← ClaudeAtlas

security-auditlisted

Use when auditing code for security vulnerabilities, reviewing auth, permissions or Firestore/Storage rules, before a release or store submission, after a pentest or bug report, when handling secrets, tokens or PII, or when asked "is this secure", "find security holes", "check for vulnerabilities", or "review my rules". Deepest on Flutter + Firebase (Firestore, Storage, Cloud Functions, App Check); the method works on any stack.
vishal-mandhane/divinity · ★ 2 · API & Backend · score 75
Install: claude install-skill vishal-mandhane/divinity
# Security Audit ## Overview An audit is **an adversarial proof about a specific attack surface**, not a checklist walk. A checklist produces "no hardcoded secrets found ✅". An audit produces "signed-in user B can increment their own `reputationScore` via `PATCH /users/B` because rule line 88 blocks the field only on `diff()`, and `create` does not check it at all — here is the request, here is the result." One is a claim. The other is evidence. **The audit is only as good as its weakest surface.** A perfect review of Firestore rules is worth little if one unauthenticated callable leaks the same data. So: enumerate the whole surface first, then prove each piece, then report coverage honestly. ## The Iron Laws **1. No finding without evidence you personally read.** Every finding cites `file:line` from a file you opened in this session. Not from memory, not from a doc in the repo, not from a pattern you assume is there. If you did not read it, it does not go in the report. **2. No finding without an exploit path.** State: *who* (anonymous / any signed-in user / a specific other user / admin), *what they send*, and *what they get*. If you cannot write that sentence, you have a code smell, not a finding — file it under Hardening, not under a severity. **3. No severity without the rubric.** Severity comes from the table in this skill, not from vibes. "Feels bad" is not High. **4. Verified or labelled.** Every finding is `CONFIRMED` (you reproduced it — emulator, test, or