Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.
.claude/skills/davila7-security-audit/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-04 | ✗→✓ | ▲ Improved | 81% | 0% |
| case-05 | ✗→✓ | ▲ Improved | -12% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 11% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 65% | 0% |
| case-08 | ✗→✓ | ▲ Improved | 49% | 0% |
Comprehensive security auditing workflow for web applications, APIs, and infrastructure. This bundle orchestrates skills for penetration testing, vulnerability assessment, security scanning, and remediation.
Use this workflow when:
scanning-tools - Security scanningshodan-reconnaissance - Shodan searchestop-web-vulnerabilities - OWASP Top 10Use @scanning-tools to perform initial reconnaissanceUse @shodan-reconnaissance to find exposed servicesvulnerability-scanner - Vulnerability analysissecurity-scanning-security-sast - Static analysissecurity-scanning-security-dependencies - Dependency scanningUse @vulnerability-scanner to scan for OWASP Top 10 vulnerabilitiesUse @security-scanning-security-dependencies to audit dependenciestop-web-vulnerabilities - OWASP vulnerabilitiessql-injection-testing - SQL injectionxss-html-injection - XSS testingbroken-authentication - Authentication testingidor-testing - IDOR testingfile-path-traversal - Path traversalburp-suite-testing - Burp Suite testingUse @sql-injection-testing to test for SQL injection vulnerabilitiesUse @xss-html-injection to test for cross-site scriptingUse @broken-authentication to test authentication securityapi-fuzzing-bug-bounty - API fuzzingapi-security-best-practices - API securityUse @api-fuzzing-bug-bounty to fuzz API endpointspentest-commands - Penetration testing commandspentest-checklist - Pentest planningethical-hacking-methodology - Ethical hackingmetasploit-framework - MetasploitUse @pentest-checklist to plan penetration testUse @pentest-commands to execute penetration testingsecurity-scanning-security-hardening - Security hardeningauth-implementation-patterns - Authenticationapi-security-best-practices - API securityUse @security-scanning-security-hardening to harden application securityreporting-standards - Security reportingdevelopment - Secure development practiceswordpress - WordPress securitycloud-devops - Cloud securitytesting-qa - Security testing| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-21 | pass→pass | 14,960 | 13,073 | -13% | 1 | 1 | 0% | 2,546 | 3,507 | +38% | 0 | 0 | — |
case-22 | pass→pass | 7,402 | 8,848 | +20% | 1 | 1 | 0% | 1,320 | 2,884 | +118% | 0 | 0 | — |
case-01 | fail→fail | 18,863 | 20,076 | +6% | 1 | 1 | 0% | 2,448 | 3,749 | +53% | 0 | 0 | — |
case-02 | fail→fail | 17,826 | 24,922 | +40% | 1 | 1 | 0% | 2,020 | 3,444 | +70% | 0 | 0 | — |
case-03 | fail→fail | 16,024 | 23,065 | +44% | 1 | 1 | 0% | 2,669 | 4,196 | +57% | 0 | 0 | — |
case-04 | fail→pass | 13,468 | 13,020 | -3% | 1 | 1 | 0% | 1,276 | 2,315 | +81% | 0 | 0 | — |
case-05 | fail→pass | 11,395 | 4,351 | -62% | 1 | 1 | 0% | 2,151 | 1,893 | -12% | 0 | 0 | — |
case-06 | fail→pass | 11,663 | 6,129 | -47% | 1 | 1 | 0% | 1,964 | 2,172 | +11% | 0 | 0 | — |
case-07 | fail→pass | 7,211 | 4,501 | -38% | 1 | 1 | 0% | 1,167 | 1,925 | +65% | 0 | 0 | — |
case-08 | fail→pass | 8,126 | 3,716 | -54% | 1 | 1 | 0% | 1,243 | 1,858 | +49% | 0 | 0 | — |
case-09 | fail→pass | 14,004 | 7,636 | -45% | 1 | 1 | 0% | 1,197 | 1,525 | +27% | 0 | 0 | — |
case-10 | fail→pass | 12,516 | 4,906 | -61% | 1 | 1 | 0% | 2,000 | 1,965 | -2% | 0 | 0 | — |
case-11 | pass→pass | 14,411 | 8,234 | -43% | 1 | 1 | 0% | 2,535 | 2,684 | +6% | 0 | 0 | — |
case-12 | pass→pass | 17,143 | 12,748 | -26% | 1 | 1 | 0% | 2,791 | 3,349 | +20% | 0 | 0 | — |
case-13 | pass→pass | 14,089 | 9,297 | -34% | 1 | 1 | 0% | 2,333 | 2,540 | +9% | 0 | 0 | — |
case-14 | pass→pass | 13,302 | 4,073 | -69% | 1 | 1 | 0% | 2,192 | 1,871 | -15% | 0 | 0 | — |
case-15 | fail→pass | 7,752 | 3,110 | -60% | 1 | 1 | 0% | 1,219 | 1,741 | +43% | 0 | 0 | — |
case-16 | fail→pass | 11,113 | 1,557 | -86% | 1 | 1 | 0% | 1,706 | 1,405 | -18% | 0 | 0 | — |
case-17 | fail→pass | 10,996 | 3,724 | -66% | 1 | 1 | 0% | 1,764 | 1,891 | +7% | 0 | 0 | — |
case-18 | pass→pass | 8,804 | 3,145 | -64% | 1 | 1 | 0% | 1,429 | 1,683 | +18% | 0 | 0 | — |
case-19 | fail→pass | 10,834 | 2,969 | -73% | 1 | 1 | 0% | 1,593 | 1,712 | +7% | 0 | 0 | — |
case-20 | pass→pass | 9,754 | 12,845 | +32% | 1 | 1 | 0% | 1,939 | 3,671 | +89% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +50 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.