AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Platform Environment Skill Audit

skill-brilliantrough-agent-skills-platform-environment-skill-audit · by brilliantrough

Audit accelerator environment skills and platform/cluster docs for personal repository, user, Conda, credential, and validation-artifact leakage; use when republishing CUDA, MUSA, PPU, ROCm, or other server environment guidance for multiple users.

— No reviews yet
0 installs
0 views
— view→install

Install

$ agentstack add skill-brilliantrough-agent-skills-platform-environment-skill-audit

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • ✓ Prompt-injection patterns
  • ✓ Secret / credential exfiltration
  • ✓ Dangerous shell & filesystem operations
  • ✓ Untrusted network calls
  • ✓ Known-malicious package signatures

What it can access

  • ✓ Network access No
  • ✓ Filesystem access No
  • ✓ Shell / process execution No
  • ✓ Environment & secrets No
  • ✓ Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-brilliantrough-agent-skills-platform-environment-skill-audit)

Reliability & compatibility

✓ Security review passed
0 installs to date
— no reviews yet
● today

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Platform Environment Skill Audit? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Platform Environment Skill Audit

Use this skill before sharing a machine-specific accelerator skill or cluster runbook with another user or host.

Audit scope

Inspect the skill, every file it links to, and the commands it asks an agent to run. Separate portable guidance from local facts.

Search for:

  • personal usernames, initials, home directories, repositories, branches, and

experiment names;

  • absolute data, checkpoint, result, cache, Conda, Toolkit, and runtime paths;
  • hostnames, IP addresses, ports, mount names, account names, and scheduler

partitions;

  • credentials, tokens, proxy URLs, private package indexes, and shell history;
  • validation outputs that expose PIDs, job names, model names, or private data;
  • claims copied from another host without a current-host validation date.

Classification

Classify each fact as one of:

portable       valid for any supported installation
local-platform valid only for the named host or homogeneous host class
workload       belongs to one repository or experiment
sensitive      must not be published

Portable skills should use placeholders for user and storage roots. Local skills may name the host and paths, but must say so in the description and must not claim that another host has the same state. Workload details belong in the project, not in a platform skill.

Specialized accel-* trio (reflux path)

When auditing a specialized accel-platform-install / accel-pytorch-python / accel-pytorch-code-porting from the agent-skills repo, the platform layer is meant to be platform-generic but concrete:

  • Vendor-standard paths (e.g. /opt/musa, /usr/local/Ascend/..., /opt/maca,

official versioned user-space prefixes) and platform version facts classify as portable — valid for any host of that platform following the same install. Do not demand placeholders for them; vagueness here is a defect, not safety.

  • Host-bound facts (user home dirs, this host's /data mounts and capacity,

LVM/raw device names, hostname, IP, local-only tool paths) do not belong in the trio — move them to the host-layer skill (-environment / system-profile style, named per host, never refluxed). That host-layer skill is the "clearly named local platform skill" this audit prescribes.

  • Reject the trio only for host-bound facts, credentials, or claims copied

from another host without a current-host validation date — never merely for containing platform-standard absolute paths.

Required checks

  1. Search recursively for old storage roots, usernames, hostnames, credentials,

and copied validation dates.

  1. Resolve symlinks and report broken or cross-user targets.
  2. Verify every advertised path exists on the intended host.
  3. Confirm package, driver, Toolkit, library, and Python versions live.
  4. Distinguish installation success, native linking, single-device compute,

collectives, and application validation.

  1. Remove secrets rather than masking only their display.
  2. Re-run the search after editing and report remaining intentional local facts.

Do not rewrite a local skill into vague portable advice when the local facts are its purpose. Instead, keep a portable install skill and a clearly named local platform skill with explicit ownership boundaries.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.