owasp-bsi-auditlisted
Install: claude install-skill silvio-l/skills
# OWASP + BSI IT-Grundschutz Audit
Audits like a human auditor would — only automated and more thorough: every control assessed individually, every verdict justified. The main context stays free because the actual assessment work goes to subagents that write their results to disk (see [ORCHESTRATION.md](ORCHESTRATION.md)). The BSI portion follows [BSI-Standard 200-2](BSI-METHODIK.md) — Schutzbedarf is fixed at **normal** (Basis + Standard requirements) per this skill's design.
**Report language note:** the generated `report.md`/`report.html`/`fix-plan.md` are deliberately written in **German** — BSI IT-Grundschutz is a German standard with German normative vocabulary (MUSS/SOLLTE, Basis-/Standard-Anforderungen, Umsetzungsstatus ja/teilweise/nein/entbehrlich), and the audience for a Grundschutz-Check is German-speaking. This skill's own documentation (this file and its siblings) is English per repo convention; only the report *output* is German by design.
## Flow
1. **Check catalog freshness.** Read `catalog/SOURCES.md`. Older than 90 days or a file is missing → run `python3 scripts/build_catalog.py` (fetches the latest ASVS/MASVS/BSI/SSDF/SLSA editions, see below). Briefly tell the user if a refresh ran.
2. **Confirm the target directory.** If the user didn't name a path, ask or infer it from context. Create `<repo>/.audit-tmp/`.
3. **Structure analysis.** One `Agent` call, `model: haiku`, following the prompt skeleton in ORCHESTRATION.md step 1. Result: `.audit-tmp/profi