--- name: owasp-security-audit description: Use when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a Node.js/Express/React application. --- # OWASP Top 10 Security Audit ## Overview Systematic methodology for auditing web applications against the OWASP Top 10:2021. Combines automated tooling with manual code review, produces a prioritized remediation plan with verification steps and CI/CD integration guidance. **Core principle:** Every finding must be verified with tooling or code evidence, prioritized by exploitability, and paired with a concrete fix the agent can implement. ## When to Use - Cybersecurity audit or security review request - OWASP Top 10 compliance assessment - Pre-release security gate or penetration test preparation - Post-incident security hardening - Dependency vulnerability triage **When NOT to use:** - Quick fix for a single known vulnerability (just fix it) - General code quality review (use `code-auditing` skill instead) - Infrastructure/cloud security review (out of scope - this covers application layer) ## Audit Methodology ### Phase 0: Environment Setup and Automated Scans Run automated tools FIRST - they catch low-hanging fruit before manual review. **Required scans (execute all):** | Tool | Command | Covers | |------|---------|--------| | npm audit | `npm audit --json` | A06: Known CVEs in dependencies | | ESLint security | `npx eslint --plugin security .` | A03, A05: Code-level vulnerabilities | | Outdated check | `npm outdated` | A06: Outdated packages | | Secret scan | `rg -i '(password\|secret\|api_key\|token)\s*[:=]' --glob '!node_modules' --glob '!*.lock'` | A02: Hardcoded secrets | | .gitignore check | Verify `.env`, `*.pem`, `*.key` are in `.gitignore` | A02: Committed secrets | | Git history secrets | `git log --all --diff-filter=A -- '*.env' '*.pem' '*.key'` | A02: Secrets in git history | | Debug/telemetry code | `rg 'fetch\(.*127\.0\.0\.1\|localhost:[0-9]{4}' --glob '*.{ts,js,jsx,tsx}'` | A04: Dev-only outbound requests | **Record baseline metrics:** Total vulnerabilities by severity, outdated dependency count, secret scan hits. ### Phase 1: Systematic Category Audit Audit EVERY category using the checklist in the Quick Reference section. Do not skip categories even if they seem irrelevant - document "N/A" with justification. For each category: 1. Run the specific checks listed in the checklist 2. Record findings with file path, line number, and severity 3. Note what you checked even if clean (proves thoroughness) ### Phase 2: Findings Classification Rate each finding using this severity matrix: | Severity | Criteria | Example | |----------|----------|---------| | **Critical** | Exploitable remotely, no auth required, data breach likely | Hardcoded DB credentials in git, zero authentication | | **High** | Exploitable with some effort, significant impact | Missing security headers, no rate limiting, IDOR | | **Medium** | Requires specific conditions, moderate impact | Outdated dependencies without known exploits, weak validation | | **Low** | Minimal impact or unlikely exploitation | Missing CSP fine-tuning, verbose error messages in dev | ### Phase 3: Prioritized Remediation Plan Group fixes into implementation phases: **Phase A - Immediate (< 1 day, critical/high):** - Rotate exposed credentials - Add authentication middleware - Install and configure Helmet - Add rate limiting - Fix `.gitignore` and purge secrets from git history **Phase B - Short-term (1-3 days, high/medium):** - Implement RBAC authorization - Add input sanitization (xss/DOMPurify) - Configure structured logging - Set body size limits - Add CSRF protection **Phase C - Medium-term (1-2 weeks, medium/low):** - Upgrade outdated dependencies - Add CI/CD security pipeline - Implement audit logging - Add security monitoring/alerting Each fix must include: what to change, where, a code example, and how to verify it works. ### Phase 4: Verification and CI/CD Integration For each remediation, define a verification step: - Unit test that validates the security control - curl command that proves the vulnerability is fixed - CI pipeline check that prevents regression ## Quick Reference: OWASP Top 10 Audit Checklist ### A01: Broken Access Control **Step 1: Enumerate all routes first.