Pre-release security audit for ANY project — AI-built or hand-written, web or mobile. Scans the codebase for the full range of real-world risks that get apps breached: leaked API & AI-provider keys, exposed configs/secrets, broken auth & access control (IDOR), injection (SQL/XSS/command), SSRF, open databases & cloud storage, exposed admin/debug surfaces, missing security headers, unverified webhooks/CSRF, missing rate limits (incl. AI cost-bombing), vulnerable dependencies, mobile-specific leaks, and prompt-injection in AI features. Writes a plain-English markdown report. No jargon. Free.
$npx -y skills add raffa-jarrl/lictor-ai --skill lictor-security-checkInstalls into the current project.
Run `npx skills use "https://github.com/raffa-jarrl/lictor-ai" --skill "raffa-jarrl/lictor-ai/lictor-security-check"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/raffa-jarrl/lictor-ai" that are relevant to the current task. Run `npx skills add "https://github.com/raffa-jarrl/lictor-ai"` and select the relevant skills, then follow their instructions.