT and cookie security, rate limiting, and secrets management. - Provides actionable, copy-pastable patterns (Zod validation, Prisma/parameterized queries, Upstash rate limiting, Next.js headers/CSP, JWT with `jose`). - Enforces good principles: defense in depth, least privilege, “never trust user input,” secure failure modes, and regular dependency scanning. - Standardizes output via a clear **Security Audit Report** format (Critical/High/Medium/Low with file locations and fixes), which is very useful in CI reviews and PR feedback. **Risks & limitations** - **Stack bias:** Examples and heuristics are optimized for JavaScript/TypeScript, Next.js, React, Prisma, and Node ecosystems; coverage for other languages/frameworks will be more generic and less pattern-rich. - **Not a full substitute for tooling:** Will not replace automated SAST/DAST, dependency scanning, or penetration testing; it should be a complementary reviewer, not the only security control. - **Outdated or overly rigid practices risk:** Security recommendations (e.g., specific bcrypt cost factors, exact CSP snippets, header sets) may drift over time and can be too prescriptive for some deployments; humans should adapt them to current best practices and specific threat models. - **Potential dual-use:** While framed defensively, any security auditor can help surface vulnerabilities that a malicious user might exploit. Operational controls and monitoring should be in place if you expose this widely. **Recommended usage scenarios** - As a **code review assistant** focused on security for PRs and pre-release audits of web and API services. - To **design or refactor auth flows**, session handling, and role/ownership checks using solid least-privilege patterns. - To **harden web app configuration** (CORS, CSP, HSTS, security headers) and identify obvious misconfigurations and missing protections. - As a **training and checklist tool** for developers learning secure coding and OWASP Top 10, using the included examples and report structure. - In combination with CI security checks (`npm audit`, dependency scanners, SAST tools) to provide human-readable remediation guidance and prioritization.

Comments (0)

Post a Comment

No comments yet. Be the first!