ci-cd-security
75Audit GitHub Actions Workflows
GitHub Actions workflows can expose credentials, repositories, and releases through subtle configuration errors. This skill applies a structured security review and proposes concrete fixes.
Audit AI Agent Skills Before Installation
Unvetted agent skills can hide prompt injection, credential theft, persistence, or unsafe dependencies. This skill combines offline scanning with guided semantic review.
Kopieren Sie diese Anfrage in Ihren Agent. Sie enthält die maßgebliche Skill-Seite und das Manifest.
Review the Skillstore skill "skill-security" from https://skillstore.io/skills/superagent-ai-skill-security.md and its manifest at https://skillstore.io/api/skills/superagent-ai-skill-security/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Ihr Agent sollte weiterhin seinen Plan anzeigen und alle von der Sicherheitsrichtlinie verlangten Bestätigungen anfordern.
Verwenden Sie diese Links, wenn ein KI-Agent, Crawler oder Skript sauberen Kontext benötigt, statt die vollständige Seite zu lesen.
„skill-security“ wird verwendet. Audit a documentation skill that contains no scripts or external dependencies.
Erwartetes Ergebnis:
„skill-security“ wird verwendet. Audit a skill whose script reads environment secrets and sends them to an unknown endpoint.
Erwartetes Ergebnis:
„skill-security“ wird verwendet. Audit a build skill that invokes a fixed compiler command.
Erwartetes Ergebnis:
All 146 static alerts are false positives caused by scanning defensive documentation, signatures, detector source, or Markdown syntax as payload behavior. The scanner makes no network requests or secret reads, but archive extraction lacks resource limits and permits disk exhaustion.
Teile den versionierten Bewertungsbericht, das neutrale Badge, die Einbettungskarte und Zitate. Skillstore berichtet Nachweise, ohne zu entscheiden, ob dieser Skill sicher ist.
https://skillstore.io/skills/superagent-ai-skill-security/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/superagent-ai-skill-security?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/superagent-ai-skill-security?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/superagent-ai-skill-security/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/superagent-ai-skill-security.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>superagent-ai. (2026). skill-security security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/superagent-ai-skill-security/audits/1@techreport{superagent-ai-superagent-ai-skill-security-2026,
author = {superagent-ai},
title = {skill-security security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/superagent-ai-skill-security/audits/1},
note = {Author version unspecified}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "skill-security security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "superagent-ai"
date-released: "2026-08-13"
url: "https://skillstore.io/skills/superagent-ai-skill-security/audits/1"
identifiers:
- type: other
value: "skillstore:superagent-ai-skill-security:audit:1"
description: "Skillstore immutable audit report identifier"
Review a local skill before granting it access to developer files and tools.
Triage submitted skills and investigate high-risk findings before publication.
Generate SARIF findings for skill repositories during automated validation.
Audit the skill at [local path]. Explain whether it is safe to install and cite each confirmed finding.
Scan [archive path] and separate confirmed risks from false positives. Include practical remediation for each confirmed issue.
Audit [skill path]. Compare its declared purpose with filesystem, network, environment, and command behavior. Highlight any mismatch.
Perform a publication audit of [skill path]. Review all executable files, assess supply-chain risks, and provide a concise release recommendation.
Autor
superagent-aiLizenz
MIT
Skillstore-Revision
r1
Versionshinweis
Der Autor hat keine Version angegeben.
Ref.
b855ff950d61b6aa57ef643d2f8c3c50a5745db8
Aktualität der Wartung
13.8.2026
Nutzung
0 Downloads · 0 Aufrufe
Scan AI Plugins Before Installation
von hashgraph-online
Unreviewed agent extensions can contain prompt injection, unsafe commands, secret exposure, or supply-chain risks. This skill guides local scanning and clear interpretation before trust.
Sicherheits- und Lizenzrisiken von Abhängigkeiten auditieren
von sickn33
Risiken durch Abhängigkeiten sind schwer über Schwachstellen, Lizenzen, Updates und Supply-Chain-Signale hinweg zu priorisieren. Dieser Skill führt Claude, Codex und Claude Code durch strukturierte Audits und Behebungspläne.
Frontend-Code auf XSS-Risiken prüfen
von sickn33
Frontend-XSS-Probleme werden bei normalen Code-Reviews leicht übersehen. Diese Skill führt Claude, Codex und Claude Code durch gezielte Prüfungen auf unsicheres Rendering, URL-Verarbeitung und Lücken bei der Sanitization.
Sicherheitsrisiken von Abhängigkeiten scannen
von sickn33
Schwachstellen in Abhängigkeiten und Lizenzrisiken sind über verschiedene Ökosysteme hinweg schwer nachzuverfolgen. Diese Skill unterstützt beim Scannen, Priorisieren, Erstellen von SBOMs und bei der Planung von Gegenmaßnahmen.
Abhängigkeitssicherheit und Lizenzen prüfen
von sickn33
Probleme mit Abhängigkeiten können Produkte Schwachstellen, Lizenzkonflikten und Lieferkettenrisiken aussetzen. Diese Skill führt Claude, Codex und Claude Code durch Audits, Upgrade-Planung und Berichte zur Behebung.
Skill-Berechtigungen prüfen
von guo-yu
Claude Code-Skills können Shell-Berechtigungen benötigen, die manuell schwer zu überprüfen sind. Dieser Skill analysiert die deklarierte Befehlsnutzung und hilft, passende allowlist-Einträge mit Warnungen bei weitreichenden Änderungen zu erstellen.