ghe-requirements
Manage GHE Requirements
Feature work can drift when requirements are missing or stale. This skill defines requirement files, versioning, issue links, and backup steps.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "ghe-requirements" from https://skillstore.io/skills/emasoft-ghe-requirements.md and its manifest at https://skillstore.io/api/skills/emasoft-ghe-requirements/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "ghe-requirements". Create a requirement for adding export filters to a reporting dashboard.
Expected outcome:
- A draft requirement with a feature overview, user story, and acceptance criteria for filtered exports.
- A proposed atomic change list covering UI controls, export behavior, and tests.
- A dependency section noting related dashboard and reporting requirements.
Using "ghe-requirements". Check whether issue 42 is linked to the current REQ version.
Expected outcome:
- A validation summary showing whether the issue includes a requirement link.
- A version comparison between the issue text and the current requirement file.
- A short remediation note if the issue is missing or stale.
Security Audit
High RiskThe audit found many Markdown backtick false positives, but several bash workflow blocks remain real external-command surfaces. The highest confirmed risk is authorization to write ~/.claude settings, plus an overbroad instruction block that can weaken normal instruction hierarchy.
Confirmed security concerns (1)
Capability review items (29)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (49)
📁 Filesystem access (4)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/emasoft-ghe-requirements/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/emasoft-ghe-requirements?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/emasoft-ghe-requirements?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/emasoft-ghe-requirements/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/emasoft-ghe-requirements.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
Emasoft. (2026). ghe-requirements security audit report (audit version 9) [Author version unspecified]. Skillstore. https://skillstore.io/skills/emasoft-ghe-requirements/audits/9BibTeX citation
@techreport{emasoft-emasoft-ghe-requirements-2026,
author = {Emasoft},
title = {ghe-requirements security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/emasoft-ghe-requirements/audits/9},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "ghe-requirements security audit report (audit version 9)"
version: "unspecified"
type: report
authors:
- name: "Emasoft"
date-released: "2026-07-05"
url: "https://skillstore.io/skills/emasoft-ghe-requirements/audits/9"
identifiers:
- type: other
value: "skillstore:emasoft-ghe-requirements:audit:9"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Prepare a Feature Requirement
Create a structured requirement before development starts, with acceptance criteria, atomic changes, tests, and dependencies.
Coordinate GitHub Issue Work
Link GitHub development issues to the current requirement version so implementers share the same source of truth.
Review Requirement Drift
Compare issue links, requirement versions, and acceptance criteria before implementation review or test planning.
Try These Prompts
Create a GHE requirement draft for this feature request: [feature]. Include user story, acceptance criteria, atomic changes, tests, and dependencies.
Update this GHE requirement for a minor version change: [requirement summary]. Preserve original intent and list the revision history entry.
Prepare GitHub issue requirements text for REQ-[number] version [version]. Include the primary link, acceptance criteria, and atomic changes.
Audit this GitHub issue against its linked GHE requirement. Identify missing links, stale versions, uncovered acceptance criteria, and unclear tests.
Best Practices
- Confirm requirement changes with the user before changing acceptance criteria or scope.
- Keep issue links tied to explicit requirement versions.
- Review shell examples before running them in repositories with sensitive files.
Avoid
- Starting development work before a requirement file exists.
- Changing requirement scope without updating revision history.
- Running GitHub CLI or file commands without checking paths and permissions.