Search

Security · alpha-omega-security/scrutineer

37 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Default pipeline scrutineer runs when a repository is added.

alpha-omega-security/scrutineer245—~2.9kAutomated safety check: PassMITtoday
2

Run bandit against the Python source in the repository and map its hits into the findings shape.

alpha-omega-security/scrutineer245—~615Automated safety check: NotesMITtoday
3

Audit the repository against the OpenSSF Baseline with darnit, resolve the controls darnit defers to LLM analysis or could not verify, and record per-control verdicts plus the attained Baseline level.

alpha-omega-security/scrutineer245—~1.4kAutomated safety check: NotesMITtoday
4

Run git-pkgs list and sbom against the repository and emit one envelope with per-section status.

alpha-omega-security/scrutineer245—~596Automated safety check: PassMITtoday
5

Mine repository history for security fixes that were never published as advisories, producing a cached worklist for threat-model and advisory-deep-dive.

alpha-omega-security/scrutineer245—~2.9kAutomated safety check: NotesMITtoday
6

File a low-severity finding as an ordinary public GitHub issue after explicit analyst confirmation.

alpha-omega-security/scrutineer245—~1.3kAutomated safety check: PassMITtoday
7

Generate a CycloneDX SBOM for the repository via git-pkgs sbom.

alpha-omega-security/scrutineer242—~290Automated safety check: PassMITyesterday
8

Run semgrep's p/security-audit and p/secrets rulesets and map hits into the findings shape.

alpha-omega-security/scrutineer242—~439Automated safety check: PassMITyesterday
9

Re-audit every past GHSA/CVE advisory published against this repository, anchored on each advisory's fix commit, for four failure modes, a regression of the original bug, a bypass of the fix, an…

alpha-omega-security/scrutineer242—~3.5kAutomated safety check: NotesMITyesterday
10

Decide whether a finding's suggested fix is a breaking change for top dependents.

alpha-omega-security/scrutineer242—~1.4kAutomated safety check: PassMITyesterday
11

Match the repository to a CVE Numbering Authority so disclosures route to the CNA's security contact when one covers the repo.

alpha-omega-security/scrutineer242—~1.2kAutomated safety check: PassMITyesterday
12

For one (finding, dependent) pair, decide whether the dependent's code reaches the upstream finding.

alpha-omega-security/scrutineer242—~989Automated safety check: PassMITyesterday
13

Compare open findings in one repository and record how they relate.

alpha-omega-security/scrutineer242—~1.6kAutomated safety check: PassMITyesterday
14

Build a read-only compromise timeline and evidence bundle from local Git history and public forge/archive records.

alpha-omega-security/scrutineer242—~2.1kAutomated safety check: NotesMITyesterday
15
15.Fork

Stage a scanned repository into a private repo in the configured GitHub organisation.

alpha-omega-security/scrutineer242—~3.3kAutomated safety check: PassMITyesterday
16

Draft operational mitigations for a finding consumers can apply before a fix ships.

alpha-omega-security/scrutineer242—~1.3kAutomated safety check: PassMITyesterday
17

Propose a code patch for a finding. An agent skill from alpha-omega-security/scrutineer.

alpha-omega-security/scrutineer242—~1.9kAutomated safety check: PassMITyesterday
18

Check whether known sinks in this application's dependencies are reachable from its own trust boundaries.

alpha-omega-security/scrutineer242—~1.9kAutomated safety check: PassMITyesterday
19

Map distinct externally reachable input-processing subsystems into focus areas for the threat-model skill to carry into later security audits.

alpha-omega-security/scrutineer242—~951Automated safety check: PassMITyesterday
20

After a finding has been marked fixed, watch the upstream for a release that contains the fix.

alpha-omega-security/scrutineer242—~1.3kAutomated safety check: PassMITyesterday
21

File a finding on the upstream repository through GitHub's private vulnerability reporting, request the temporary private fork, and push the proposed patch to it when available.

alpha-omega-security/scrutineer242—~2.6kAutomated safety check: PassMITyesterday
22

High-recall static source-code vulnerability scan adapted from Anthropic's defending-code reference harness.

alpha-omega-security/scrutineer242—~3.2kAutomated safety check: PassMITyesterday
23

Focused static audit of device firmware and IoT software for update, boot, provisioning, credential, debug-interface and device-communication boundary failures, using an ISVS-informed threat model.

alpha-omega-security/scrutineer242—~1.6kAutomated safety check: NotesMITyesterday
24

Focused static audit for attacker-controlled reads, requests, parsers, or error paths that can disclose files, metadata, secrets, or internal responses.

alpha-omega-security/scrutineer242—~2.2kAutomated safety check: NotesMITyesterday
25

Audit package manager clients, registries, and proxies against a bundled threat model.

alpha-omega-security/scrutineer242—~1kAutomated safety check: NotesMITyesterday
26

Focused static audit for real personal or customer-identifying data committed to source or exposed through logs, URLs, telemetry, exports, and responses.

alpha-omega-security/scrutineer242—~3kAutomated safety check: NotesMITyesterday
27

Focused static audit of web applications and APIs for session, browser-origin, upload and business-workflow boundary failures, using an ASVS-informed threat model.

alpha-omega-security/scrutineer242—~1.3kAutomated safety check: NotesMITyesterday
28

Map native languages, extension bridges, build tools, manifests, and dependencies after shallow Git submodules have been initialized.

alpha-omega-security/scrutineer242—~425Automated safety check: PassMITyesterday
29

Eval-only short-prompt variant of security-deep-dive for A/B testing against the production prompt.

alpha-omega-security/scrutineer242—~1.3kAutomated safety check: PassMITyesterday
30

Run brief --json to produce a structured overview of the repository.

alpha-omega-security/scrutineer242—~435Automated safety check: PassMITyesterday
31

Derive a project's security contract from its source and docs, then emit it as structured data other skills can cite.

alpha-omega-security/scrutineer242—~6.8kAutomated safety check: PassMITyesterday
32

Re-run a finding's reproduction against current HEAD, test its attack tree, grade five fixed evidence criteria, and account for every matched design control.

alpha-omega-security/scrutineer242—~5.7kAutomated safety check: PassMITyesterday
33

Fetch published GHSA and CVE advisories affecting any package this repository produces, via advisories.ecosyste.ms.

alpha-omega-security/scrutineer242—~696Automated safety check: PassMITyesterday
34

Normalize an externally-produced security report in an arbitrary format into scrutineer findings.

alpha-omega-security/scrutineer242—~1kAutomated safety check: PassMITyesterday
35

Fetch repository metadata (description, default branch, languages, license, stars, archived, icon) from repos.ecosyste.ms and save it on the repository row.

alpha-omega-security/scrutineer242—~748Automated safety check: PassMITyesterday
36

Look up every package this repository publishes across all registries via packages.ecosyste.ms, with downloads, dependent counts, latest version, registry URL and supply-chain risk flags.

alpha-omega-security/scrutineer242—~1.2kAutomated safety check: PassMITyesterday
37

Extract bounded operational lessons from a settled triage cohort without changing finding dispositions or suppressions.

alpha-omega-security/scrutineer242—~874Automated safety check: PassMITyesterday