Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Gibson Audit

ASecurity

Audit any repository for Gibson-readiness: what the product is, stack, test/CI/gate coverage, backlog shape, risk surfaces (money, auth, consent/PII, security boundaries, production data), and a plain-English readiness report with concrete gaps. First stage of the /gibson pipeline; also useful standalone ('audit this repo', 'is this repo ready for the fleet', 'gibson readiness check').

26 stars
0 votes
0 copies
0 views
Added 9/28/2026
ai-agentsgorailsgitsecurity

Security Analysis

A100/100

Scanned 9/28/2026

Install to Claude Code

$npx -y skills add The-AIE/the-gibson --skill gibson-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Gibson Audit?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Gibson Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/the-aie-gibson-audit/badge)](https://www.skillsdirectory.com/skills/the-aie-gibson-audit)

More formats (shields.io, HTML) on the badges page.

Files
SKILL.md
---
name: gibson-audit
description: "Audit any repository for Gibson-readiness: what the product is, stack, test/CI/gate coverage, backlog shape, risk surfaces (money, auth, consent/PII, security boundaries, production data), and a plain-English readiness report with concrete gaps. First stage of the /gibson pipeline; also useful standalone ('audit this repo', 'is this repo ready for the fleet', 'gibson readiness check')."
---

# gibson-audit — know the repo before touching it

Input: a repo path or GitHub URL (clone to a scratch location if URL-only).
Output: a readiness report the owner can read without knowing how to code, plus
a machine-usable gap list the `gibson-setup` skill consumes.

## What to inspect (read-only by default — the ONLY write this skill may ever make is persisting the audit report, and that goes through a worktree per Law 3)

1. **Product identity** — README, package.json/pyproject, deployed URLs. One
   paragraph: what this software does, for whom.
2. **Stack + build reality** — language, framework, how to build/test/run.
   Actually run the test suite if cheap; report pass/fail truthfully.
3. **Guardrails present vs missing** — checklist against the Gibson baseline:
   - `AGENTS.md` (or section) with fleet rules?
   - CI running tests on PRs? Required checks configured?
   - Branch protection on the default branch?
   - Risk classifier / Tier-C gating (money, auth, consent/PII, security
     boundaries, production data)?
   - DCO or sign-off convention?
   - Secrets hygiene (gitleaks or equivalent)?
   - Kill switch (`gibson/HALT` support comes free with the loop)?
4. **Backlog shape** — open issues: how many are well-scoped with acceptance
   criteria vs vague? Is there a plan doc? (No usable backlog → the pipeline
   must run `gibson-direct` before `gibson-run`.)
5. **Risk surfaces** — grep for ALL Law 7 categories: money/payments, auth,
   consent/PII, security boundaries (headers, rate limits, sandboxing), and
   anything touching production data. These paths get Tier-C treatment
   regardless of what the repo's own docs say.
6. **Deployment posture** — if a live/preview URL exists, run
   `scripts/posture-probe.sh <url>` from the Gibson clone for headers/cookies/
   rate-limit reality. Preview/staging only — never burst production.

## Report format

Two parts, always both:
- **For the owner (plain English, Ask Contract style):** what the repo is, how
  healthy it is, what's missing before agents can safely run unattended, and
  anything that genuinely needs their decision. No jargon unexplained.
- **Gap list (machine part):** checkbox list of missing guardrails with the
  exact `gibson-setup` action for each. Return it inline by default. If asked
  to persist it as `gibson/audit.md` in the target, that write goes through a
  worktree + branch like any other mutation (Law 3) — persisting the audit is
  the one thing that graduates this skill out of read-only mode, so it follows
  the write rules.

Truthfulness rule (Law 8): report what IS, including pre-existing test failures
and scary findings. Never soften a gap because it's awkward.

Attribution

The-AIEThe-AIE
View sourceMore from The-AIE →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

695601 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →