agentsclimarketplace

Five agent security review

Skill onfire7777/universal-ai-skills-library/skills/five-agent-security-review

Use for five-agent-dev-team secret handling, workflow permissions, Docker safety, dependency audit, local binding, and supply-chain review.From its SKILL.md

Install
npx -y skills add onfire7777/universal-ai-skills-library --skill five-agent-security-review

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 14 stars14 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

0.7 KB, 120 tokens by cl100k_base, as published. Nobody here has run it

Five Agent Security Review

Check:

  • least-privilege workflow permissions
  • no secrets in code, config, logs, PR bodies, state, or docs
  • no broad OAuth/GitHub scopes without a spec reason
  • Docker compose output is not resolved into state or logs
  • services bind to 127.0.0.1 unless explicitly required
  • npm audit fix --force is never used
  • moderate advisories are handled by documented policy, not hidden

Evidence should be compact: command names, pass/fail, and redacted risk notes.

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.