agentsclimarketplace

Security compliance review

Skill addxai/enterprise-harness-engineering/skills/security-compliance-review

Perform a structured security and compliance review using evidence from code/config/docs. Use for MR/PR review, architecture review, and periodic full scans. Detects secrets exposure, PII leakage, access control gaps, and compliance violations.From its SKILL.md

Install
npx -y skills add addxai/enterprise-harness-engineering --skill security-compliance-review

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

SKILL.md

6.8 KB, ~1.5k tokens by cl100k_base, as published. Nobody here has run it

Security & Compliance Review

A comprehensive security and compliance review framework. Based on input materials and baseline policies, intelligently determines the risk surface and provides actionable remediation recommendations.

For detailed rules and examples, see references/REFERENCE.md.

Execution Flow

Step 0: Pre-Gate — System Type Determination (Blocking)

  • Must first determine the system type: Consumer-facing / Internal product / Mixed
  • If unable to determine: output a "clarification question" first (blocking conclusion); do not proceed to subsequent checks until the answer is received

Step 1: Relevance Assessment

  1. Define scope first: Prioritize MR/diff/specified directory; fall back to scanning the repository
  2. Find evidence next: Code/configuration/CI/Helm/dependencies
  3. Then draw conclusions: Relevant / Not Relevant (N/A) / Unknown
  4. Unknown triggers clarification/blocking only for "must-clarify items"

Step 2: Risk Map Check

Must output a table: Risk Category | Relevance | Trigger Clues | Handling | Evidence/Recommendations

Required risk categories to cover:

  • R0 System Type
  • R4 Bulk Capability/Export
  • R5 Observation Leakage (Logs/Tracking/Error Reporting)
  • R6 Secrets/Credentials
  • R7 Third-Party Boundary
  • R11 Zero Human Access to High-Sensitivity Data (Video/Address/Phone)
  • R12 Retention & Deletion/DSAR
  • R14 Agent Skills Supply Chain
  • R15 Location Permissions

Step 3: Categorized Handling by Rules

Company Standard Items (enforced by default, no clarification needed)

If evidence is insufficient: handling = Default standard + recommendation, with the gap marked as "evidence needed (not clarification)":

  • Unified Observability SDK + masking/export restrictions/audit (R5)
  • Secrets/credentials: Secret Zero, no plaintext/hard-coded, rotation and audit (R6)
  • CI/Helm/IaC must use Vault injection and controlled references
  • Ops/support access boundary: restricted platform, default masking, default no-export, ticket-bound, full audit

Agent Skills Supply Chain (R14, triggered when Skills files detected)

If the MR/repository contains SKILL.md, .cursor/skills/, .cursor/rules/, AGENTS.md:

  • Check for prompt injection patterns (ignore previous instructions, bypass safety, etc.)
  • Check for hard-coded credentials (API Keys, Tokens, connection strings)
  • Check for executable scripts (scripts/ directory; risk is 2.12x that of instruction-only Skills)
  • Check for hidden HTML comments (<!-- -->, invisible to humans but readable by LLMs)
  • Check for internal information leakage (internal domains, IP addresses)
  • If none of the above files exist: mark Not Relevant (N/A)

Must-Clarify Items (blocking when missing)

  • System type
  • Whether new/relaxed export/bulk capability is added (export/download/csv/xlsx/report/bulk/batch clues)
  • Third-party boundary (new/modified third-party SDK/Webhook/external API, visible field mappings)
  • Encryption and key management (involving PIN/password/OTP/token/key/Private Key, etc.)
  • New PII fields and masking approach (beyond user_id/SN/email)

Location Permissions (R15, company-level privacy red line)

Absolutely prohibited to request user geolocation permissions on any platform, including but not limited to:

  • Android: ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, ACCESS_BACKGROUND_LOCATION
  • iOS: NSLocationWhenInUseUsageDescription, NSLocationAlwaysUsageDescription
  • Web: navigator.geolocation, Permissions API geolocation
  • Flutter: geolocator, location and other location plugins

City/region information may only be obtained through user's active selection. The selection result must be persisted and not re-asked.

Red Lines (finding triggers failure)

  • Employee (including ops/support) can directly access/export raw video: immediate Remediation Required / Fail
  • Plaintext storage/transmission/logging of passwords, tokens, keys, or other credential elements: high-risk blocking
  • Human-viewable entry points for high-sensitivity data (address/phone): immediate Remediation Required / Fail
  • Requesting any form of geolocation permission: immediate Remediation Required / Fail (R15)

Output Structure

Must strictly follow this Markdown structure:

2.0 Scope & Gates

- **scope**: Modules/directories/PR scope covered by this review
- **System type and adopted strategy**: Consumer-facing / Internal product / Mixed
- **Blocking items (if any)**: List blocking items (reference R#/G#/E#)
- **Clarification questions and unknowns**: Cover only the must-clarify checklist

2.1 Summary

- **Conclusion**: Pass / Conditional Pass / Fail
- **Risk level**: Low / Medium / High
- **Risk item summary**: Reference R#
- **Key evidence index**: List E# only

2.2 Risk Map

Risk IDRisk CategoryRelevanceTrigger CluesHandlingEvidence/Recommendations
R0System TypeRelevant/N/A/UnknownCluesClarify/Default standard+recommendation/BlockE#/Recommendations

2.3 Gap List

Gap IDGap DescriptionRisk LevelRelated Risk ItemEvidence ReferenceRecommended Remediation
G1DescriptionHigh/Medium/LowR#E#A#

2.4 Recommendations & Checklist (Actions)

PriorityAction IDRecommendationRelated GapEvidence Reference
Fix NowA1Specific recommendationG#E#

2.5 Evidence Appendix

Evidence IDEvidence TypeReferenceExcerpt
E1Doc/Code/Configpath:Lx-LyExcerpt

Examples

Bad - Hard-coded Secret

API_KEY = "sk-<account-id>abcdef"  # Violates R6

Good - Using Vault

API_KEY = vault.read('myapp/api-key')

For more examples, see references/REFERENCE.md.

Exemptions

ScenarioCondition
Local dev environmentConfiguration used only for local testing (must not be committed to repository)
Legacy system migrationLegacy system undergoing compliance remediation (migration plan must be provided)

Exemption method: /override skill=security-compliance-review reason="..." evidence="..."

References

What ships with it: 1 file

24.8 KB alongside SKILL.md

references/

Gives 0 of the 12 instructions most review quality skills give in ~1.5k tokens

Counted across 1,273 of the 2,403 authors here whose files we hold, read 2026-09-06

  • Ask one question at a timein 63 of 1273, across 62 files
  • Provide a recommended answer for each questionin 47 of 1273, across 45 files
  • Rank findings by severityin 44 of 1273
  • Use parameterized queries for database accessin 38 of 1273, across 20 files
  • Validate all user input with schemasin 33 of 1273, across 15 files
  • Store secrets in environment variablesin 32 of 1273, across 14 files
  • Explore the codebase to answer questionsin 31 of 1273, across 29 files
  • Store tokens in httpOnly cookiesin 30 of 1273, across 12 files
  • Implement rate limiting on API endpointsin 30 of 1273, across 12 files
  • Sanitize user-provided HTMLin 29 of 1273, across 11 files
  • Return generic error messages to usersin 28 of 1273, across 10 files
  • Cite file and line for every findingin 28 of 1273, across 25 files

Said here and by no other author read

  • Determine system type before proceeding
  • Output a risk map table
  • Check for executable scripts
  • Check for hidden HTML comments
  • Check for internal information leakage
  • Mark gaps as evidence needed if insufficient

Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.