← ClaudeAtlas

code-auditlisted

Use for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.
xAmirHamza77/ReverseOps-Skill · ★ 4 · AI & Automation · score 72
Install: claude install-skill xAmirHamza77/ReverseOps-Skill
# Source Code Security Audit ## ACTION REQUIRED (execute immediately after reading) 1. `NOW`: Read `../field-journal/precedent-pentest.md` or the code audit authorization 2. `NOW`: Confirm you have **source code/repository access** (source-less binaries → switch to an RE skill) 3. `NOW`: Identify the language stack and scope (directory/service/PR diff) 4. `NEXT`: tool-index; semgrep, etc. 5. `ACT`: Threat-model sketch → automated scanning → manual verification ## Applicable Scenarios - White-box audits, PR/differential security review - SAST with Semgrep / CodeQL / Bandit / gosec, etc. - Dangerous APIs, injection points, missing authorization, crypto misuse - Division of work with `supply-chain-security/`: this skill focuses on **first-party code logic**; supply-chain focuses on dependencies and pipelines ## Workflow ### 1. Scope & Threat Model ```text □ Trust boundaries: user input, files, deserialization, SSRF, auth middleware □ High-value assets: authentication, payments, admin panels, key handling ``` ### 2. Automated Scanning ```bash semgrep --config auto . # or a project ruleset semgrep --config p/owasp-top-ten . ``` ### 3. Manual Verification (MUST) ```text □ Every SAST hit: reachable? exploitable? false positive? □ Authorization: IDOR/privilege bypass, missing checks, broken multi-tenant isolation □ Injection: SQL/command/template/LDAP □ Crypto: hardcoded keys, ECB, custom crypto ``` ### 4. Deliverables ```text Finding: location + data flow + PoC + remedi