SkillAgentSearch skills...

ouros-security-audit

Coordinate an authorized security audit of Ouros repositories and QA/local services

Install / Use

npx skills add Ouros-App/ouros-skills --skill ouros-security-audit

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

59/100

Category

Security

Supported Platforms

Zed

Our assessment of ouros-security-audit

ouros-security-audit scores 59/100 on our quality scale, 1085th of 1,116 Security skills we index.

Its SKILL.md is 2.7 KB long, well organised into 9 sections and no code examples: a solid amount of guidance for an agent.

It has no GitHub stars yet, so there is no community track record; judge it on its content.

Substance
26/30
Structure
13/20
Description
12/15
Adoption
0/20
Freshness
5/15

Maintenance, license and trust

  • We could not determine when the repository was last updated.
  • No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
  • Its trust signals score 68/100, with 3 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

ouros-security-audit compared with similar skills

All 4 of these similar skills score higher than ouros-security-audit; compare them before choosing.

SkillScoreStarsUpdatedFormat
ouros-security-audit (this skill)by Ouros-App590—SKILL.md
algorithmic-artby anthropics100177.9k13d agoSKILL.md
pptxby anthropics100177.9k13d agoSKILL.md
designby nextlevelbuilder100130.2k14d agoSKILL.md
ui-ux-pro-maxby nextlevelbuilder100130.2k14d agoSKILL.md

Frequently asked questions

How do I install ouros-security-audit?
Run npx skills add Ouros-App/ouros-skills --skill ouros-security-audit. The install tabs above show the steps for each supported agent.
Which AI agents does ouros-security-audit work with?
It is written for Zed, as a SKILL.md file. Other agents that read the same format can often use it too.
Is ouros-security-audit safe to use?
It declares no license and scores 68/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is ouros-security-audit still maintained?
We could not determine when the repository was last updated.

name: ouros-security-audit description: "Coordinate an authorized security audit of Ouros repositories and QA/local services. Use when the user asks for a broad security review, red-team-style assessment, attack-surface audit, pre-release security pass, or autonomous security campaign across multiple Ouros components."

Ouros Security Audit

Act as the security lead, not as an unrestricted attacker.

When Ouros-specific architecture matters, read ../../references/ouros-security-model.md.

Inputs to establish

Use available repository/config context to resolve these without repeatedly asking the operator:

  • repositories/components in scope;
  • allowed runtime environments;
  • available test identities and fixtures;
  • whether runtime mutation is permitted;
  • where findings should be written.

If runtime scope is not explicit, default to static analysis plus local/QA-only planning.

Workflow

1. Build the attack-surface map

Group discovered surfaces into identity/authentication, authorization/object ownership, APIs/business logic, AI/MCP/tools, data stores, secrets/configuration, CI/CD/supply chain, and deployment/observability.

Record only concrete surfaces found in code/config. Do not invent endpoints.

2. Prioritize hypotheses

Prefer tests that could demonstrate authentication/authorization bypass, cross-user or cross-tenant access, tool/MCP privilege expansion, sensitive-data exposure, secret exposure, or unsafe business-logic mutation.

Deprioritize cosmetic hardening until high-impact boundaries are covered.

3. Delegate by test type

  • Runtime hypothesis -> load ../safe-runtime-testing/SKILL.md.
  • MIDAS/MCP/agent hypothesis -> load ../ouros-ai-security/SKILL.md.
  • Any candidate finding -> hand to ../finding-verifier/SKILL.md before calling it confirmed.

4. Maintain finding states

Use exactly: hypothesis, testing, candidate, confirmed, rejected, blocked.

Never promote candidate to confirmed without independent reproduction or equivalently strong deterministic evidence.

5. Output

Maintain a compact campaign table with: surface | hypothesis | state | severity-if-confirmed | evidence-ref | owner/next-step.

For confirmed findings include affected component/boundary, prerequisites, minimal reproduction, expected vs observed behavior, impact, root cause, remediation direction, and a regression-test recommendation.

Hard safety boundaries

Do not target production by default, third-party infrastructure, perform destructive tests, persistence, credential harvesting, load/flood testing, modify pre-existing business data for convenience, or tamper with audit evidence.

Stop a runtime test if scope, resource ownership, rollback strategy, or cleanup target becomes ambiguous.

Related Skills

View on GitHub
GitHub Stars0
CategorySecurity
UpdatedNaNy ago
Forks0

Trust signals

68/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

2 medium1 low
ouros-security-audit — Zed Skill: Install & Safety Check | SkillAgent