# Security Audit Report

**Client/Repo**: <repo_name>
**Date**: <date>
**Auditor**: <auditor>
**Audited by**: gemma-deployment-security plugin

---

## Executive Summary

| Severity | Count |
|---|---|
| 🔴 Critical | <critical_count> |
| 🟠 Important | <important_count> |
| 🟡 Recommended | <recommended_count> |
| ⚪ Note | <note_count> |

<overall_assessment>

---

## 🔴 Critical Findings

<critical_findings_or_"None found.">

---

## 🟠 Important Findings

<important_findings>

---

## 🟡 Recommended Improvements

<recommended_findings>

---

## ⚪ Notes

<notes>

---

## ✅ Checks Passed

The following security controls are correctly configured:

- <passed_check_1>
- <passed_check_2>
[...]

---

## Audit Scope

| Skill | Status | Notes |
|---|---|---|
| audit-docker-compose | <ran/skipped> | <notes> |
| audit-dockerfile | <ran/skipped> | <notes> |
| audit-cicd-workflows | <ran/skipped> | <notes> |
| audit-infrastructure-as-code | <ran/skipped> | <notes> |
| audit-airflow-config | <ran/skipped> | <notes> |
| audit-pre-commit | <ran/skipped> | <notes> |
| audit-server-config | <ran/skipped> | <notes> |
