/g The Contract Codex ← 返回动态 Catalog

Dependency Audit Triage Boundaries

Triage dependency audit results with explicit boundaries: audits only find known advisories, so verify before trusting a package and never commit secrets.

难度:advanced 分类:security-ops 来源:Security and Hardening - addyosmani/agent-skills (GitHub)

完整 Prompt(可直接复制)

/goal
GOAL:
Complete Dependency Audit Triage Boundaries for a production operations environment: Triage dependency audit results with explicit boundaries: audits only find known advisories, so verify before trusting a package and never commit secrets.

CONTEXT:
- Before editing, read the nearest AGENTS.md/CLAUDE.md, current issue or PLAN.md, and any failing logs already in the repo.
- Inspect workflow permissions, cloud IAM, release artifacts, and audit evidence.
- Establish a baseline by running or locating evidence for: `npm audit && git status --short`.

CONSTRAINTS:
- Keep the scope limited to this goal; do not expand into unrelated cleanup.
- Do not weaken tests, delete assertions, or mask errors to make verification pass.
- Respect the repository's AGENTS.md/CLAUDE.md instructions and existing patterns.
- Do not print, copy, rotate, or exfiltrate real secrets.
- Do not widen production permissions without a documented least-privilege reason.

DONE WHEN:
- The implementation or documentation directly satisfies: Triage dependency audit results with explicit boundaries: audits only find known advisories, so verify before trusting a package and never commit secrets.
- The verification command or evidence path succeeds: `npm audit && git status --short`.
- The final diff is scoped to the relevant files and has no unrelated formatting churn.

VERIFY:
- Run `npm audit && git status --short` or the closest repo-local equivalent if the exact command is not available.
- Capture before/after evidence for the behavior, metric, report, or artifact involved.
- If verification cannot run locally, stop and report the missing dependency instead of guessing success.

OUTPUT:
- Summarize changed files, key decisions, verification output, and remaining risks.
- Include any follow-up that is required for production rollout or human review.

STOP RULES:
- Pause if secrets, production access, stakeholder decisions, or destructive data operations are required.
- Pause after three failed fix attempts on the same symptom and challenge the root-cause hypothesis.
- Do not mark the goal complete until the current repository state has been audited against DONE WHEN.

来源与证据

原始来源: Security and Hardening - addyosmani/agent-skills (GitHub)

证据摘要: Audits only find known advisories; they do not catch a newly malicious or typosquatted package.; source: Security and Hardening - addyosmani/agent-skills (GitHub); type: tool-readme; verification: npm audit && git status --short