TIKAZ中文
← Back to the 30-Skill catalog

🛠️ Independently installable TIKAZ Skill

skill-security-audit

Statically inspect third-party agent skills before installation for prompt injection, destructive commands, credential access, dependency risk, hidden network behavior, and unsafe permissions.

Workflow group: EngineeringSpecialist Skill

Evidence and core advantages

6-stage delivery loopSpecification, impact analysis, implementation, tests, security, and release evidence remain connected.
Change-impact firstRepository relationships and blast radius are checked before broad refactors.
Evidence-backed handoffA change is not called complete until native tests and relevant release checks pass.

These are inspectable workflow properties and quality gates, not untested performance percentages.

01

What it owns

Statically inspect third-party agent skills before installation for prompt injection, destructive commands, credential access, dependency risk, hidden network behavior, and unsafe permissions.

02

When to use it

Install and invoke this Skill directly when its named capability is the complete task. Use the suite orchestrator when the outcome crosses multiple capabilities.

03

Install independently

Copy only this Skill folder. No sibling Skill is required. Keep the destination folder identical to the Skill name.
Copy-Item -Recurse -LiteralPath '.\suites\engineering\skill-security-audit' -Destination '.\.agents\skills\skill-security-audit'

04

Try it directly

Use skill-security-audit on this Skill directory before installation. Classify blockers, cite exact evidence, and state any behavior static inspection cannot verify.

05

Execution contract

The single English execution source owns inputs, outputs, validation, fallback, and limits. User documentation never creates a second executable rule set.Open the execution source ↗

Skills in this group

engineeringcode-intelligenceengineering-deliveryskill-security-auditsupabase-operationsvideo-workbench