Security Hygiene Audit
Review authentication, authorization, secrets, input validation, dependency risk and unsafe defaults within a defined application scope.
Purpose
This is a publishable P0 built-in DevRunbook package. It is designed for the inspect work mode with default autonomy diagnose and risk tier high.
Required context
- Scope: Describe the repository, application and deployment boundaries to assess.
- Deployment context: Describe trust boundaries, exposure, users, data and runtime environment.
Completion
- Findings include evidence, exploitability context and remediation priority.
- The report states that it is not a formal penetration test.
- Validation evidence and unresolved limitations are reported honestly.
Quality status
Editorially reviewed and covered by static structure and determinism fixtures. It is not represented as execution-validated or battle-tested until the platform stores corresponding evidence.