Selective Reading Rule
Start with:
references/senior-master-standard.md
references/usage-routing.md
references/quality-checklist.md
Then load only the inherited docs, scripts, assets, or examples that match the user's actual task.
Audit Skills (Premium Universal Security)
Overview
Expert security auditor for AI Skills and Bundles. Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated payloads across Windows, macOS, Linux/Unix, and Mobile (Android/iOS).
2-4 sentences is perfect.
When to Use This Skill
- Use when you need to audit AI skills and bundles for security vulnerabilities
- Use when working with cross-platform security analysis
- Use when the user asks about verifying skill legitimacy or performing security reviews
- Use when scanning for mobile threats in AI skills
How It Works
Step 1: Static Analysis
Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated payloads.
Step 2: Platform-Specific Threat Detection
Analyzes code for platform-specific security issues across Windows, macOS, Linux/Unix, and Mobile (Android/iOS).
1. Privilege, Ownership & Metadata Manipulation
- Elevated Access:
sudo, chown, chmod, TakeOwnership, icacls, Set-ExecutionPolicy.
- Metadata Tampering:
touch -t, setfile (macOS), attrib (Windows), Set-ItemProperty, chflags.
- Risk: Unauthorized access, masking activity, or making files immutable.
2. File/Folder Locking & Resource Denial
- Patterns:
chmod 000, chattr +i (immutable), attrib +r +s +h, Deny ACEs in icacls.
- Global Actions: Locking or hiding folders in
%USERPROFILE%, /Users/, or /etc/.
- Risk: Denial of service or data locking.
3. Script Execution & Batch Invocation
- Legacy/Batch Windows:
.bat, .cmd, cmd.exe /c, vbs, cscript, wscript.
- Unix Shell:
.sh, .bash, .zsh, chmod +x followed by execution.
- PowerShell:
.ps1, powershell -ExecutionPolicy Bypass -File ....
- Hidden Flags:
-WindowStyle Hidden, -w hidden, -noprofile.
4. Dangerous Install/Uninstall & System Changes
- Windows:
msiexec /qn, choco uninstall, reg delete.
- Linux/Unix:
apt-get purge, yum remove, rm -rf /usr/bin/....
- macOS:
brew uninstall, deleting from /Applications.
- Risk: Removing security software or creating unmonitored installation paths.
5. Mobile Application & OS Security (Android/iOS)
- Android Tools:
adb shell, pm install, am start, apktool, dex2jar, keytool.
- Android Files: Manipulation of
AndroidManifest.xml (permissions), classes.dex, or strings.xml.
- iOS Tools:
xcodebuild, codesign, security find-identity, fastlane, xcrun.
- iOS Files: Manipulation of
Info.plist, Entitlements.plist, or Provisioning Profiles.
- Mobile Patterns: Jailbreak/Root detection bypasses, hardcoded API keys in mobile source, or sensitive permission requests (Camera, GPS, Contacts) in non-mobile skills.
- Risk: Malicious mobile package injection, credential theft from mobile builds, or device manipulation via ADB.
6. Information Disclosure & Network Exfiltration
- Patterns:
curl, wget, Invoke-WebRequest, Invoke-RestMethod, scp, ftp, nc, socat.
- Sensible Data:
.env, .ssh, cookies.sqlite, Keychains (macOS), Credentials (Windows), keystore (Android).
- Intranet: Scanning internal IPs or mapping local services.
7. Service, Process & Stability Manipulation
- Windows:
Stop-Service, taskkill /f, sc.exe delete.
- Unix/Mac:
kill -9, pkill, systemctl disable/stop, launchctl unload.
- Low-level: Direct disk access (
dd), firmware/BIOS calls, kernel module management.
8. Obfuscation & Persistence
- Encoding:
Base64, Hex, XOR loops, atob().
- Persistence:
reg add (Run keys), schtasks, crontab, launchctl (macOS), systemd units.
