sk Skill · nifrajs
security-checkup
Deterministic, no-AI security scan of the current repo: dependency advisories (osv-scanner), committed secrets (gitleaks), unsafe-pattern taint rules (semgrep), and the project verify gate. Normalizes every result into one Finding schema, writes .security/report.json + report.md, and exits with a CI-gateable contract. Makes no model calls and needs no API key.
Open on skills.sh ↗read 2026-09-15
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 1
- Connections
- 1
jsonbashTypeScript
- Host repository
- nifrajs/nifra
- Allowed tools
- Bash
- Host stars
- 3
- Host language
- TypeScript