agentsclimarketplace

Risk audit

Skill jzills/claude-marketplace/plugins/shimmering-forest/skills/risk-audit

A Claude Code plugin marketplace with skills for git workflows, code quality, safety, and more.

Install
npx -y skills add jzills/claude-marketplace --skill risk-audit

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

View the shimmering-forest risk auditor's current configuration and recent audit log entries. Use when the user types "/risk-audit", asks to "show risk audit config", "check risk thresholds", "view audit log", "show blocked operations", or "what is shimmering-forest configured to block".

SKILL.md

3.8 KB, 932 tokens by cl100k_base, as published. Nobody here has run it

Risk Audit Viewer

You are helping the user inspect the shimmering-forest risk auditor plugin.

Arguments

The user invoked this with: $ARGUMENTS

If the argument is a number N (e.g. /risk-audit 20), show the last N log entries. If no argument is given, show the last 10 entries and the current config.

Step 1 — Read the config

Read ~/.claude/shimmering-forest.config.json.

If the file does not exist, tell the user:

No user config found. The plugin is using built-in defaults.

Then display the defaults:

SettingDefault
block_thresholdHigh
warn_thresholdMedium
show_all_scoresfalse
block_modehard
audit_logtrue
audit_log_path~/.claude/shimmering-forest.log
Excepted toolsRead
Excepted patterns(none)

If the file exists, display it as a formatted table:

SettingValue
cvss_version{cvss_version}
block_threshold{block_threshold}
warn_threshold{warn_threshold}
show_all_scores{show_all_scores}
block_mode{block_mode}
audit_log{audit_log}
audit_log_path{audit_log_path}
Excepted tools{exceptions.tool_names joined by ", "}
Excepted patterns{count of exceptions.command_patterns} custom patterns

Also show the severity bands for reference. Adjust the tier label based on cvss_version:

  • CVSS 4.0: show "None" for the 0.0 tier and list dimension names as VI / VC / VA / SI / PR
  • CVSS 3.1: show "Info" for the 0.0 tier and list dimension names as II / CI / AI / SC / PR
TierScore RangeDefault Action
Critical9.0–10.0Block
High7.0–8.9Block
Medium4.0–6.9Warn
Low0.1–3.9Allow
None / Info0.0Allow

Step 2 — Read recent log entries

Run the following to get the last N entries in reverse-chronological order (most recent first):

tail -n {N} {audit_log_path} | tac

If the file does not exist, say:

No audit log found yet — no operations have been scored in this installation.

If it exists, each line is a JSON object. Parse and display as a table, most recent entry at the top:

TimeToolScoreSeverityDecisionSubject
{ts}{tool_name}{score}{severity}{decision}{subject, truncated to 60 chars}

Step 3 — Summary statistics

From the displayed entries, compute and show:

  • Total entries shown
  • Breakdown by decision: X blocked, Y warned, Z allowed
  • Highest risk score seen and which tool/rule produced it
  • Most commonly scored tool

Step 4 — Offer next steps

End with:

To change thresholds, edit ~/.claude/shimmering-forest.config.json. To whitelist a command pattern, add a regex to exceptions.command_patterns. To whitelist a tool entirely, add its name to exceptions.tool_names.

If any blocked entries are shown, add:

Use /risk-audit 50 to see more history.

If the user's prompt asked specifically about a blocked operation (e.g. "is git push blocked?"), also offer the two concrete options for allowing it:

  1. Raise the block threshold — e.g. set block_threshold to "Critical" so only scores ≥ 9.0 are blocked:
    { "block_threshold": "Critical", "warn_threshold": "High" }
    
  2. Whitelist the specific command — add a regex to exceptions.command_patterns:
    { "exceptions": { "command_patterns": ["^git\\s+push\\b"] } }
    

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 326,970. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.