mirror of
https://github.com/alirezarezvani/claude-skills.git
synced 2026-08-28 04:24:58 +00:00
The Skill Security Audit failed PR #984 with 2 CRITICAL CMD-INJECT findings on hivemind's Node scripts — pre-existing since #979 merged while Actions wasn't triggering; touching the skill's agent files pulled it into audit scope. Spawning headless opencode worker processes is this skill's core, documented function (SKILL.md Prerequisites + the PR #979 dependency disclosure), so the imports carry the auditor's own suppression directive with the justification inline. Re-audit: PASS, 0 critical / 0 high. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qgc6RYXWJPr5oW9DHU7zR4 |
||
|---|---|---|
| .. | ||
| assets | ||
| scripts | ||
| .gitignore | ||
| LICENSE.txt | ||
| SKILL.md | ||