本文へ移動
cccskills
無料GitHub で公開

absolute-audit

Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without suppressing. Complements the built-in /security-review. Triggers on "absolute audit", "security audit", "are we vulnerable", "scan for CVEs", "check for secrets/injection", "harden this".

インストール方法を見る

含まれるファイル(3)

  • SKILL.md4.6 KB
  • README.md808 B
  • references/health-engine.md5.3 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Start your first response with the 🔒 emoji.

Absolute Audit

Find and triage security problems across the repo — vulnerable dependencies (CVEs) and risky code patterns — then fix the ones worth fixing, safely. Output is a severity-ranked findings table with a remediation per item, not a raw scanner dump.

Runs the shared engine in references/health-engine.md — read it for the DETECT → SCAN → TRIAGE → FIX → VERIFY → REPORT loop and the safety contract. This file covers only what's specific to security auditing.

Authorized defensive use. This command audits the user's own repository to find and fix weaknesses. It is for hardening, not for attacking systems or evading detection.


When to use

  • "Run a security audit", "are we vulnerable?", "check our deps for CVEs".
  • After a CVE disclosure affecting something you use.
  • Periodic hygiene on main.

Distinct from the built-in /security-review (reviews the pending diff on your branch) — audit scans the whole committed repo, deps included. They complement.


What it scans

1. Dependency vulnerabilities (CVEs) — primary:

EcosystemScanner
npm / pnpm / yarnnpm audit --json / pnpm audit --json / yarn npm audit --json
Pythonpip-audit (preferred) or safety check
Gogovulncheck ./...
Cross-languageosv-scanner against the lockfile if available

2. Code-level patterns — read-only grep/static pass for high-signal issues only: hardcoded secrets/keys/tokens, eval/dynamic exec on input, SQL built by string concatenation, missing authz checks on sensitive routes, disabled TLS verification, unsafe deserialization, overly-broad CORS. Prefer the project's existing SAST/linter security rules (eslint-plugin-security, bandit, gosec) if configured.

Report suspected leaked secrets but never print the secret value — reference path:line and the kind.


Risk ranking (TRIAGE)

Rank by severity × exploitability × reachability, not raw CVSS:

SeverityDefault
Critical / High, reachable, fix availablefix now (wave 1)
Moderate, reachablefix this pass
Low / not reachable from app codereport, usually defer
Transitive-only, no direct upgrade pathflag, note the blocking parent

Mark each: is it reachable from the app's actual code paths? A CVE in an unused transitive branch is lower priority than a Moderate one on a hot path. State the fixed version or the mitigation for each.


Fix & verify

  • Dep CVEs → resolve via the smallest version move that clears it (delegate the actual bump mechanics to the upgrade flow's per-ecosystem steps). Prefer patched minors; escalate to a major only when that's the only fix, and gate it.
  • Code issues → apply the concrete fix (parameterize the query, move the secret to env
    • flag the leaked one for rotation, add the authz check). Each fix is its own small wave.
  • After each wave, re-run the scanner: the finding must actually disappear, and tests/build stay green. Never resolve by suppressing/allowlisting the alert.
  • Leaked live secrets: flag for rotation — removing from code doesn't undo exposure.

Gotchas

  1. Audit fatigue → blanket ignore. Triage by reachability instead of muting the scanner.
  2. Fixing a CVE by suppressing it. An allowlisted advisory is still a vulnerability.
  3. Printing the secret. Reference location + type only; never echo the value.
  4. Deleting a secret from code ≠ safe. It's in git history and was exposed — rotate it.
  5. Stopping at deps. Many real issues are in code, not the dependency tree — run both passes.

Companion commands

  • /absolute upgrade — does the actual version moves for vulnerable deps.
  • /security-review (built-in) — pair with this to also cover your pending diff.
  • /absolute work — if remediation is a real refactor (e.g. replacing an auth flow), hand off.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Lint and typecheck debt paydown: clear pre-existing repo-wide lint/type violations and suppressions (@ts-ignore, # type: ignore) one rule per wave, fixing causes not symptoms. Runs on green main. For diff-scoped quality use absolute-simplify. Triggers on "absolute debt", "fix our lint warnings", "clear the type errors", "get to strict mode", "burn down suppressions".

日本語の概要は準備中です。原文の説明を表示しています。

maddhruv/absolute2192026年7月6日 更新

Flaky test fixes: detect nondeterministic tests empirically (repeat/shuffle/parallel runs), diagnose the root cause, fix it — never retry/skip/sleep — and verify across many randomized runs. Triggers on "absolute deflake", "fix flaky tests", "CI is flaky", "this test fails randomly/intermittently".

日本語の概要は準備中です。原文の説明を表示しています。

maddhruv/absolute2192026年7月6日 更新

Diátaxis-driven documentation for AI coding agents: write, improve, or audit tutorials, how-tos, reference, explanation, and developer docs (README, CONTRIBUTING, ADRs). Detects the docs stack; gates on the outline before writing prose; verifies every claim against the code before it ships. Triggers on "absolute docs", "write docs", "write a tutorial", "write a README", "document this", "improve this doc", "audit our docs".

日本語の概要は準備中です。原文の説明を表示しています。

maddhruv/absolute2192026年7月6日 更新

One-time setup for absolute: interview how you want it to behave (output style, autonomy, TDD strictness, spec dir, families) + detect the stack once, then write `.absolute.config.json` (project, committed) and `~/.absolute/config.json` (user defaults + per-project overrides). Every other absolute-* command reads it instead of re-detecting; non-blocking — commands proceed without it and soft-recommend it. Triggers on "absolute init", "set up absolute", "initialize absolute", "configure absolute", "first-time setup", "remember my conventions for this repo".

日本語の概要は準備中です。原文の説明を表示しています。

maddhruv/absolute2192026年7月6日 更新

Dead code and dependency cleanup, repo-wide: unused deps, unreferenced exports, unreachable code, orphaned files — removed only with tool evidence, in reversible waves. Runs on green main. For diff-scoped cleanup use absolute-simplify. Triggers on "absolute prune", "remove dead code", "find unused deps/exports", "what can we delete", "clean up orphaned files".

日本語の概要は準備中です。原文の説明を表示しています。

maddhruv/absolute2192026年7月6日 更新

Use when the user wants to simplify, clean up, refactor, tidy, or refine code — their staged/unstaged git changes or a target file/path. Reduces complexity, flattens nesting, removes redundancy and dead code, scores each change by value (holding low-value churn), then runs tests to prove nothing broke. Invoke on: "simplify", "simplify this", "simplify my code/changes", "clean up", "clean this up", "clean up my changes", "refactor this", "make this cleaner", "tidy this up", "reduce complexity", "flatten this", "remove dead code", "make it more readable", "polish before commit", or "absolute simplify". Acts on your working diff; for repo-wide dead code use absolute-prune; for lint/type debt use absolute-debt.

日本語の概要は準備中です。原文の説明を表示しています。

maddhruv/absolute2192026年7月6日 更新

maddhruv のスキルをすべて見る

このスキルの問題を報告する