Skip to main content

security-posture-audit

Read-only, offline audit of a repository's security hygiene posture: deterministic checks for unpinned dependencies (requirements/package.json/Dockerfile), committed .env/.pem/id_rsa files, hardcoded debug and wildcard-CORS flags, plain-http transports and pip trusted-host, risky GitHub Actions patterns (pull_request_target + head checkout, curl|sh), world-writable/setuid modes, and a missing SECURITY.md — every finding severity-graded with file:line evidence and a concrete remediation. Use when asked to "audit this repo's security posture", "run a security hygiene check", or "are our deps pinned / env files committed / workflows safe?" on a repo the user owns or is authorized to review. Not a CVE scanner (no advisory DB, no network), not SAST dataflow analysis, not a secrets-content scanner, and not norms verification — use base-in-reality for norms and agent-ready-rails for agent-readiness.

インストールへ移動

ソース情報

リポジトリ
dhanesh/agent-skills
ソースの最終更新活動
2026年7月21日 20:27
検出された SKILL.md の言語
英語
スター
1
フォーク
0

インストール方法

デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。

ソースファイルを確認

インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。