← Cursor Slash Commands · ENGINEERING
/audit
Codebase Quality & Security Auditor
Scans for security vulnerabilities, dead code, slow queries, and anti-patterns.
/audit Run full security and performance audit on API route handlers and database queriesWhere it installs
# .cursor/commands/audit.md
# no frontmatter, the file opens with its H1 title# .claude/commands/audit.md
---
description: ...
argument-hint: [optional focus, e.g. security or tenant isolation]
allowed-tools: Read, Grep, Glob, Skill, TodoWrite, Task, ...
---What it does
/audit is a Cursor slash command. Type it in chat to run a saved workflow: Codebase Quality & Security Auditor.
Performs deep static analysis across the entire codebase to detect OWASP security flaws, unhandled errors, memory leaks, missing indexes, and dead code.
Scans for security vulnerabilities, dead code, slow queries, and anti-patterns. Unlike a skill, a command is something you invoke on purpose. The agent does not decide to run /audit for you.
Why it exists
Founders retype the same multi-step prompt until it rots. /audit exists so the pipeline, all 4 steps of it, is a file in .cursor/commands, versioned with the repo.
It ships in the Engineering Kit. It is wired to App Security Auditor (security-auditor), Technical Lead & System Architect (tech-lead), and PostgreSQL & Database Pro (postgres-pro). Required skills: Web Security Fundamentals & OWASP Defense; Web Performance & Core Web Vitals Optimization; PostgreSQL & Drizzle ORM Schema Standards.
When to use it
- Use before major releases or when refactoring legacy code to identify risks.
- Use /audit when you want that pipeline, not a freeform chat. If you only need one step, use a narrower command or a single agent.
- Start a new chat. Do not run this command in a thread that just wrote marketing copy.
When not to use it
- Do not run /audit as a substitute for reading the diff. The command produces files; you still gate them.
- Do not chain it into a 40-turn chat. Fresh context is part of the design.
- Do not run it if you have not filled CURSOR.md. The pipeline will invent a stack.
Example workflow
- Inspect API routes for missing authentication checks and unvalidated inputs
- Analyze database queries for N+1 problems and missing composite indexes
- Scan dependency trees for known CVE vulnerabilities
- Output prioritized audit report with exact line-by-line remediation diffs
Example usage
Type this in Cursor chat: /audit Run full security and performance audit on API route handlers and database queries
The command file tells the session which agents to adopt and which skills to read. You should see phase headers, not a single dump of code.
If a phase fails its gate, stop. Do not add 'just continue'.
Example output
- Expected artifact: docs/audits/codebase-audit.md
Best practices
- Keep the prompt specific. /audit Run full security and performance audit on API route handlers and database queries is the shape: object, constraint, and outcome.
- Let the listed agents work in order: security-auditor → tech-lead → postgres-pro.
- Save outputs in the repo. Chat-only answers evaporate.
- Engineering commands should leave tests or an audit note, not only implementation files.
Common mistakes
- Typing /audit with no object ('do the thing'). The pipeline will guess.
- Re-running the command in the same chat after a failed gate instead of fixing the failing file.
- Editing the command file to skip review so it 'goes faster'.
- Skipping the Web Security Fundamentals & OWASP Defense skill that the command depends on.
Frequently asked questions
What does /audit do in Cursor?
Performs deep static analysis across the entire codebase to detect OWASP security flaws, unhandled errors, memory leaks, missing indexes, and dead code.When should I run /audit?
Use before major releases or when refactoring legacy code to identify risks.What is an example /audit prompt?
/audit Run full security and performance audit on API route handlers and database queriesWhich skills does /audit load?
Web Security Fundamentals & OWASP Defense; Web Performance & Core Web Vitals Optimization; PostgreSQL & Drizzle ORM Schema StandardsIs /audit a Cursor skill?
No. /audit is a slash command you type. Skills are playbooks the agent may load. Use both: the command runs the workflow, the skills constrain how it writes.
Run /audit from your own repo
AgenticKit installs 47 slash commands, 46 agents, and 61 skills. One command installation.