Forgeprint

Catalog entries are written once, in English. Your browser can translate them.

← all crews

crews/appsec-audit-crew

AppSec Audit Crew

Assembled by @aliosmanmho

A whole-application security and privacy audit: threat model and ASVS requirements first, a deletion path for every personal field, and a test for every control.

Claude Code Codex CLI GitHub Copilot CLI Cursor Gemini CLI Windsurf Cline OpenCode Kiro

What it is for

A deep audit of a whole application: threat model, ASVS 5.0 requirements, authentication and authorization, dependencies and secrets, personal data and its deletion, and a test for each control that goes red when the control is removed.

Where it is wrong

Hardening a single API (that is api-hardening-crew), compliance paperwork or legal conclusions, a penetration test, or one known finding in one file. A single finding is small, sequential work for the security reviewer alone.

Members

Integrations

Read it

README.md

Use it

Ask an agent connected to the Forgeprint MCP for get_crew with this slug. A crew is a recommendation with a name on it, not a requirement. get_crew { "slug": "appsec-audit-crew" }