Skip to harness content
Open technical reference map

Work-type skill

Security Audit

Test security, privacy, authorization, and tenant-isolation claims.

valdris-security-auditOwning system: Active lifecycle owner

Skill orientation

Use this panel to select and sequence the skill. The canonical source follows below.

Purpose
Test security, privacy, authorization, and tenant-isolation claims.
Category and sequence
Work type; sequence 5
Primary use
Security, Privacy, Auth, Permissions, Compliance
Required gates
Classification, Foundation, Code Intelligence, Production, Proof
Conditional gates
ai-assurance and eval when AI is involved
Red Zone triggers
Iam, RLS, Credential Rotation, Destructive Security Test, Customer Data
Next route
Return to the active lifecycle route
Source identifier
skills/valdris-security-audit/SKILL.md
Canonical pathskills/valdris-security-audit/SKILL.mdRevision69bab1cInspect source

Valdris Security Audit

  1. Confirm authorization and scope, then validate the intake, deterministic classification, route, and code-intelligence artifacts before testing or making repository claims.
  2. Resolve the route-required Layer 0 foundation assessment. Audit-only work may report a failing foundation; remediation cannot proceed as though it passed.
  3. Map assets, actors, trust boundaries, data classes, threats, and plausible abuse cases.
  4. Inspect current code and configuration; do not infer controls from documentation alone.
  5. Test positive and negative authorization, tenant isolation, input handling, secrets, dependencies, and failure paths.
  6. For AI workloads, test direct and indirect prompt injection, tool authorization, retrieval permissions, memory isolation, and sensitive trace handling.
  7. Rank findings by exploitability, impact, affected users, evidence, and remediation confidence.
  8. Apply the smallest verified remediation and add regression proof when implementation is authorized, then resolve every route-required production, AI, eval, trajectory, smoke, and domain gate.

Human approval is mandatory for production IAM/RLS, credential rotation, destructive security testing, incident containment, customer-data access, or acceptance of residual critical risk.

Write security/review.md and attach scans/tests rather than replacing evidence with prose.