Skill-Audit-Bericht

phoenix-security-engineer Audit-Bericht.

Role 06 of the Phoenix Security spec pipeline. Produces a threat model and security requirements grounded in Phoenix Security's actual architecture: 6 trust boundaries (tenant↔platform, platform↔integrations, platform↔AI/LLM, platform↔CI/CD, platform↔AWS, CTI↔GCP), high-value asset inventory (vuln data, API keys, reachability results, SBOM, AI I/O, board reports), MITRE ATT&CK technique mapping, and regulatory hooks (NCSC, NIST, DORA, UK GDPR, CISA KEV). Use this skill when requirements need a security layer, when someone says "threat model this", "add security requirements", "what are the security risks", "AppSec review", or "what do we need to secure here". Always run after phoenix-ambiguity-hunter produces a clean spec, and before phoenix-contract-architect.

Blockiert · BlockierenPrüfung nötigErstellt 11. Okt. 2026Heuristisches Metadaten-Audit
73
Audit
62
Vertrauen
65
Qualität
70
Sicherheit
100
Maintain
92
Installieren

OpenAgentSkill Trust Score

62
Manuelle Prüfung

OpenAgentSkill Trust Score

The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.

GitHub-Akzeptanz

Warnung

48

70 GitHub-Stars

Star-/Fork-Aktivität

Warnung

43

70 Stars und 9 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbar

Aktuelle Wartung

Bestanden

100

30 Tage seit dem letzten Push

Lizenzklarheit

Bestanden

86

MIT

README/SKILL.md-Vollständigkeit

Info

76

Öffentliche Metadaten benötigen mehr README/SKILL.md-Kontext

Abhängigkeits-/Laufzeitrisiko

Warnung

46

command execution surface, credential or environment access

Installationsverfügbarkeit

Bestanden

92

npx skills add Security-Phoenix-demo/security-skills-claude-code --skill phoenix-security-engineer

Sicherheit des Installationsbefehls

Bestanden

92

Standard-Paket- oder Laufzeit-Installationspfad

Berechtigungsumfang

Fehlgeschlagen

18

secrets or environment access, shell or command execution

Repository-Nachweis

Bestanden

86

https://github.com/Security-Phoenix-demo/security-skills-claude-code/tree/main/plugins/phoenix-prd-pipeline/skills/phoenix-security-engineer

Prüfstatus

Info

66

KI-Prüfdaten verfügbar

Agent-validierte Ergebnisse

Info

54

Noch keine Agent-Ergebnisdaten

Prüfungen

Installations- und Adoptionsprüfung

6 Bestanden · 17 Prüfung nötig

Installationspfad

92

Bestanden

npx skills add Security-Phoenix-demo/security-skills-claude-code --skill phoenix-security-engineer

Repository

88

Bestanden

https://github.com/Security-Phoenix-demo/security-skills-claude-code/tree/main/plugins/phoenix-prd-pipeline/skills/phoenix-security-engineer

Lizenz

86

Bestanden

MIT

Wartung

100

Bestanden

30 Tage seit dem letzten Push

KI-Prüfung

55

Prüfen

References to PSC-03 and PSC-08 are not defined within the skill; they assume external context from the broader pipeline.

README/SKILL.md-Vollständigkeit

84

Bestanden

Usable description available

Abhängigkeitsrisiko

46

Beheben

command execution surface, credential or environment access

Sicherheit des Installationsbefehls

92

Bestanden

Standard-Paket- oder Laufzeit-Installationspfad

Berechtigungsumfang

18

Beheben

secrets or environment access, shell or command execution

Star-/Fork-Aktivität

43

Beheben

70 Stars und 9 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbar

Akzeptanz

68

Info

70 GitHub-Stars

Financial decision safety

58

Prüfen

Research-only use: do not treat output as financial advice or execute a position without human approval.

Warnungen

  • Dependency or permission surface needs review
  • Permission surface may require sandboxing
  • Financial research output is not financial advice; require human review before any live investment decision
  • References to PSC-03 and PSC-08 are not defined within the skill; they assume external context from the broader pipeline.
  • The skill is tightly coupled to Phoenix Security's architecture, limiting reuse outside that specific domain.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • GitHub adoption: 70 GitHub stars
  • Stars/forks activity: 70 stars, 9 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution

Methode

This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.

Nahe Optionen vergleichen

Ähnliche Skills als Nächstes prüfen