Coding & Development
🤖 Manus
Free
AI Agent
Automation
Open Source
Security Audit & Hardening Skill
A defensive security audit skill for apps you own: scans headers, cookies, leaked secrets, vulnerable dependencies, code flaws, and containers — then fixes issues in safe order and writes an AI-executable fix plan plus a human-readable brief.
(0)
0 salesDescription
Security Audit & Hardening Skill — Mahara AI
A structured, defensive security workflow for software you own or are authorized to test. It runs what can be run locally through the coding agent, uses TestSprite (via MCP) for live functional and access-control testing when available, fixes what it safely can, and ends with two deliverables: an AI Fix Plan precise enough for another agent to execute step by step, and a Human Brief the owner can read in two minutes.
How it works — 8 phases:
1. Intake: repo and/or live URL, ownership confirmation, depth level (Essentials / Standard / Strict), and skips. Pastes external audit reports (Rafter, securityheaders.com, Snyk) and tracks each item to fixed.
2. Recon: detects stack, package managers, hosting config, and which scanners are installed. Writes a short threat model.
3. Scans by depth: security headers and cookies, leaked secrets in code and git history (Gitleaks), vulnerable packages (npm audit, OSV-Scanner, Trivy), code scan (Semgrep), manual code review, passive OWASP ZAP, TestSprite functional/authz tests, container/IaC checks, and SBOM.
4. Triage: merges duplicates, rates severity for your app's context, marks confidence, assigns stable IDs.
5. Fix in safe order: leaked secrets first (you rotate keys), then critical code issues, then headers. Runs build and tests after each batch.
6. Verify: re-runs each specific check and records before/after evidence.
7. Report: SECURITY_FIX_PLAN.md (AI-executable, English) + findings.json + SECURITY_BRIEF.md (human-readable, user's language).
8. Maintenance: GitHub Actions CI workflow, Dependabot config, recurring re-run scheduling.
Ground rules: defensive only (no exploit code), staging over production for active scans, secrets never printed in full, CSP rolled out in Report-Only first.
Built by Hossamudin Hassan — Mahara AI (maharaai.com).
Reviews (0)
No reviews yet
Free