Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Run read-only exposure checks for security advisories and write a structured local audit report.
.claude/skills/sickn33-cyber-audit/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-06 | ✗→✓ | ▲ Improved | 34% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 3% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 30% | 0% |
| case-11 | ✗→✓ | ▲ Improved | 37% | 0% |
| case-04 | ✓→✗ | ▼ Worse | 62% | 0% |
~/Documents/security-audits/.sudo. Never..md file (even if the verdict is "Not affected" — the audit trail matters).~/Documents/security-audits/YYYY-MM-DD-<short-kebab-slug>.md. Use today's date from the environment header.bash# --- Node / npm ecosystem (supply-chain advisories) --- which npm pnpm yarn; npm root -g; pnpm root -g 2>/dev/null ls /opt/homebrew/lib/node_modules # global npm find ~ -maxdepth 8 -type d -name "<pkg>" 2>/dev/null \ | grep -v -E "(Library/Caches|\.Trash)" # installed copies find ~/Documents ~/Desktop ~/Downloads -maxdepth 8 -type f \ \( -name "package.json" -o -name "package-lock.json" \ -o -name "pnpm-lock.yaml" -o -name "yarn.lock" \) 2>/dev/null \ | xargs grep -l "<pkg>" 2>/dev/null # direct + transitive # --- Python ecosystem --- which python3 pip pipx uv pip list 2>/dev/null | grep -i "<pkg>" find ~/Documents -maxdepth 6 -name "requirements*.txt" -o -name "pyproject.toml" \ -o -name "poetry.lock" -o -name "uv.lock" 2>/dev/null | xargs grep -l "<pkg>" 2>/dev/null # --- Homebrew / system binaries --- brew list --versions <formula> 2>/dev/null which <binary>; <binary> --version 2>/dev/null # --- Running processes / listeners (for RCE / network CVEs) --- pgrep -lf "<binary>" lsof -iTCP -sTCP:LISTEN -P -n 2>/dev/null | grep "<port>" # --- LaunchAgents / LaunchDaemons (persistence / autostart) --- ls ~/Library/LaunchAgents /Library/LaunchAgents /Library/LaunchDaemons 2>/dev/null \ | grep -i "<vendor>" # --- Env vars that change exposure (e.g. OLLAMA_HOST, listening addr) --- launchctl getenv <VAR>; grep -r "<VAR>" ~/.zshrc ~/.zprofile ~/.config 2>/dev/null # --- VS Code / browser extensions (for IDE-targeted advisories) --- ls ~/.vscode/extensions 2>/dev/null | grep -i "<ext>"
If the advisory mentions an ecosystem not above (Rust cargo, Go modules, Ruby gems, Docker images, etc.), apply the same pattern: global install path + manifest grep + running processes.
File: ~/Documents/security-audits/YYYY-MM-DD-<short-kebab-slug>.md
markdown# <Subject> — Audit **Date:** YYYY-MM-DD **Host:** the user's Mac ## <CVEs | Advisory> in scope - **<ID or source> "<Name>"** — <one-line description>. <Affected versions or scope>. ## Audit results | Check | Result | |---|---| | <Check 1> | <Result> | | <Check 2> | <Result> | ## Verdict **<Not affected. | Affected. | Partially affected.>** - <Rationale bullet 1> - <Rationale bullet 2> ## Action taken None — diagnostic only, no files modified, no <packages installed/removed | services started/stopped | firewall rules changed>. ## Follow-ups - <Actionable item, or "None" if truly nothing>
Match the tone of the two existing reports in ~/Documents/security-audits/ — terse, factual, bulleted, no hedging.
Never on your own. If the verdict is "Affected", list the remediation command in Follow-ups and stop. The user runs it.
