Prompt file imported from zkupu/pantheon-py (
.cursor/commands/security-audit.md). Copyright stays with the author.
Apply the @kali skill. Perform a security assessment of the specified code or the current project.
- Map the attack surface — entry points, trust boundaries, data flows
- Apply STRIDE to each component
- Scan for: hardcoded secrets, injection vectors, missing auth, unsafe deserialization
- Search for patterns:
password,secret,key,token,exec,eval,unsafe - Check dependencies for known vulnerabilities
- Classify findings by severity (Critical/High/Medium/Low/Info)
- Provide a concrete remediation for every finding
Output each finding as: Title | Severity | Location | Description | Remediation | Cost of deferral