- Tubes:
curl ... | bash, iwr ... | iex.
9. Legitimacy & Scope (Universal)
- Registry Alignment: Cross-reference with
CATALOG.md.
- Structural Integrity: Does it follow the standard repo layout?
- Healthy Scope: Does a "UI Design" skill need
adb shell or sudo?
Step 3: Reporting
Generates a security report with a score (0-10), platform target identification, flagged actions, threat analysis, and mitigation recommendations.
Examples
Example 1: Security Review
"Perform a security audit on this skill bundle"
Example 2: Cross-Platform Threat Analysis
"Scan for mobile threats in this AI skill"
Best Practices
- ✅ Perform non-intrusive analysis
- ✅ Check for privilege escalation patterns
- ✅ Look for information disclosure vulnerabilities
- ✅ Analyze cross-platform threats
- ❌ Don't execute potentially malicious code during audit
- ❌ Don't modify the code being audited
- ❌ Don't ignore mobile-specific security concerns
Common Pitfalls
Problem: Executing code during audit
Solution: Stick to static analysis methods only
Problem: Missing cross-platform threats
Solution: Check for platform-specific security issues on all supported platforms
Problem: Failing to detect obfuscated payloads
Solution: Look for encoding patterns like Base64, Hex, XOR loops, and atob()
Related Skills
@security-scanner - Additional security scanning capabilities
Limitations
- Use this skill only when the task clearly matches the scope described above.
- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.
1---2name: audit-skills3description: ALWAYS use this when the request matches Audit Skills: Expert security auditor for AI Skills and Bundles.4---56## Selective Reading Rule78Start with:910- `references/senior-master-standard.md`11- `references/usage-routing.md`12- `references/quality-checklist.md`1314Then load only the inherited docs, scripts, assets, or examples that match the user's actual task.1516<!-- security-allowlist: curl-pipe-bash -->1718# Audit Skills (Premium Universal Security)1920## Overview2122Expert security auditor for AI Skills and Bundles. Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated payloads across Windows, macOS, Linux/Unix, and Mobile (Android/iOS).232-4 sentences is perfect.2425## When to Use This Skill2627- Use when you need to audit AI skills and bundles for security vulnerabilities28- Use when working with cross-platform security analysis29- Use when the user asks about verifying skill legitimacy or performing security reviews30- Use when scanning for mobile threats in AI skills3132## How It Works3334### Step 1: Static Analysis3536Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated payloads.3738### Step 2: Platform-Specific Threat Detection3940Analyzes code for platform-specific security issues across Windows, macOS, Linux/Unix, and Mobile (Android/iOS).4142#### 1. Privilege, Ownership & Metadata Manipulation43- **Elevated Access**: `sudo`, `chown`, `chmod`, `TakeOwnership`, `icacls`, `Set-ExecutionPolicy`.44- **Metadata Tampering**: `touch -t`, `setfile` (macOS), `attrib` (Windows), `Set-ItemProperty`, `chflags`.45- **Risk**: Unauthorized access, masking activity, or making files immutable.4647#### 2. File/Folder Locking & Resource Denial48- **Patterns**: `chmod 000`, `chattr +i` (immutable), `attrib +r +s +h`, `Deny` ACEs in `icacls`.49- **Global Actions**: Locking or hiding folders in `%USERPROFILE%`, `/Users/`, or `/etc/`.50- **Risk**: Denial of service or data locking.5152#### 3. Script Execution & Batch Invocation53- **Legacy/Batch Windows**: `.bat`, `.cmd`, `cmd.exe /c`, `vbs`, `cscript`, `wscript`.54- **Unix Shell**: `.sh`, `.bash`, `.zsh`, `chmod +x` followed by execution.55- **PowerShell**: `.ps1`, `powershell -ExecutionPolicy Bypass -File ...