vibeforge1111/spark-intelligence-builder · Archived

security-auditor

Audit local-agent systems, specs, and code for security weaknesses and hardening priorities.

First seen Jun 22, 2026

Installation

$ npx skills add vibeforge1111/spark-intelligence-builder --skill security-auditor

Summary

  • Audit local-agent systems, specs, and code for security weaknesses and hardening priorities.
  • Use when reviewing Spark Intelligence features, security-sensitive diffs, identity or pairing flows, host-execution boundaries, webhook adapters, auth and secret handling, or when producing a security grade and remediation list that others can reuse later.

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 4
License LICENSE
Default branch main
Open issues 1
Status Archived

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 2,092 B
  • docs SUMMARY.md 373 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 1 installs

SKILL.md

Security Auditor

Use this skill when work touches:

  • security review
  • pre-landing diff review
  • trust-boundary grading
  • hardening backlog creation
  • local-agent security posture checks
  • reusable audit reports for other builders

Read First

  • docs/SECURITYDOCTRINEV1.md
  • docs/IDENTITYANDSESSIONMODELSPEC_V1.md
  • docs/PROVIDERANDAUTHCONFIGSPEC_V1.md
  • docs/CODINGRULESETV1.md
  • docs/SECURITYRESEARCHPLANHERMESOPENCLAW.md
  • docs/OPENCLAWHERMESSECURITYHISTORYANALYSIS_2026-03-25.md

Then read:

  • references/audit-framework.md
  • references/competitor-findings.md

Core Doctrine

Audit for real security failures first:

  • identity confusion
  • host takeover paths
  • dangerous defaults
  • weak approvals
  • secret leakage
  • cross-session leakage

Do not get distracted by style before those are clear.

Workflow

  1. Identify the artifact being reviewed.
  2. Map the relevant trust boundaries.
  3. Check identity, session, auth, host, webhook, secret, and logging behavior.
  4. Compare the design against known OpenClaw and Hermes hardening classes.
  5. Grade the system.
  6. Produce severity-first findings and a hardening order.

Required Outputs

Return these explicitly:

  • security grade
  • critical findings
  • high findings
  • medium findings
  • low findings
  • open questions
  • hardening priorities
  • required tests

Review Rules

  • findings first
  • exploit paths before theory
  • boundary mistakes before optional improvements
  • remediation order before broad advice

Default Deliverable

The result should usually be a reusable security audit with:

  • grade
  • severity-ordered findings
  • concrete hardening steps
  • tests to add before shipping