crews/appsec-audit-crew
AppSec Audit Crew
A whole-application security and privacy audit: threat model and ASVS requirements first, a deletion path for every personal field, and a test for every control.
Claude Code Codex CLI GitHub Copilot CLI Cursor Gemini CLI Windsurf Cline OpenCode Kiro
What it is for
A deep audit of a whole application: threat model, ASVS 5.0 requirements, authentication and authorization, dependencies and secrets, personal data and its deletion, and a test for each control that goes red when the control is removed.
Where it is wrong
Hardening a single API (that is api-hardening-crew), compliance paperwork or legal conclusions, a penetration test, or one known finding in one file. A single finding is small, sequential work for the security reviewer alone.
Members
Integrations
Read it
Use it
Ask an agent connected to the Forgeprint MCP for get_crew with this slug. A crew is a recommendation with a name on it, not a requirement. get_crew { "slug": "appsec-audit-crew" }