Skip to content

feat: add skill security audit - #2950

Open
liyangbing wants to merge 2 commits into
github:mainfrom
liyangbing:feat/add-skill-security-audit
Open

feat: add skill security audit#2950
liyangbing wants to merge 2 commits into
github:mainfrom
liyangbing:feat/add-skill-security-audit

Conversation

@liyangbing

Copy link
Copy Markdown

Summary

  • Add skill-security-audit, a read-only-by-default workflow for reviewing third-party Agent Skills, MCP servers, connectors, and desktop extensions before installation.
  • Cover capability inventory, sensitive-data flow, dependency and release provenance, evidence-based findings, and a least-privilege test plan.
  • Source and maintenance context: sandbaseai/awesome-workbuddy.

Validation

  • npm run skill:validate
  • npm run build
  • git diff --check

The generated skills index is included as required by CONTRIBUTING.md.

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

🔒 PR Risk Scan Results

Scanned 1 changed file(s).

Severity Count
🔴 High 0
🟠 Medium 0
ℹ️ Info 0

✅ No matching risk patterns were detected in changed files.

This is an automated soft-gate report. Findings indicate review targets and do not block merge by themselves.

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

🔴 Contributor Reputation Check: HIGH risk

Check Risk
Profile HIGH
Credential audit NONE

Maintainers: please review this contributor before merging.
See the workflow run for full details.
Automated check powered by AGT.

@github-actions github-actions Bot added the needs-review:HIGH Contributor reputation check flagged HIGH risk label Sep 5, 2026
@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

🔍 Vally Lint Results

✅ All checks passed

Scope Checked
Skills 1
Agents 0
Total 1
Severity Count
❌ Errors 0
⚠️ Warnings 0
ℹ️ Advisories 0

Summary

Level Finding
ℹ️ ✅ skill-security-audit (2/2 checks passed)
ℹ️ ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
ℹ️ ✓ spec-compliance: All spec checks passed.
ℹ️ ✓ [valid-refs] All file references across 1 skill(s) are valid.
ℹ️ ✓ valid-refs: All file references resolve to existing files within the skill directory.
ℹ️ 1 skill(s) linted, 1 passed
Full linter output
### Linting skills/skill-security-audit
✅ skill-security-audit (2/2 checks passed)
    ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
        ✓ spec-compliance: All spec checks passed.
    ✓ [valid-refs] All file references across 1 skill(s) are valid.
        ✓ valid-refs: All file references resolve to existing files within the skill directory.

1 skill(s) linted, 1 passed

@liyangbing

Copy link
Copy Markdown
Author

补充人工复核信息:本 PR 的 skill-security-audit 源码来自公开的 sandbaseai/awesome-workbuddy,对应文件已通过本仓库 38 项测试、git diff --check,并在本仓库的 Skill Security Audit安全审计记录 中公开。PR 的风险扫描和 Vally lint 均为通过;Contributor Reputation Check 显示 HIGH 属于维护者侧信誉门禁,我不会绕过它,请维护者按自己的贡献者政策人工确认来源和提交历史。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-review:HIGH Contributor reputation check flagged HIGH risk new-submission PR adds at least one new contribution skills PR touches skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant