[ AI Augmentation Protocol ]
Target: Local Development
Status: Operational
System Ready

Execute
Security.

Your AI just became a senior security engineer. One command. 29 battle-tested security checks built into every coding assistant you already use.

[ Installation Vector ]
โฏnpx @netxeo/security-skill
[ Technical Specs ]
Security Modules
0
CWE Covered
0
OWASP Lists
0ร—
ASVS Level
0
[ Execution Log ]

What happens after
/security-audit
USER > /security-audit
๐Ÿ” Detecting stack... Next.js ยท Supabase ยท Vercel ยท Node 20
๐Ÿ“‹ Running 25 security checks across 29 modules...
โ•”โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•—
โ•‘  ๐Ÿ”  SECURITY AUDIT โ€” myproject          โ•‘
โ•‘      Stack: Next.js ยท Supabase ยท Vercel  โ•‘
โ• โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•ฃ
โ•‘  SCORE  :  61 / 100  [ WARNING ]         โ•‘
โ• โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•ฃ
โ•‘  [!] Secrets & Files        12/20  โ† FIX โ•‘
โ•‘  [+] Auth & Sessions        18/20        โ•‘
โ•‘  [!] Database (RLS)          8/20  โ† FIX โ•‘
โ•‘  [-] HTTP Headers           13/20        โ•‘
โ•‘  [+] Source Code            18/20        โ•‘
โ•šโ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
CRITICAL โ€” Supabase service role key exposed in frontend
Any visitor gets full DB access ยท Execute: /security-fix supabase-key
HIGH โ€” RLS disabled on 3 tables (users, orders, messages)
Authenticated users can read all rows ยท Execute: /security-fix rls
[ Visual Evidence ]
Without Protocol
AI behavior before
With Protocol Active
AI behavior after
Execution Output
Bonus execution
[ Implementation Protocol ]
[01]

One command. Zero config.

npx @netxeo/security-skill
Installs 29 security modules and auto-configures every AI assistant on your machine. Done in under 10 seconds.
[02]

Your AI becomes the expert.

/security-scan
Auto-detects your stack โ€” Next.js, Firebase, Docker โ€” and runs targeted checks. No guessing, no false positives.
[03]

Review & fix. Your call.

/security-fix
See the exact diff before anything changes. Every fix is explained. Non-breaking. Approved by you.
[ Feature Matrix ]
[01]

Scans in 30 seconds

No build step. No cloud. Pure AI pattern recognition on your actual codebase.

[02]

You approve every fix

The AI proposes a diff. You decide. Nothing changes without your explicit approval.

[03]

Security score /100

Tracked in memory-security.md. You'll watch your score climb with every fix.

[04]

Any stack, anywhere

Next.js, Express, Django, Laravel, Spring Boot. Auto-detected from your project.

[05]

Context-rich findings

Each vulnerability includes the attack vector, real-world impact, and a tailored fix.

[06]

Persistent memory

Accepted risks, rotation schedules โ€” your AI remembers across every session.

[ Engine Compatibility ]
ClaudeCLAUDE.md
GitHub Copilotcopilot-instructions.md
Cursor.cursorrules
Windsurf.windsurfrules
Cline.clinerules
OpenAI CodexAGENTS.md
Continue.dev.continue/config.yaml
Aider.aider.conf.yml
GeminiGEMINI.md