agentsclimarketplace

Absolute audit

Skill maddhruv/absolute/skills/absolute-audit

Absolute Skills to 10x your Development Lifecycle

Install
npx -y skills add maddhruv/absolute --skill absolute-audit

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

What its author says it does

Copied from the file, not written here

Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without suppressing. Complements the built-in /security-review. Triggers on "absolute audit", "security audit", "are we vulnerable", "scan for CVEs", "check for secrets/injection", "harden this".

The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

4.6 KB, as published. Nobody here has run it

Start your first response with the πŸ”’ emoji.

Absolute Audit

Find and triage security problems across the repo β€” vulnerable dependencies (CVEs) and risky code patterns β€” then fix the ones worth fixing, safely. Output is a severity-ranked findings table with a remediation per item, not a raw scanner dump.

Runs the shared engine in references/health-engine.md β€” read it for the DETECT β†’ SCAN β†’ TRIAGE β†’ FIX β†’ VERIFY β†’ REPORT loop and the safety contract. This file covers only what's specific to security auditing.

Authorized defensive use. This command audits the user's own repository to find and fix weaknesses. It is for hardening, not for attacking systems or evading detection.


When to use

  • "Run a security audit", "are we vulnerable?", "check our deps for CVEs".
  • After a CVE disclosure affecting something you use.
  • Periodic hygiene on main.

Distinct from the built-in /security-review (reviews the pending diff on your branch) β€” audit scans the whole committed repo, deps included. They complement.


What it scans

1. Dependency vulnerabilities (CVEs) β€” primary:

EcosystemScanner
npm / pnpm / yarnnpm audit --json / pnpm audit --json / yarn npm audit --json
Pythonpip-audit (preferred) or safety check
Gogovulncheck ./...
Cross-languageosv-scanner against the lockfile if available

2. Code-level patterns β€” read-only grep/static pass for high-signal issues only: hardcoded secrets/keys/tokens, eval/dynamic exec on input, SQL built by string concatenation, missing authz checks on sensitive routes, disabled TLS verification, unsafe deserialization, overly-broad CORS. Prefer the project's existing SAST/linter security rules (eslint-plugin-security, bandit, gosec) if configured.

Report suspected leaked secrets but never print the secret value β€” reference path:line and the kind.


Risk ranking (TRIAGE)

Rank by severity Γ— exploitability Γ— reachability, not raw CVSS:

SeverityDefault
Critical / High, reachable, fix availablefix now (wave 1)
Moderate, reachablefix this pass
Low / not reachable from app codereport, usually defer
Transitive-only, no direct upgrade pathflag, note the blocking parent

Mark each: is it reachable from the app's actual code paths? A CVE in an unused transitive branch is lower priority than a Moderate one on a hot path. State the fixed version or the mitigation for each.


Fix & verify

  • Dep CVEs β†’ resolve via the smallest version move that clears it (delegate the actual bump mechanics to the upgrade flow's per-ecosystem steps). Prefer patched minors; escalate to a major only when that's the only fix, and gate it.
  • Code issues β†’ apply the concrete fix (parameterize the query, move the secret to env
    • flag the leaked one for rotation, add the authz check). Each fix is its own small wave.
  • After each wave, re-run the scanner: the finding must actually disappear, and tests/build stay green. Never resolve by suppressing/allowlisting the alert.
  • Leaked live secrets: flag for rotation β€” removing from code doesn't undo exposure.

Gotchas

  1. Audit fatigue β†’ blanket ignore. Triage by reachability instead of muting the scanner.
  2. Fixing a CVE by suppressing it. An allowlisted advisory is still a vulnerability.
  3. Printing the secret. Reference location + type only; never echo the value.
  4. Deleting a secret from code β‰  safe. It's in git history and was exposed β€” rotate it.
  5. Stopping at deps. Many real issues are in code, not the dependency tree β€” run both passes.

Companion commands

  • /absolute upgrade β€” does the actual version moves for vulnerable deps.
  • /security-review (built-in) β€” pair with this to also cover your pending diff.
  • /absolute work β€” if remediation is a real refactor (e.g. replacing an auth flow), hand off.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.