Install
$ agentstack add skill-aborroy-aiup-alfresco-audit-config-validator ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Audit Config Validator
Validate the given custom Alfresco audit application against these rules.
XML Structure Validation
- The audit XML must be well-formed and its root `` element must declare the audit model
namespace http://www.alfresco.org/repo/audit/model/3.2.
- There must be exactly one `
with bothnameandkey` attributes.
Application Key / Enable Consistency
- The `` value must be lowercase and prefix-scoped.
- FLAG as ERROR if no
audit.{app-key}.enabledproperty is present in a companion
.properties file matching the key exactly.
- Why it breaks: the application is defined but never enabled, so nothing is recorded.
- WARN if
audit.enabled=true(the master switch) is not present anywhere in the project.
Extractor / Generator Wiring
- Every `
must reference a`
declared in ``.
- Every `
must reference a`
declared in ``.
- For each custom (non-built-in) ``, there must be a Spring
bean whose registeredName property matches, with parent="auditModelExtractorBase".
- FLAG as ERROR a
registeredNamewith no matching bean (the application fails to register
or records nothing).
Java Extractor Validation
- If a
*DataExtractor.javaexists, it mustextends AbstractDataExtractorand implement
isSupported and extractData.
- If a
*DataGenerator.javaexists, it mustextends AbstractDataGenerator.
Registration Validation
- The audit model must be registered via an
AuditModelRegistrationBean
(init-method="registerModel") whose auditModelUrl points at the audit XML on the classpath.
- The registering context must be imported from
module-context.xml. - WARN if `
is absent whiledataSource` paths reference a producer path that
is not mapped into the application namespace.
Output
Report all violations with file path, line number, rule violated, and suggested fix. If no violations found, confirm the audit application is valid.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: aborroy
- Source: aborroy/aiup-alfresco
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.