`.56- **Hidden Flags**: `-WindowStyle Hidden`, `-w hidden`, `-noprofile`.5758#### 4. Dangerous Install/Uninstall & System Changes59- **Windows**: `msiexec /qn`, `choco uninstall`, `reg delete`.60- **Linux/Unix**: `apt-get purge`, `yum remove`, `rm -rf /usr/bin/...`.61- **macOS**: `brew uninstall`, deleting from `/Applications`.62- **Risk**: Removing security software or creating unmonitored installation paths.6364#### 5. Mobile Application & OS Security (Android/iOS)65- **Android Tools**: `adb shell`, `pm install`, `am start`, `apktool`, `dex2jar`, `keytool`.66- **Android Files**: Manipulation of `AndroidManifest.xml` (permissions), `classes.dex`, or `strings.xml`.67- **iOS Tools**: `xcodebuild`, `codesign`, `security find-identity`, `fastlane`, `xcrun`.68- **iOS Files**: Manipulation of `Info.plist`, `Entitlements.plist`, or `Provisioning Profiles`.69- **Mobile Patterns**: Jailbreak/Root detection bypasses, hardcoded API keys in mobile source, or sensitive permission requests (Camera, GPS, Contacts) in non-mobile skills.70- **Risk**: Malicious mobile package injection, credential theft from mobile builds, or device manipulation via ADB.7172#### 6. Information Disclosure & Network Exfiltration73- **Patterns**: `curl`, `wget`, `Invoke-WebRequest`, `Invoke-RestMethod`, `scp`, `ftp`, `nc`, `socat`.74- **Sensible Data**: `.env`, `.ssh`, `cookies.sqlite`, `Keychains` (macOS), `Credentials` (Windows), `keystore` (Android).75- **Intranet**: Scanning internal IPs or mapping local services.7677#### 7. Service, Process & Stability Manipulation78- **Windows**: `Stop-Service`, `taskkill /f`, `sc.exe delete`.79- **Unix/Mac**: `kill -9`, `pkill`, `systemctl disable/stop`, `launchctl unload`.80- **Low-level**: Direct disk access (`dd`), firmware/BIOS calls, kernel module management.8182#### 8. Obfuscation & Persistence83- **Encoding**: `Base64`, `Hex`, `XOR` loops, `atob()`.84- **Persistence**: `reg add` (Run keys), `schtasks`, `crontab`, `launchctl` (macOS), `systemd` units.85- **Tubes**: `curl ... | bash`, `iwr ... | iex`.8687#### 9. Legitimacy & Scope (Universal)88- **Registry Alignment**: Cross-reference with `CATALOG.md`.89- **Structural Integrity**: Does it follow the standard repo layout?90- **Healthy Scope**: Does a "UI Design" skill need `adb shell` or `sudo`?9192### Step 3: Reporting9394Generates a security report with a score (0-10), platform target identification, flagged actions, threat analysis, and mitigation recommendations.9596## Examples9798### Example 1: Security Review99100```markdown101"Perform a security audit on this skill bundle"102```103104### Example 2: Cross-Platform Threat Analysis105106```markdown107"Scan for mobile threats in this AI skill"108```109110## Best Practices111112- ✅ Perform non-intrusive analysis113- ✅ Check for privilege escalation patterns114- ✅ Look for information disclosure vulnerabilities115- ✅ Analyze cross-platform threats116- ❌ Don't execute potentially malicious code during audit117- ❌ Don't modify the code being audited118- ❌ Don't ignore mobile-specific security concerns119120## Common Pitfalls121122- **Problem:** Executing code during audit123 **Solution:** Stick to static analysis methods only124125- **Problem:** Missing cross-platform threats126 **Solution:** Check for platform-specific security issues on all supported platforms127128- **Problem:** Failing to detect obfuscated payloads129 **Solution:** Look for encoding patterns like Base64, Hex, XOR loops, and atob()130131## Related Skills132133- `@security-scanner` - Additional security scanning capabilities134135## Limitations136- Use this skill only when the task clearly matches the scope described above.137- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.138- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.