skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
blockmatic/basilic-skills647 installs

w-security

Review the change or tree against repository security docs and existing checks.

How do I install this agent skill?

npx skills add https://github.com/blockmatic/basilic-skills --skill w-security
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    The skill reviews repository changes for security defects by analyzing repository documentation and code. It presents a low risk of indirect prompt injection as it processes untrusted documentation and can execute local security scripts defined in the repository configuration.

  • Socketpass

    No alerts

  • Snykpass

    Risk: LOW · No issues

What does this agent skill do?

Find security defects relative to repository security docs and existing scanners. Do not invent CORS, encryption, password, or header policy. Stay report-only unless the user asked to fix.

  1. Read the repository security docs. If missing, stop and ask; do not invent a bar.
  2. Spawn 2–3 read-only explorers on authn/authz, secret/exposure, and input validation for the changed paths. Reconcile trigger and consequence yourself.
  3. Validate each suspected issue with a trigger and consequence. Skip invented CVEs and timings.
  4. If authorized, run existing security scripts or CI jobs from the docs or package.json. Record passed, failed, or not run.
  5. If fixes are authorized, change the owning cause. Policy changes need a human. Docs: /w-docs if behavior or commands changed.

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/blockmatic/basilic-skills/w-security">View w-security on skillZs</a>