ouros-security-audit
Coordinate an authorized security audit of Ouros repositories and QA/local services
Install / Use
npx skills add Ouros-App/ouros-skills --skill ouros-security-auditInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of ouros-security-audit
ouros-security-audit scores 59/100 on our quality scale, 1085th of 1,116 Security skills we index.
Its SKILL.md is 2.7 KB long, well organised into 9 sections and no code examples: a solid amount of guidance for an agent.
It has no GitHub stars yet, so there is no community track record; judge it on its content.
Maintenance, license and trust
- We could not determine when the repository was last updated.
- No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
- Its trust signals score 68/100, with 3 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
ouros-security-audit compared with similar skills
All 4 of these similar skills score higher than ouros-security-audit; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| ouros-security-audit (this skill)by Ouros-App | 59 | 0 | — | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 13d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 13d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 14d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 14d ago | SKILL.md |
Frequently asked questions
- How do I install ouros-security-audit?
- Run
npx skills add Ouros-App/ouros-skills --skill ouros-security-audit. The install tabs above show the steps for each supported agent. - Which AI agents does ouros-security-audit work with?
- It is written for Zed, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is ouros-security-audit safe to use?
- It declares no license and scores 68/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is ouros-security-audit still maintained?
- We could not determine when the repository was last updated.
Skill content
View source on GitHubname: ouros-security-audit description: "Coordinate an authorized security audit of Ouros repositories and QA/local services. Use when the user asks for a broad security review, red-team-style assessment, attack-surface audit, pre-release security pass, or autonomous security campaign across multiple Ouros components."
Ouros Security Audit
Act as the security lead, not as an unrestricted attacker.
When Ouros-specific architecture matters, read ../../references/ouros-security-model.md.
Inputs to establish
Use available repository/config context to resolve these without repeatedly asking the operator:
- repositories/components in scope;
- allowed runtime environments;
- available test identities and fixtures;
- whether runtime mutation is permitted;
- where findings should be written.
If runtime scope is not explicit, default to static analysis plus local/QA-only planning.
Workflow
1. Build the attack-surface map
Group discovered surfaces into identity/authentication, authorization/object ownership, APIs/business logic, AI/MCP/tools, data stores, secrets/configuration, CI/CD/supply chain, and deployment/observability.
Record only concrete surfaces found in code/config. Do not invent endpoints.
2. Prioritize hypotheses
Prefer tests that could demonstrate authentication/authorization bypass, cross-user or cross-tenant access, tool/MCP privilege expansion, sensitive-data exposure, secret exposure, or unsafe business-logic mutation.
Deprioritize cosmetic hardening until high-impact boundaries are covered.
3. Delegate by test type
- Runtime hypothesis -> load
../safe-runtime-testing/SKILL.md. - MIDAS/MCP/agent hypothesis -> load
../ouros-ai-security/SKILL.md. - Any candidate finding -> hand to
../finding-verifier/SKILL.mdbefore calling it confirmed.
4. Maintain finding states
Use exactly: hypothesis, testing, candidate, confirmed, rejected, blocked.
Never promote candidate to confirmed without independent reproduction or equivalently strong deterministic evidence.
5. Output
Maintain a compact campaign table with: surface | hypothesis | state | severity-if-confirmed | evidence-ref | owner/next-step.
For confirmed findings include affected component/boundary, prerequisites, minimal reproduction, expected vs observed behavior, impact, root cause, remediation direction, and a regression-test recommendation.
Hard safety boundaries
Do not target production by default, third-party infrastructure, perform destructive tests, persistence, credential harvesting, load/flood testing, modify pre-existing business data for convenience, or tamper with audit evidence.
Stop a runtime test if scope, resource ownership, rollback strategy, or cleanup target becomes ambiguous.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
