Security TDD — Security skill for Claude Code
SECURITY phase - Comprehensive OWASP Top 10 security audit and remediation with automatic report storage in sprintdag directory.
How to install Security TDD
Installs to ~/.claude/commands/toonvos-empty-opensaas-security-tdd.md
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/ToonVos/empty-opensaas/HEAD/.claude/commands/security-tdd.md -o ~/.claude/commands/toonvos-empty-opensaas-security-tdd.md Restart Claude Code, or start a new session, for it to be picked up.
What Security TDD does
SECURITY phase - Comprehensive OWASP Top 10 security audit and remediation with automatic report storage in sprintdag directory.
Alternatives in Security
- Free Code — The free build of Claude Code 8.1k ★
- Engage.Exploit — Execute Phase 4 - Exploitation and Access Establishment 348 ★
- Cross-Pollinate Hex MCP Servers — Diff-driven audit: find real transferable changes across hex-line-mcp, hex-ssh-mcp, hex-graph-mcp 238 ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Audit Pipelines
TDD-validated audit-grade decision pipelines - canonical encoding (RFC 8785 JCS), append-only decision logs, f
Migration Audit
Safety review of pending Supabase / Postgres migrations: destructive ops, locking impact on large tables, miss
Senior Engineering Partner
A stack-agnostic Claude Code skill: strict code reviewer, pair programmer, debugger, and mentor (Python/Bash/A
Adversarial Testing
Use when authoring evals/predicates (Scout, TDD-Engineer), framing an audit (Auditor), or justifying which pha
Audit Deadcode
Comprehensive dead code audit — finds all unused files, functions, classes, and variables by walking the call
Dotnet Refactor
Phase-gated refactoring/design loop - session-blind subagents build the map and traces, empirical probes prece
Related Agents
Security Audit Agent
자바 코드 보안 취약점 검증 전문. Refactor 작업 직후 또는 git commit 직전 호출. OWASP Top 10 + Secret Scan (trufflehog/ggshield) + Pro
Documentation Keeper
Use this agent when:\n\n1. After Feature Completion: A new feature file appears in features/ directory with st
Security Sentinel
Deep security review focused on OWASP Top 10, injection, auth/authz, data exposure, and dependency vulnerabili