core-security-audit
by chrissgon
Audit the workbench for security beyond what the scan sees: every skill, agent, agent override, provider, adapter, script, hook and CI workflow answered against the security checklist, each finding with file:line, a quote, a severity and a fix, high findings verified in the code, and the fixes grouped by owner in a dated audit record. Also vet a third-party skill before anyone installs it, with a verdict. Use this skill when someone asks for a security audit or review of the workbench, a periodic audit is due, a skill from outside is about to be installed ("is this skill safe?", "install this skill"), or the scan passes but something still looks risky.