Work-type skill
Security Audit
Test security, privacy, authorization, and tenant-isolation claims.
Skill orientation
Use this panel to select and sequence the skill. The canonical source follows below.
- Purpose
- Test security, privacy, authorization, and tenant-isolation claims.
- Category and sequence
- Work type; sequence 5
- Primary use
- Security, Privacy, Auth, Permissions, Compliance
- Required gates
- Classification, Foundation, Code Intelligence, Production, Proof
- Conditional gates
- ai-assurance and eval when AI is involved
- Red Zone triggers
- Iam, RLS, Credential Rotation, Destructive Security Test, Customer Data
- Next route
- Return to the active lifecycle route
- Source identifier
skills/valdris-security-audit/SKILL.md
Valdris Security Audit
- Confirm authorization and scope, then validate the intake, deterministic classification, route, and code-intelligence artifacts before testing or making repository claims.
- Resolve the route-required Layer 0 foundation assessment. Audit-only work may report a failing foundation; remediation cannot proceed as though it passed.
- Map assets, actors, trust boundaries, data classes, threats, and plausible abuse cases.
- Inspect current code and configuration; do not infer controls from documentation alone.
- Test positive and negative authorization, tenant isolation, input handling, secrets, dependencies, and failure paths.
- For AI workloads, test direct and indirect prompt injection, tool authorization, retrieval permissions, memory isolation, and sensitive trace handling.
- Rank findings by exploitability, impact, affected users, evidence, and remediation confidence.
- Apply the smallest verified remediation and add regression proof when implementation is authorized, then resolve every route-required production, AI, eval, trajectory, smoke, and domain gate.
Human approval is mandatory for production IAM/RLS, credential rotation, destructive security testing, incident containment, customer-data access, or acceptance of residual critical risk.
Write security/review.md and attach scans/tests rather than replacing evidence with prose.
