Install
$ agentstack add skill-jbdamask-john-claude-skills-repo-security-review Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.
Security review
⚠ Flagged2 finding(s); flagged for manual review. · v0.1.0 How review works →
- • Prompt-injection patterns
- • Secret / credential exfiltration
- • Dangerous shell & filesystem operations
- • Untrusted network calls
- • Known-malicious package signatures
- high Dangerous shell/eval execution.
- high Pipes remote content directly into a shell (remote code execution).
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ● Dynamic code execution Used
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Repo Security Review
Perform security audits on GitHub repositories to identify data exfiltration, malicious code, or suspicious behavior before installation.
Workflow
1. Gather Repository Info
- Fetch the main page to understand what the project does
- Locate the GitHub repository URL
- Identify install scripts (install.sh, setup.py, Makefile, etc.)
2. Review Install Scripts
Fetch and analyze all install scripts for:
- URLs contacted - Should only be official sources (GitHub releases, package registries)
- Commands executed - Look for curl/wget to unknown hosts, eval of remote code
- File system access - Unexpected writes outside install directory
- Environment variables - Harvesting of secrets, API keys, credentials
3. Audit Source Code
Examine main application code for:
- Network calls - All HTTP/HTTPS requests and their destinations
- Data collection - Any telemetry, analytics, or phone-home behavior
- File access - Reading sensitive files (~/.ssh, ~/.aws, credentials)
- Obfuscated code - Base64 encoded strings, eval(), exec()
4. Check Dependencies
Review dependency files (package.json, go.mod, requirements.txt, Cargo.toml):
- Look for analytics/telemetry packages
- Check for typosquatted package names
- Verify packages are from reputable sources
5. Provide Assessment
Summarize findings with:
- Overall verdict (Safe / Caution / Unsafe)
- Network activity - All external endpoints contacted
- Data storage - Where data is stored (local vs remote)
- Red flags found - Any suspicious patterns
- Recommendation - Install as-is, build from source, or avoid
Red Flags Reference
See [references/red-flags.md](references/red-flags.md) for comprehensive list of suspicious patterns.
Key Suspicious Patterns (Quick Reference)
Install scripts:
curl | bashfrom non-official URLs- Hidden file creation (dotfiles outside expected locations)
- Modification of shell profiles to inject code
- Download and execute without verification
Source code:
- Hardcoded IPs or non-GitHub/official URLs
- Base64 encoded payloads
- Reading SSH keys, AWS credentials, browser data
- Sending data to analytics endpoints
- Obfuscated variable names
Dependencies:
analytics,telemetry,trackingpackages- Misspelled package names (typosquatting)
- Packages with very few downloads/stars
- Dependencies from personal GitHub repos
Output Format
## Security Review Summary: [Project Name]
### [Status Emoji] Install Script - [CLEAN/SUSPICIOUS/DANGEROUS]
[Findings]
### [Status Emoji] Application Code - [CLEAN/SUSPICIOUS/DANGEROUS]
[Findings]
### [Status Emoji] Dependencies - [CLEAN/SUSPICIOUS/DANGEROUS]
[Findings]
### Assessment
[Overall verdict and recommendation]
Use checkmarks for clean, warning signs for suspicious, X for dangerous.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: jbdamask
- Source: jbdamask/john-claude-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.