Two existing reports in ~/Documents/security-audits/ show the expected style:
baseline-audit.md (long-form baseline audit — different format, do not mimic)YYYY-MM-DD-example-advisory.md and any newer YYYY-MM-DD-*.md files (this is the format to match)davidondrej/skills; verify local paths, tools, credentials, and agent features before acting.| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-20 | fail→fail | 8,626 | 8,391 | -3% | 1 | 1 | 0% | 1,522 | 2,114 | +39% | 0 | 0 | — |
case-01 | fail→fail | 11,015 | 29,972 | +172% | 1 | 1 | 0% | 792 | 3,617 | +357% | 0 | 0 | — |
case-02 | fail→fail | 25,821 | 19,745 | -24% | 1 | 1 | 0% | 867 | 2,186 | +152% | 0 | 0 | — |
case-03 | fail→fail | 15,693 | 25,992 | +66% | 1 | 1 | 0% | 3,114 | 4,382 | +41% | 0 | 0 | — |
case-04 | pass→fail | 8,080 | 10,583 | +31% | 1 | 1 | 0% | 1,300 | 2,111 | +62% | 0 | 0 | — |
case-05 | pass→pass | 16,335 | 34,193 | +109% | 1 | 1 | 0% | 1,583 | 4,071 | +157% | 0 | 0 | — |
case-06 | fail→pass | 10,878 | 3,696 | -66% | 1 | 1 | 0% | 1,594 | 2,139 | +34% | 0 | 0 | — |
case-07 | fail→fail | 7,600 | 7,123 | -6% | 1 | 1 | 0% | 1,249 | 1,819 | +46% | 0 | 0 | — |
case-08 | pass→fail | 7,465 | 12,193 | +63% | 1 | 1 | 0% | 1,145 | 2,018 | +76% | 0 | 0 | — |
case-09 | fail→pass | 11,784 | 5,086 | -57% | 1 | 1 | 0% | 2,222 | 2,291 | +3% | 0 | 0 | — |
case-10 | fail→pass | 8,639 | 2,446 | -72% | 1 | 1 | 0% | 1,405 | 1,825 | +30% | 0 | 0 | — |
case-11 | fail→pass | 9,454 | 3,474 | -63% | 1 | 1 | 0% | 1,509 | 2,071 | +37% | 0 | 0 | — |
case-12 | fail→fail | 8,775 | 14,486 | +65% | 1 | 1 | 0% | 497 | 2,047 | +312% | 0 | 0 | — |
case-13 | pass→fail | 21,386 | 10,312 | -52% | 1 | 1 | 0% | 3,467 | 2,041 | -41% | 0 | 0 | — |
case-14 | pass→fail | 6,691 | 9,398 | +40% | 1 | 1 | 0% | 1,256 | 2,042 | +63% | 0 | 0 | — |
case-15 | pass→fail | 11,089 | 14,171 | +28% | 1 | 1 | 0% | 2,119 | 2,256 | +6% | 0 | 0 | — |
case-16 | pass→pass | 8,160 | 4,264 | -48% | 1 | 1 | 0% | 1,399 | 2,181 | +56% | 0 | 0 | — |
case-17 | pass→pass | 10,331 | 8,893 | -14% | 1 | 1 | 0% | 1,949 | 2,826 | +45% | 0 | 0 | — |
case-18 | pass→pass | 12,452 | 5,218 | -58% | 1 | 1 | 0% | 2,240 | 2,462 | +10% | 0 | 0 | — |
case-19 | fail→fail | 6,296 | 3,248 | -48% | 1 | 1 | 0% | 1,201 | 2,071 | +72% | 0 | 0 | — |
case-21 | pass→pass | 7,993 | 3,472 | -57% | 1 | 1 | 0% | 1,219 | 1,981 | +63% | 0 | 0 | — |
case-22 | pass→fail | 5,368 | 11,270 | +110% | 1 | 1 | 0% | 962 | 2,434 | +153% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 11 counted toward the lift figure. The other 11 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of -9 percentage points is the difference between those two pass rates over the 11 comparable cases. 7 cases got worse with the skill loaded, and they are included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.