repo-security-review
Security audit for GitHub repositories before installation. Use when user wants to check if a repo/app is safe to install, review install scripts for malicious code, verify an open source project isn't collecting data, or audit dependencies for suspicious packages. Triggers on phrases like "is this safe to install", "check this repo", "review this script", "audit this code", "is this sketchy".
What this skill does
# Repo Security Review Perform security audits on GitHub repositories to identify data exfiltration, malicious code, or suspicious behavior before installation. ## Workflow ### 1. Gather Repository Info - Fetch the main page to understand what the project does - Locate the GitHub repository URL - Identify install scripts (install.sh, setup.py, Makefile, etc.) ### 2. Review Install Scripts Fetch and analyze all install scripts for: - **URLs contacted** - Should only be official sources (GitHub releases, package registries) - **Commands executed** - Look for curl/wget to unknown hosts, eval of remote code - **File system access** - Unexpected writes outside install directory - **Environment variables** - Harvesting of secrets, API keys, credentials ### 3. Audit Source Code Examine main application code for: - **Network calls** - All HTTP/HTTPS requests and their destinations - **Data collection** - Any telemetry, analytics, or phone-home behavior - **File access** - Reading sensitive files (~/.ssh, ~/.aws, credentials) - **Obfuscated code** - Base64 encoded strings, eval(), exec() ### 4. Check Dependencies Review dependency files (package.json, go.mod, requirements.txt, Cargo.toml): - Look for analytics/telemetry packages - Check for typosquatted package names - Verify packages are from reputable sources ### 5. Provide Assessment Summarize findings with: - **Overall verdict** (Safe / Caution / Unsafe) - **Network activity** - All external endpoints contacted - **Data storage** - Where data is stored (local vs remote) - **Red flags found** - Any suspicious patterns - **Recommendation** - Install as-is, build from source, or avoid ## Red Flags Reference See [references/red-flags.md](references/red-flags.md) for comprehensive list of suspicious patterns. ## Key Suspicious Patterns (Quick Reference) **Install scripts:** - `curl | bash` from non-official URLs - Hidden file creation (dotfiles outside expected locations) - Modification of shell profiles to inject code - Download and execute without verification **Source code:** - Hardcoded IPs or non-GitHub/official URLs - Base64 encoded payloads - Reading SSH keys, AWS credentials, browser data - Sending data to analytics endpoints - Obfuscated variable names **Dependencies:** - `analytics`, `telemetry`, `tracking` packages - Misspelled package names (typosquatting) - Packages with very few downloads/stars - Dependencies from personal GitHub repos ## Output Format ``` ## Security Review Summary: [Project Name] ### [Status Emoji] Install Script - [CLEAN/SUSPICIOUS/DANGEROUS] [Findings] ### [Status Emoji] Application Code - [CLEAN/SUSPICIOUS/DANGEROUS] [Findings] ### [Status Emoji] Dependencies - [CLEAN/SUSPICIOUS/DANGEROUS] [Findings] ### Assessment [Overall verdict and recommendation] ``` Use checkmarks for clean, warning signs for suspicious, X for dangerous.
Related in Security
mac-ops
IncludedComprehensive macOS workstation operations — diagnose kernel panics, identify failing drives, audit launchd startup items, decode wake reasons, triage TCC permission denials, manage APFS snapshots, recover from no-boot. Use for: Mac is slow, slow bootup, won't boot, kernel panic, kernel_task hot, mds_stores CPU, photoanalysisd, cloudd, login loop, gray screen, sleep wake failure, drive failing, IO errors, APFS snapshots eating space, Time Machine local snapshots, Spotlight indexing, launchd, LaunchAgent, LaunchDaemon, login items, TCC permissions, Full Disk Access, Screen Recording denied, Gatekeeper, quarantine, com.apple.quarantine, app is damaged, helper tool, /Library/PrivilegedHelperTools, pmset, wake reasons, dark wake, sysdiagnose, panic.ips, DiagnosticReports, configuration profile, MDM profile, remote diagnostics over SSH.
a11y-audit
IncludedRun accessibility audits on web projects combining automated scanning (axe-core, Lighthouse) with WCAG 2.1 AA compliance mapping, manual check guidance, and structured reporting. Output is configurable: markdown report only, markdown plus machine-readable JSON, or markdown plus issue tracker integration. Use this skill whenever the user mentions "accessibility audit", "a11y audit", "WCAG audit", "accessibility check", "compliance scan", or asks to check a web project for accessibility issues. Also trigger when the user wants to verify WCAG conformance or map findings to a specific standard (CAN-ASC-6.2, EN 301 549, ADA/AODA).
erpclaw
IncludedAI-native ERP system with self-extending OS. Full accounting, invoicing, inventory, purchasing, tax, billing, HR, payroll, advanced accounting (ASC 606/842, intercompany, consolidation), and financial reporting. 413 actions across 14 domains, 43 expansion modules. Constitutional guardrails, adversarial audit, schema migration. Double-entry GL, immutable audit trail, US GAAP.
assess
IncludedAssesses and rates quality 0-10 across multiple dimensions (correctness, maintainability, security, performance, testability, simplicity) with pros/cons analysis. Compares against project conventions and prior decisions from memory. Produces structured evaluation reports with actionable improvement suggestions. Use when evaluating code, designs, architectures, or comparing alternative approaches.
spring-boot-security-jwt
IncludedProvides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
code-hardcode-audit
IncludedDetect hardcoded values, magic numbers, and leaked secrets. TRIGGERS - hardcode audit, magic numbers, PLR2004, secret scanning.