Auditing

Auditing taxonomy generated by the site skill importer.

12 skills
A
information-security-manager-iso27001

by alirezarezvani

The information-security-manager-iso27001 skill helps AI agents perform ISO 27001:2022 ISMS work for HealthTech, MedTech, and regulated software teams. Use it for risk assessment, Annex A control mapping, compliance review, evidence checklists, incident response planning, and audit gap analysis with included references and scripts.

Compliance Review
Favorites 0GitHub 22.2k
A
iso27001-audit-prep

by alirezarezvani

iso27001-audit-prep is a focused ISO 27001 ISMS audit readiness skill. It uses six forcing questions to pressure-test scope, risk register freshness, Annex A linkage, management review, corrective actions, and sample-ready evidence before internal, certification, or surveillance audits.

Compliance Review
Favorites 0GitHub 22.1k
A
soc2-audit-prep

by alirezarezvani

soc2-audit-prep is a SOC 2 Type II compliance review skill that runs six observation-period forcing questions via /cs:soc2-audit-prep <scope>. Use it to pressure-test scope, TSC choices, skipped control cycles, evidence gaps, incidents, and audit readiness before fieldwork.

Compliance Review
Favorites 0GitHub 22.1k
A
compliance-os

by alirezarezvani

compliance-os is a multi-framework compliance orchestration skill for Compliance Review. Use it to assess framework applicability, map control overlap, prioritize reusable evidence, and simulate mock internal audits with JSON templates and Python helper scripts.

Compliance Review
Favorites 0GitHub 22.1k
A
seo-drift

by AgriciDaniel

seo-drift is a GitHub skill for tracking SEO-critical page elements over time, comparing baselines, and catching regressions after deploys, CMS edits, or template changes. Use the seo-drift skill for SEO Content, technical on-page checks, and practical seo-drift usage when you need a clear answer to whether anything broke.

SEO Content
Favorites 0GitHub 6.2k
T
constant-time-testing

by trailofbits

constant-time-testing is a practical skill for auditing cryptographic code for timing side channels. Use the constant-time-testing skill to inspect secret-dependent branches, memory access patterns, and microarchitectural behavior, then apply a focused constant-time-testing guide for Security Audit workflows.

Security Audit
Favorites 0GitHub 5k
T
semgrep

by trailofbits

Semgrep skill for static analysis on codebases with automatic language detection, parallel workers, merged SARIF output, and plan-first approval. Built for semgrep for Security Audit workflows, it supports run all and important only modes, uses --metrics=off, and can leverage Semgrep Pro when available.

Security Audit
Favorites 0GitHub 5k
T
codeql

by trailofbits

The codeql skill helps you run CodeQL with fewer blind spots during a security audit. It focuses on database quality, suite selection, data extensions, and SARIF review so you can use codeql usage more reliably across supported languages. Use it for repeatable codeql guide steps when analyzing real repositories.

Security Audit
Favorites 0GitHub 5k
T
constant-time-analysis

by trailofbits

constant-time-analysis is a security-audit skill for finding timing side-channel risks in cryptographic code before they become exploitable bugs. Use it to review secret-dependent math, branches, comparisons, and compiled output when checking C, C++, Go, Rust, Swift, Java, Kotlin, PHP, JavaScript, TypeScript, Python, or Ruby.

Security Audit
Favorites 0GitHub 5k
T
ton-vulnerability-scanner

by trailofbits

ton-vulnerability-scanner is a focused audit skill for TON smart contracts written in FunC. It helps identify integer-as-boolean misuse, fake Jetton contract handling, and missing gas checks when forwarding TON. Use it for a fast first-pass Security Audit before deeper manual review.

Security Audit
Favorites 0GitHub 5k
T
substrate-vulnerability-scanner

by trailofbits

substrate-vulnerability-scanner helps audit Substrate and FRAME pallets for critical issues like arithmetic overflow, panic DoS, bad origin checks, incorrect weights, and unsafe unsigned extrinsics. Use this substrate-vulnerability-scanner skill for Security Audit reviews of runtimes, pallet extrinsics, and weight logic.

Security Audit
Favorites 0GitHub 5k
T
guidelines-advisor

by trailofbits

guidelines-advisor is a smart contract development advisor based on Trail of Bits best practices. It analyzes a codebase to generate documentation, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Use the guidelines-advisor guide for clear, evidence-based recommendations.

Technical Writing
Favorites 0GitHub 4.9k
Auditing