Security Audit Pipeline
Developer Official v1.0.13Scan code for vulnerabilities, categorise findings by OWASP type, prioritise by severity, and produce a remediation roadmap
by skrptiq
Sign in to import this skrpt into your workspace.
Sign inWhat's included 20 nodes
Security Audit Pipeline
Orchestrates a full security audit: scan for vulnerabilities, categorise by OWASP type, assess severity, plan remediation, and produce an executive report
Brief Compliance Check
Checks output against its stated brief — required sections, constraints, and missing deliverables
Consistency Check
Checks naming, terminology, tense, voice, style, and internal coherence across a document
Executive Reporting
Produces an executive summary and detailed technical findings report for separate audiences
Finding Categorisation
Groups scan findings by OWASP Top 10 category for structured analysis and reporting
Language Polish
Spelling, grammar, punctuation, sentence clarity, and minor wording cleanup
Remediation Planning
Generates specific fix recommendations per finding with code examples, effort estimates, and dependency mapping
Severity Assessment
Rates each finding by severity using CVSS-like criteria: exploitability, impact, and affected scope
Vulnerability Scanning
Scans codebase for security vulnerabilities including injection flaws, authentication issues, exposed secrets, and insecure configurations
Assess Severity
Rates each categorised finding by severity using structured exploitability, impact, and scope criteria
Categorise Findings
Groups raw scan findings into OWASP Top 10 categories for structured analysis
Check Brief Compliance
Verifies output meets all requirements from the original brief
Check Consistency
Checks naming, terminology, tense, voice, and internal coherence across a document
Plan Remediation
Generates specific fix recommendations with code examples, effort estimates, and dependency mapping
Polish Language
Corrects spelling, grammar, punctuation, and improves sentence clarity
Scan Vulnerabilities
Instructs the LLM to perform a comprehensive vulnerability scan of the target codebase
Write Executive Report
Produces a two-part audit report: executive summary for leadership and detailed technical findings for engineers
LLM Service
Language model service for analysis, synthesis, and document generation
OWASP Top 10 Reference
Reference card listing the OWASP Top 10 2021 categories with descriptions and common examples
Security Finding Template
Structured template for documenting individual security findings consistently across the audit
Requirements 1 service, 2 permissions, 3 data types
- LLM Service
- filesystem:read
- shell:execute
- source code
- pii
- credentials
Security Passed
Detected
- Services:
- Permissions: shell:execute
- Data Handling: pii
Version history 5 releases
Automated release v1.0.13
Automated release v1.0.12
Automated release v1.0.11
Automated release v1.0.10
Automated release v1.0.8
More from Developer
View all →Code Review Pipeline
Automated PR review with style checking, security scan, and structured feedback
Webapp Testing Pipeline
Plan test cases, write and execute tests, report failures, and fix issues in an automated cycle
Sprint Wrapup Pipeline
Summarises sprint retrospective notes and extracts action items for the next sprint