Back to catalogue

Security Audit Pipeline

Developer Official v1.0.26

Scan code for vulnerabilities, categorize findings by OWASP type, prioritize by severity, and produce a remediation roadmap

by skrptiq

audit code-review owasp security vulnerability
workflow Updated 16 July 2026 13 nodes 1 download

Sign in to import this skrpt into your workspace.

Sign in
What's included 13 nodes
1 workflow 5 skills 5 prompts 1 source 1 asset
workflow (1)

Security Audit Pipeline

Orchestrates a full security audit: scan for vulnerabilities, categorize by OWASP type, assess severity, plan remediation, and produce an executive report

skills (5)

Executive Reporting

Produces an executive summary and detailed technical findings report for separate audiences

Finding Categorization

Groups scan findings by OWASP Top 10 category for structured analysis and reporting

Remediation Planning

Generates specific fix recommendations per finding with code examples, effort estimates, and dependency mapping

Severity Assessment

Rates each finding by severity using CVSS-like criteria: exploitability, impact, and affected scope

Vulnerability Scanning

Scans codebase for security vulnerabilities including injection flaws, authentication issues, exposed secrets, and insecure configurations

prompts (5)

Assess Severity

Rates each categorized finding by severity using structured exploitability, impact, and scope criteria

Categorize Findings

Groups raw scan findings into OWASP Top 10 categories for structured analysis

Plan Remediation

Generates specific fix recommendations with code examples, effort estimates, and dependency mapping

Scan Vulnerabilities

Instructs the LLM to perform a comprehensive vulnerability scan of the target codebase

Write Executive Report

Produces a two-part audit report: executive summary for leadership and detailed technical findings for engineers

source (1)

OWASP Top 10 Reference

Reference card listing the OWASP Top 10 2021 categories with descriptions and common examples

asset (1)

Security Finding Template

Structured template for documenting individual security findings consistently across the audit

Requirements 1 service, 2 permissions, 3 data types
Services
  • LLM Service
Permissions
  • filesystem:read
  • shell:execute
Data Handling
  • source code
  • pii
  • credentials
Security Passed
All checks passed v1.0.26 · scanner v3.3.0

Detected

  • Services: llm-service
  • Permissions: shell:execute
  • Data Handling: pii
Version history 15 releases
v1.0.26 latest 16 July 2026

GH#845 — republish with American English (en-US) content, completing the source-only GH#805 flip that never reached the Hub. Copy only — no functional or behaviour change.

v1.0.25 3 July 2026

GH#745 — declare per-step `output: {name, type}` on every execution step (vulnerabilities/list, categorised_findings/text, severity_assessment/text, remediation_plan/text, executive_report/text, polished_report/text, consistency_verdict/decision, compliance_verdict/decision). Lights up the #744 rich flow-map. Content-only; no bindings or logic changes.

v1.0.24 7 June 2026

Fix-forward after Row 3b v1.0.23 publish failure. The v1.0.23 per-skrpt CI's "Register version with Hub API" step failed because the consumer's source `manifest.id` (c9d5e32b…) did not match the D1 catalogue row's id (a80ac015…) — a legacy drift from before Action 6 (`0bcc5ae0`) made publish-skrpt.mjs Step 2 INSERT use `manifest.id` for the D1 id column. v1.0.24 reconciles the source `manifest.id` to the catalogue authoritative value (Row-5-equivalent for consumers) and republishes. Per Adj-1: no re-tag of v1.0.23; the orphaned GitHub release artefact stays inert (no D1 versions row, no consumer pinned it).

v1.0.22 22 May 2026

Wave 2: re-signed with canonical engine signing pipeline.

v1.0.19 19 May 2026

Signature fix — RELEASE_NOTES.md now included in integrity checksum.

v1.0.18 19 May 2026

Initial catalogue release with full structural and content-quality validation. All scanner checks pass.

v1.0.17 18 May 2026

Release notes unavailable for this version.

v1.0.16 14 May 2026

Release notes unavailable for this version.

v1.0.15 14 May 2026

Release notes unavailable for this version.

v1.0.14 13 May 2026

Release notes unavailable for this version.

v1.0.13 11 May 2026

Release notes unavailable for this version.

v1.0.12 27 April 2026

Release notes unavailable for this version.

v1.0.11 25 April 2026

Release notes unavailable for this version.

v1.0.10 16 April 2026

Release notes unavailable for this version.

v1.0.8 13 April 2026

Release notes unavailable for this version.

More from Developer

View all →

Send feedback

Sign in to send feedback — it lets us follow up and keeps the tracker free of spam.