{"id":"bd51840d-977b-46b4-8ab7-7e73d778e856","slug":"r1ptw0-security-analyst","name":"security-analyst","description":"Use when the user wants a security audit, penetration test, threat model, vulnerability hunt, security fix plan, SBOM, compliance mapping, privacy assessment, or security posture comparison between runs.","canonicalUrl":"https://www.xpersona.co/skill/r1ptw0-security-analyst","sourceUrl":"https://github.com/r1ptw0/security-analyst","homepage":null,"source":"GITHUB_OPENCLEW","vendor":{"slug":"r1ptw0","label":"R1ptw0","url":"https://github.com/r1ptw0/security-analyst"},"protocols":["MCP"],"capabilities":["run","read","mcp_task"],"trustScore":null,"trustConfidence":"unknown","artifactCount":0,"benchmarkCount":0,"lastRelease":null,"freshnessAt":"2026-04-14T22:26:08.496Z","freshnessLabel":"Apr 14, 2026","securityReviewed":true,"openapiReady":false,"stats":[{"label":"Trust score","value":"Unknown"},{"label":"Compatibility","value":"MCP"},{"label":"Freshness","value":"Apr 14, 2026"},{"label":"Vendor","value":"R1ptw0"},{"label":"Artifacts","value":"0"},{"label":"Benchmarks","value":"0"},{"label":"Last release","value":"Unpublished"}],"factsPreview":[{"factKey":"docs_crawl","category":"integration","label":"Crawlable docs","value":"6 indexed pages on the official domain","href":"https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar","sourceUrl":"https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar","sourceType":"search_document","confidence":"medium","observedAt":"2026-04-15T05:03:46.393Z","isPublic":true},{"factKey":"vendor","category":"vendor","label":"Vendor","value":"R1ptw0","href":"https://github.com/r1ptw0/security-analyst","sourceUrl":"https://github.com/r1ptw0/security-analyst","sourceType":"profile","confidence":"medium","observedAt":"2026-04-14T22:26:08.496Z","isPublic":true},{"factKey":"protocols","category":"compatibility","label":"Protocol compatibility","value":"MCP","href":"https://www.xpersona.co/api/v1/agents/r1ptw0-security-analyst/contract","sourceUrl":"https://www.xpersona.co/api/v1/agents/r1ptw0-security-analyst/contract","sourceType":"contract","confidence":"medium","observedAt":"2026-04-14T22:26:08.496Z","isPublic":true},{"factKey":"handshake_status","category":"security","label":"Handshake status","value":"UNKNOWN","href":"https://www.xpersona.co/api/v1/agents/r1ptw0-security-analyst/trust","sourceUrl":"https://www.xpersona.co/api/v1/agents/r1ptw0-security-analyst/trust","sourceType":"trust","confidence":"medium","observedAt":null,"isPublic":true}],"highlights":["Trust evidence available"],"agentCard":{"name":"security-analyst","description":"Use when the user wants a security audit, penetration test, threat model, vulnerability hunt, security fix plan, SBOM, compliance mapping, privacy assessment, or security posture comparison between runs.","source":"GITHUB_OPENCLEW","sourceId":"github:1166013975","repository":"https://github.com/r1ptw0/security-analyst","documentation":"https://www.xpersona.co/skill/r1ptw0-security-analyst/agent/r1ptw0-security-analyst","protocols":["MCP"],"capabilities":["run","read","mcp_task"],"languages":["typescript"],"install":{"command":"git clone https://github.com/r1ptw0/security-analyst.git","ecosystem":"git"},"examples":[{"kind":"example","language":"text","snippet":"Recon: Reconnaissance (14 agents, all parallel — 2 waves)\n  └─ Wave A (12 agents, batch-spawned): metadata, docs, HTTP, boundaries, crown jewels, auth, integrations, secrets, security work, config, frontend, deps\n  └─ Wave B (2 agents, batch-spawned): data flows, scope notes (depend on Wave A)\n  └─ Assembly: orchestrator builds recon/index.md from LOD-0+1 returns\n\nSurface: Attack Surface + Git History + Dependencies + Config (up to 16 agents, batch-spawned in parallel)\n  ├─ HTTP entry points, authz rules, integrations, frontend\n  ├─ LLM/AI security (OWASP Top 10 for LLM Applications)\n  ├─ API schema validation (OpenAPI, GraphQL, gRPC)\n  ├─ WebSocket / SSE real-time security\n  ├─ File upload security\n  ├─ Injection/auth/SSRF/data-exposure variant hunting via git history\n  ├─ Dependency audit (npm audit, supply chain)\n  ├─ Infrastructure config, secrets, KMS, IAM\n  ├─ CI/CD pipeline security (GitHub Actions, GitLab CI)\n  └─ Container security (Docker, Kubernetes)\n\n┌─ SBOM Assembly (orchestrator, no agent — runs in parallel with logic stage)\n│\nLogic: Business Logic (4 agents batch-spawned, needs surface stage)\n  ├─ Race conditions and TOCTOU\n  ├─ Authorization escalation and IDOR\n  ├─ Pipeline exploitation (input → AI → decision → action)\n  └─ DoS and resource exhaustion\n\nTracing: Data Flow Tracing (up to 4 agents batch-spawned, needs surface + logic)\n  └─ End-to-end trace of critical data flows with sanitization gap analysis\n\nExploits: Exploit Development (1 agent, needs all findings)\n  └─ Develops complete exploits with PoCs, CVSS scores, CWE/ATT&CK IDs, chains\n\nValidation: Finding Validation (1 critic agent)\n  └─ Adversarial review — catches false positives, validates fixes, adjusts severity\n\nReporting: Final Report (1 agent)\n  └─ Executive summary, risk dashboard, remediation roadmap\n\nRemediation: Fix Plan (1 agent)\n  └─ Actionable tasks with fix code, regression tests, effort estimates"},{"kind":"example","language":"text","snippet":"/security-analyst:full"}]}}