blockmatic/basilic-skills647 installs
w-security
Review the change or tree against repository security docs and existing checks.
How do I install this agent skill?
npx skills add https://github.com/blockmatic/basilic-skills --skill w-securityIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill reviews repository changes for security defects by analyzing repository documentation and code. It presents a low risk of indirect prompt injection as it processes untrusted documentation and can execute local security scripts defined in the repository configuration.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Find security defects relative to repository security docs and existing scanners. Do not invent CORS, encryption, password, or header policy. Stay report-only unless the user asked to fix.
- Read the repository security docs. If missing, stop and ask; do not invent a bar.
- Spawn 2–3 read-only explorers on authn/authz, secret/exposure, and input validation for the changed paths. Reconcile trigger and consequence yourself.
- Validate each suspected issue with a trigger and consequence. Skip invented CVEs and timings.
- If authorized, run existing security scripts or CI jobs from the docs or package.json. Record passed, failed, or not run.
- If fixes are authorized, change the owning cause. Policy changes need a human. Docs:
/w-docsif behavior or commands changed.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/blockmatic/basilic-skills/w-security">View w-security on skillZs</a>