** Run `rg 'router\.(get|post|put|patch|delete)' --glob '*.ts'` and list every endpoint. Then verify EACH has auth middleware. | Check | How | Severity if missing | |-------|-----|-------------------| | Authentication middleware on ALL routes | Enumerate all routes, verify each has auth middleware in chain | Critical | | RBAC / role-based authorization | Check for role checks before data access | Critical | | IDOR protection | Verify resource ownership checks (e.g., `where: { id, userId }`) | High | | CORS configuration | Check `cors()` options - no wildcard in production | High | | Serverless CORS vs Express CORS | Compare `serverless.yml` CORS with Express CORS config | Medium | | CSRF protection | Check for `csurf` or double-submit cookie pattern | Medium | ### A02: Cryptographic Failures | Check | How | Severity if missing | |-------|-----|-------------------| | No hardcoded secrets | `rg '(password\|secret\|key)\s*[:=]\s*["\x27]' --glob '!*.lock'` | Critical | | `.env` in `.gitignore` | `rg '\.env' .gitignore` — verify NOT commented out | Critical | | Secrets in git history | `git log --all --diff-filter=A -- '*.env' '*.pem'` — if found, recommend `bfg-repo-cleaner` purge | Critical | | Prisma uses `env("DATABASE_URL")` | Check `schema.prisma` datasource block — no inline connection string | Critical | | HTTPS enforcement | Check for `https` redirects or HSTS headers | High | | PII field filtering | Check API responses for unnecessary sensitive fields | Medium | | Password hashing (if auth exists) | Verify bcrypt/argon2, not SHA/MD5 | Critical | ### A03: Injection | Check | How | Severity if missing | |-------|-----|-------------------| | No raw SQL | `rg '\$(queryRaw\|executeRaw)\|rawQuery' --glob '*.ts'` | Critical | | Parameterized queries (Prisma/ORM) | Verify all DB access through ORM, no string concatenation | Critical | | Input validation on all endpoints | Check every route handler has validation before DB ops | High | | File upload filename sanitization | Check multer/upload config for `originalname` usage | High | | Sort/filter field allowlists | Verify user-supplied field names checked against allowlist | Medium | | No `eval()` or `Function()` | `rg 'eval\(\|new Function\(' --glob '*.{ts,js}'` | Critical | | No template literal injection in logs | Check log statements for unsanitized user input | Low | | Mass assignment prevention | Verify `req.body` is NOT spread directly into Prisma `create`/`update` — use explicit field allowlists | High | ### A04: Insecure Design | Check | How | Severity if missing | |-------|-----|-------------------| | Request body size limits | Check `express.json({ limit: ... })` | Medium | | File upload size/type restrictions | Check multer config for `limits` and `fileFilter` | High | | File upload path traversal | Verify upload destination is absolute, filename is sanitized | High | | Validation not bypassable | Check validators cannot be skipped (e.g., with extra fields) | High | | No debug/telemetry endpoints in production | `rg 'fetch\(.*127\.0\.0\.1\|localhost:[0-9]' --glob '*.{ts,js,jsx}'` | High | | Error responses don't leak internals | Verify 500 errors return generic messages | Medium | ### A05: Security Misconfiguration | Check | How | Severity if missing | |-------|-----|-------------------| | Helmet.js installed and configured | Check `package.json` for `helmet`, `index.ts` for `app.use(helmet())` | High | | `x-powered-by` disabled | `app.disable('x-powered-by')` or Helmet handles it | Low | | Rate limiting | Check for `express-rate-limit` or equivalent | High | | Strict CORS (no wildcard) | Verify `origin` is not `*` or `true` | High | | Environment variable validation | Check for startup validation of required env vars | Medium | | No default credentials | Check seed files, test configs for hardcoded passwords | Medium | | HTTP parameter pollution (HPP) | Check for `hpp` middleware or manual prevention | Low | | `trust proxy` configured (if behind LB) | Check `app.set('trust proxy', ...)` for Lambda/ALB | Medium | | CSP for React SPA | Verify `Content-Security-Policy` header restricts `script-src`, `style-src`, `connect-src` | High | | No inline `