Skip to main content

security-posture-audit

Read-only, offline audit of a repository's security hygiene posture: deterministic checks for unpinned dependencies (requirements/package.json/Dockerfile), committed .env/.pem/id_rsa files, hardcoded debug and wildcard-CORS flags, plain-http transports and pip trusted-host, risky GitHub Actions patterns (pull_request_target + head checkout, curl|sh), world-writable/setuid modes, and a missing SECURITY.md — every finding severity-graded with file:line evidence and a concrete remediation. Use when asked to "audit this repo's security posture", "run a security hygiene check", or "are our deps pinned / env files committed / workflows safe?" on a repo the user owns or is authorized to review. Not a CVE scanner (no advisory DB, no network), not SAST dataflow analysis, not a secrets-content scanner, and not norms verification — use base-in-reality for norms and agent-ready-rails for agent-readiness.

Zur Installation springen

Quellinformationen

Repository
dhanesh/agent-skills
Letzte Quellaktivität
21. Juli 2026 um 20:27
Erkannte Sprache von SKILL.md
Englisch
Sterne
1
Forks
0

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.