Audit code and dependencies for concrete exploitable weaknesses while preserving MaskShift’s intentionally permissive local execution philosophy.
Scanned 10/4/2026
npx -y skills add nafeeur/MaskShift --skill security-audit --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Security Audit?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/nafeeur-security-audit)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: security-audit
description: Audit code and dependencies for concrete exploitable weaknesses while preserving MaskShift’s intentionally permissive local execution philosophy.
---
# Pragmatic Security Audit
- Treat MaskShift as an owner-operated local harness with permissive execution; do not redesign it into an approval-heavy sandbox.
- Focus on accidental remote exposure, credential leakage, path traversal in HTTP routes, command injection in non-agent input, unsafe archive extraction, dependency compromise, and unauthenticated network binding.
- Preserve the autonomous default while making scope and activity visible through audit logs and an emergency stop.
- Verify that secrets are redacted from UI/API/log output and passed to child processes only when needed.
- Report concrete exploit paths and minimal fixes; avoid generic hardening checklists.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!