This commit is contained in:
@@ -0,0 +1,22 @@
|
||||
# Security Hygiene Audit
|
||||
|
||||
Review authentication, authorization, secrets, input validation, dependency risk and unsafe defaults within a defined application scope.
|
||||
|
||||
## Purpose
|
||||
|
||||
This is a publishable P0 built-in DevRunbook package. It is designed for the `inspect` work mode with default autonomy `diagnose` and risk tier `high`.
|
||||
|
||||
## Required context
|
||||
|
||||
- Scope: Describe the repository, application and deployment boundaries to assess.
|
||||
- Deployment context: Describe trust boundaries, exposure, users, data and runtime environment.
|
||||
|
||||
## Completion
|
||||
|
||||
- Findings include evidence, exploitability context and remediation priority.
|
||||
- The report states that it is not a formal penetration test.
|
||||
- Validation evidence and unresolved limitations are reported honestly.
|
||||
|
||||
## Quality status
|
||||
|
||||
Editorially reviewed and covered by static structure and determinism fixtures. It is not represented as execution-validated or battle-tested until the platform stores corresponding evidence.
|
||||
Reference in New Issue
Block a user