Agent Skill trust card
Security Audit
Addy Osmani / addyosmani.web-quality-skills.security-audit · recorded version or snapshot 1.0
Systematically identify injection flaws, broken auth, IDOR, secrets exposure, and dependency vulnerabilities in web projects.
Metadata reviewed Elevated access
Source and identity
- Publisher
- Addy Osmani
- Namespace
- addyosmani.web-quality-skills.security-audit
- Recorded version / snapshot
- 1.0
- License
- MIT
- Artifact SHA-256
- Not recorded — a source snapshot alone does not pin an artifact
- Source repository
- https://github.com/addyosmani/web-quality-skills
Declared access
Review every permission against your own environment and least-privilege policy.
- read-write:user-selected-web-project
- process:actions-declared-by-skill-host
Required secrets
Generated examples use placeholders. Never paste real secrets into ToolDix.
No required secrets are declared in the current metadata.
Compatibility and connection
Clients
- Codex
- Claude
- Cursor
- OpenClaw
Runtimes
- portable-skill-host
Transports
- skill
Authentication
No authentication method is recorded.
Evidence
- Canonical source
canonical · observed Jul 15, 2026