Claude Code slash command for white-box security auditing with OWASP Top 10:2025 and NIST CSF 2.0 mapping
Browse cluster: Cluster 124 →Claude Security Audit is a tool for running comprehensive white-box and gray-box security audits on software projects using Claude Code or compatible AI coding assistants. It maps security findings to multiple compliance frameworks including OWASP Top 10:2025, CWE, NIST CSF 2.0, SANS/CWE Top 25, OWASP ASVS 5.0, PCI DSS 4.0.1, MITRE ATT&CK, SOC 2, and ISO 27001:2022. The tool includes over 475 security checks covering white-box testing, AI/LLM security concerns, code smells, and framework-specific vulnerabilities across 12 web frameworks including Laravel, Next.js, FastAPI, Express, Django, Rails, Spring Boot, ASP.NET Core, Go, Flask, Nuxt.js, and SvelteKit. It supports multiple execution modes like full audits, quick scans, diff-based reviews of changed files, focused deep dives on authentication or API security, and interactive triage, with options to include remediation code, generate SARIF or JSON output for CI/CD integration, and apply compliance packs for specialized domains like HIPAA, GDPR, and fintech.