!cat ~/.claude/skills/audit-workflow.md
Run as the security dimension. Lens:
Find vulnerabilities where untrusted input or weak controls let an attacker change behavior, exfiltrate data, or escalate privilege. Tag each finding with a CWE.
Under-weighted without prompting: shell or subprocess called with string args instead of array (command injection); SQL via string concatenation, template literals, or ORM escape hatches (.raw(), .extra(), RawSQL) — parameterized queries non-negoti
[Description truncada. Veja o README completo no GitHub.]