App Security Auditor

security-auditor

Scans for OWASP Top 10 vulnerabilities, XSS, CSRF, injection, and auth leaks.

Where it installs

# .claude/agents/security-auditor.md
---
name: security-auditor
description: ...
tools: Read, Glob, Grep, Skill, Bash, WebFetch, WebSearch, TodoWrite
model: opus
---

What it does

App Security Auditor is a Cursor agent playbook named security-auditor. AgenticKit installs it so a session can adopt this role instead of acting as a generic coding assistant.

The security-auditor agent performs thorough static analysis on your code to detect SQL injection, Cross-Site Scripting (XSS), insecure direct object references (IDOR), secret leaks, and unauthenticated routes before you push to production.

Scans for OWASP Top 10 vulnerabilities, XSS, CSRF, injection, and auth leaks. Security auditor agent for Cursor that inspects code for vulnerabilities, sanitizes inputs, enforces CORS headers, and audits dependencies.

Why it exists

A pile of agent files is not a team. security-auditor exists so one job, app security auditor, has a written brief, required skills, and a stop condition.

It ships in the Engineering Kit. Skills it must read: Web Security Fundamentals & OWASP Defense; SOC2 Compliance & Data Privacy Controls; Authentication & Session Security Patterns; Resilient Error Handling & Fault Tolerance. Commands that adopt this role: /audit: Codebase Quality & Security Auditor; /compliance-audit: GDPR & SOC2 Privacy Compliance Auditor; /fix: Automated Bug & Exception Debugger.

When to use it

  • Pre-deployment security reviews and vulnerability scans
  • Auditing user permissions and tenant data isolation
  • Sanitizing user inputs and configuring secure HTTP headers

When not to use it

  • Do not ask security-auditor to do a different role's job. If you need a launch post, switch agents.
  • Do not keep the same chat after this agent has finished its artifact. Start a reviewer in a new thread.
  • Do not invoke every agent in the kit for a small change.

Example workflow

  1. Install the Engineering Kit so .cursor/agents/security-auditor is on disk.
  2. Run /audit: Codebase Quality & Security Auditor, or start a chat and tell Cursor to adopt the security-auditor role.
  3. The agent should read: Web Security Fundamentals & OWASP Defense; SOC2 Compliance & Data Privacy Controls; Authentication & Session Security Patterns; Resilient Error Handling & Fault Tolerance.
  4. It produces the artifact for this role only, then stops.
  5. A different agent or you review. Same-chat self-review is not a review.

Example usage

Example: "You are security-auditor. Pre-deployment security reviews and vulnerability scans. Read security-basics before you edit."

Or let the pipeline invoke it: /audit: Codebase Quality & Security Auditor.

Capabilities you should actually see: OWASP Top 10 vulnerability detection and remediation

Example output

  • security-auditor should leave files or a written verdict, not a vibe check. OWASP Top 10 vulnerability detection and remediation API route authentication and authorization boundary checks
  • Engineering agents should touch the slice they were given (schema, route, test, or review note) and nothing else.

Best practices

  • OWASP Top 10 vulnerability detection and remediation
  • API route authentication and authorization boundary checks
  • Environment variable and API secret leakage prevention
  • Content Security Policy (CSP) and CORS configuration
  • One role per chat unless a command is explicitly orchestrating a sequence.

Common mistakes

  • Using security-auditor as a synonym for 'the Cursor agent'. It is a brief, not the product.
  • Skipping the required skills and hoping the role name is enough.
  • Letting the writer approve its own PR.
  • Invoking this agent and three unrelated ones in the same prompt.

Frequently asked questions

  • What is the security-auditor Cursor agent?
    App Security Auditor: Security auditor agent for Cursor that inspects code for vulnerabilities, sanitizes inputs, enforces CORS headers, and audits dependencies.
  • When should I invoke security-auditor?
    Pre-deployment security reviews and vulnerability scans Auditing user permissions and tenant data isolation Sanitizing user inputs and configuring secure HTTP headers
  • What skills does security-auditor use?
    Web Security Fundamentals & OWASP Defense; SOC2 Compliance & Data Privacy Controls; Authentication & Session Security Patterns; Resilient Error Handling & Fault Tolerance
  • How do I run security-auditor in Cursor?
    Run /audit: Codebase Quality & Security Auditor or /compliance-audit: GDPR & SOC2 Privacy Compliance Auditor or /fix: Automated Bug & Exception Debugger, or start a chat and adopt the security-auditor role.
  • Is security-auditor the same as Cursor's built-in Agent?
    No. Cursor Agent is the product harness. This file is a specialist brief you install so that harness takes a named role.

Install security-auditor with the rest of the team

46 agents, 61 skills, and 47 slash commands, installed into .cursor/ and .claude/. Engineering and marketing kits, one license.