Github Security Audit

Security audit for GitHub repositories before integrating them into your stack. Seven dimensions: project health, code security, supply chain, code quality, license, MCP/plugin attack surface and external trust signals. Weighted scoring with ADOPT/EVALUATE/CAUTION/AVOID verdict and an HTML report. Inspired by Trail of Bits' supply-chain auditor and insecure-defaults frameworks. Activate with: audit repo, repo security, evaluate repo, evaluate library, evaluate dependency, review repo, supply chain, is this repo safe, security audit github, repo risk, evaluate MCP server, evaluate plugin, evaluate skill, evaluate integration. Also when the user shares a GitHub link and asks whether to integrate or trust it. Do NOT activate for own-codebase reviews or SEO audits.

Consultora-AMDT 09a51b5 4 files · 25.0 KB Updated

File contents

Consultora-AMDT/claude-github-security-audit/tree/main/en/github-security-audit commit 09a51b5879

Frequently asked questions

npx skillmds@latest add consultora-amdt/github-security-audit