Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Superstack Outward

ASecurity

Going public — a push, PR creation or merge, a package publish, a release, an infra apply; run before any of them, and when the outward gate bounces a publish command. Writes the sweep receipt the gate checks. Skip for purely local work.

2 stars
0 votes
0 copies
0 views
Added 9/19/2026
ai-agentsgogitapi

Works with

cliapi

Security Analysis

A100/100

Scanned 9/19/2026

Install to Claude Code

$npx -y skills add debabsah/superstack --skill superstack-outward --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Superstack Outward?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Superstack Outward
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/debabsah-superstack-outward/badge)](https://www.skillsdirectory.com/skills/debabsah-superstack-outward)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: superstack-outward
description: Going public — a push, PR creation or merge, a package publish, a release, an infra apply; run before any of them, and when the outward gate bounces a publish command. Writes the sweep receipt the gate checks. Skip for purely local work.
---

# superstack-outward

Publishing is the one moment a mistake stops being reversible. The sweep checks what is about to ship — the delta, not the world — then writes a receipt so the outward gate lets the publish through. Every step prints what it found; "found nothing" is a result, stated with the command that looked.

## The sweep

1. **Secrets.** `gitleaks detect` if installed; otherwise grep the outgoing diff/files for key patterns (`-----BEGIN`, `api[_-]?key`, `token=`, passwords, connection strings). Any hit stops the publish until resolved — this step fails closed.
2. **Identity and AI traces.** Grep the outgoing content for AI-authorship trailers, model names, machine paths, internal usernames/emails that don't belong in public history. Check the commits being pushed, not just the working tree.
3. **Confidential terms.** If `.superstack/project.md` lists protected terms (client names, internal hosts), grep the outgoing content for them; offer to record the project's terms if none are listed and this repo has an employer/client context.
4. **Stale public claims.** Read what ships as a stranger would: version numbers, counts, "works on X" claims, install commands — spot-check each against the current tree. A README claim is a `Verified:`-grade claim.
5. **Repo-level extras** (first publish or plugin/package release): install/clone cold in a temp dir and confirm the documented entry path works.

## The receipt

Append one line to `.superstack/outward-pass`:

```
<YYYY-MM-DD HH:MM> swept: <what was covered> — findings: <n fixed / none>
```

The gate accepts a receipt for 60 minutes, then re-requires the sweep. Then retry the publish command. If the gate bounced something that genuinely isn't a publish, retrying the identical command passes once — and that override is logged to `.superstack/outward-log`, so a recurring override is a gate bug to report, not a habit to keep. One sanctioned exception: an incident mitigation (superstack-incident step 1) *is* a publish and overrides anyway — those entries are expected, noted in the incident's timeline, and its sweep runs at stability rather than before.

## Proportion

Scope the sweep to what ships: a docs-only push earns steps 2 and 4 on the docs; a first public release earns all five. Never claim a step you didn't run — the receipt line lists what was actually covered.

Attribution

debabsahdebabsah
View sourceMore from debabsah →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1066601 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

693161 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

651 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →