Triage dependency audit results with explicit boundaries: audits only find known advisories, so verify before trusting a package and never commit secrets.
/goal GOAL: Complete Dependency Audit Triage Boundaries for a production operations environment: Triage dependency audit results with explicit boundaries: audits only find known advisories, so verify before trusting a package and never commit secrets. CONTEXT: - Before editing, read the nearest AGENTS.md/CLAUDE.md, current issue or PLAN.md, and any failing logs already in the repo. - Inspect workflow permissions, cloud IAM, release artifacts, and audit evidence. - Establish a baseline by running or locating evidence for: `npm audit && git status --short`. CONSTRAINTS: - Keep the scope limited to this goal; do not expand into unrelated cleanup. - Do not weaken tests, delete assertions, or mask errors to make verification pass. - Respect the repository's AGENTS.md/CLAUDE.md instructions and existing patterns. - Do not print, copy, rotate, or exfiltrate real secrets. - Do not widen production permissions without a documented least-privilege reason. DONE WHEN: - The implementation or documentation directly satisfies: Triage dependency audit results with explicit boundaries: audits only find known advisories, so verify before trusting a package and never commit secrets. - The verification command or evidence path succeeds: `npm audit && git status --short`. - The final diff is scoped to the relevant files and has no unrelated formatting churn. VERIFY: - Run `npm audit && git status --short` or the closest repo-local equivalent if the exact command is not available. - Capture before/after evidence for the behavior, metric, report, or artifact involved. - If verification cannot run locally, stop and report the missing dependency instead of guessing success. OUTPUT: - Summarize changed files, key decisions, verification output, and remaining risks. - Include any follow-up that is required for production rollout or human review. STOP RULES: - Pause if secrets, production access, stakeholder decisions, or destructive data operations are required. - Pause after three failed fix attempts on the same symptom and challenge the root-cause hypothesis. - Do not mark the goal complete until the current repository state has been audited against DONE WHEN.
原始来源: Security and Hardening - addyosmani/agent-skills (GitHub)
证据摘要: Audits only find known advisories; they do not catch a newly malicious or typosquatted package.; source: Security and Hardening - addyosmani/agent-skills (GitHub); type: tool-readme; verification: npm audit && git status --short