claude-skills/engineering
Claude d4ea125c2f
fix(skill-security-auditor): self-skip false positives via noqa directive
Security scanners legitimately reference dangerous patterns (eval, os.system,
subprocess shell=True, etc.) inside their own regex pattern definitions and
human-readable risk/fix descriptions. Auditing the auditor itself produced
17 CRITICAL false positives — all from its own pattern table. ship-gate had
the same issue (2 CRITICALs on a check description and a variable name
called eval_findings).

Fix:
- Add 'noqa: SEC-AUDITOR' / 'auditor:ignore-line' line-suppression directive
  to all three scan loops (code patterns, prompt-injection markdown,
  pip/npm runtime install detection).
- Annotate the 179 pattern-definition lines in skill_security_auditor.py
  (regex, risk, fix entries) and 4 cleanup shutil.rmtree calls.
- Annotate ship-gate's two flagged lines (SEC-13 check description and
  eval_findings variable usage).
- Annotate SKILL.md and references/threat-model.md tables that document
  attack patterns for human readers (HTML comment <!-- noqa: SEC-AUDITOR -->).

Verified end-to-end:
  skill-security-auditor self-audit: 17 CRITICAL -> 0 (PASS)
  ship-gate self-audit: 2 CRITICAL -> 0 (PASS)
  slo-architect: PASS (0/0)
  project-management WARN unchanged (no top-level SKILL.md, expected)
2026-05-10 07:21:24 +00:00
..
.claude-plugin chore(marketplace): correct skill counts in domain manifests + root marketplace 2026-05-10 07:20:42 +00:00
.codex release: v2.1.1 — skill optimization, agents, commands, reference splits (#297) 2026-03-09 15:54:25 +01:00
agenthub fix(agents): add maxTurns + skills + narrow tools per spec completeness 2026-05-04 23:05:34 -04:00
autoresearch-agent fix(plugins): restructure 9 multi-skill domain plugins into ./skills/ layout 2026-05-02 22:51:20 +02:00
behuman fix(plugins): restructure 21 single-skill plugins into ./skills/<name>/ layout 2026-05-02 22:33:59 +02:00
chaos-engineering feat(skills): ship chaos-engineering (Phase 3 — resilience testing discipline) 2026-05-09 21:24:16 +00:00
code-tour fix(plugins): restructure 21 single-skill plugins into ./skills/<name>/ layout 2026-05-02 22:33:59 +02:00
data-quality-auditor fix(plugins): restructure 21 single-skill plugins into ./skills/<name>/ layout 2026-05-02 22:33:59 +02:00
demo-video fix(plugins): restructure 21 single-skill plugins into ./skills/<name>/ layout 2026-05-02 22:33:59 +02:00
docker-development fix(plugins): restructure 21 single-skill plugins into ./skills/<name>/ layout 2026-05-02 22:33:59 +02:00
feature-flags-architect feat(skills): ship feature-flags-architect (Phase 1 pilot — dual-publish) 2026-05-09 06:10:43 +00:00
helm-chart-builder fix(plugins): restructure 21 single-skill plugins into ./skills/<name>/ layout 2026-05-02 22:33:59 +02:00
karpathy-coder fix(agents): add maxTurns + skills + narrow tools per spec completeness 2026-05-04 23:05:34 -04:00
kubernetes-operator feat(skills): ship kubernetes-operator (Phase 2 — operator pattern discipline) 2026-05-09 09:01:45 +00:00
llm-cost-optimizer fix(plugins): restructure 21 single-skill plugins into ./skills/<name>/ layout 2026-05-02 22:33:59 +02:00
llm-wiki fix(plugins): restructure 21 single-skill plugins into ./skills/<name>/ layout 2026-05-02 22:33:59 +02:00
prompt-governance fix(plugins): restructure 21 single-skill plugins into ./skills/<name>/ layout 2026-05-02 22:33:59 +02:00
skills fix(skill-security-auditor): self-skip false positives via noqa directive 2026-05-10 07:21:24 +00:00
slo-architect feat(slo-architect): Phase 4 — SLO/SLI/error-budget discipline (#605) 2026-05-10 07:39:05 +02:00
statistical-analyst fix(plugins): restructure 21 single-skill plugins into ./skills/<name>/ layout 2026-05-02 22:33:59 +02:00
terraform-patterns fix(plugins): restructure 21 single-skill plugins into ./skills/<name>/ layout 2026-05-02 22:33:59 +02:00