Other

/cyber

Security audit for MCP, TS, Swift, shell, launchd plists. Triggers: security, vulnerability, hardening, traversal, injection, shell hardening, bash security, launchd plist, LaunchAgents, plist secret, raw API key in plist, secrets hygiene, op:// reference.

$ golems-cli skills install cyber
13 evals
3 workflows

Updated 1 week ago

You find the bugs that pass code review. Silent catches, unsanitized inputs, missing annotations, prompt injection --- the stuff that ships because "it works."

Security Audit: [target]

#SeverityFile:LinePatternFindingFix
1CRITICALserver.ts:818silent-catch.catch(() => {}) swallows registry errorLog error: .catch(e => console.error(...))

Summary

  • Critical: N | High: N | Medium: N | Low: N
  • ToolAnnotations coverage: N/M tools annotated
  • Verdict: PASS / PASS WITH NOTES / FAIL

---

## DOMAIN ROUTING

Route to the appropriate workflow based on what you're auditing:

| Task | Workflow |
|------|----------|
| Audit an MCP server | `/cyber:workflows:mcp-audit` |
| Review a PR for security | `/cyber:workflows:pr-review` |
| Full repo security scan | `/cyber:workflows:repo-scan` |
| Harden a bash script | [references/shell.md](references/shell.md) |
| Lint launchd plists for hardcoded secrets | [references/launchd-secrets.md](references/launchd-secrets.md) |

---

## Shell and launchd

**Bash** (full checklist: [references/shell.md](references/shell.md), formerly `/shell-hardening`),
applied to every script before committing:
- `set -euo pipefail`; quote every path; `mktemp` + `trap` cleanup; `shellcheck` clean.
- Build JSON with `jq --arg`, never `printf`; build commands as arrays; never `eval` or
  `bash -c "$string"` with input.
- Quote heredoc delimiters (`<<'EOF'`) whenever the body has backticks or `$()`, and always for
  collab/report/brief appends. An unquoted body executes.
- Under `pipefail`, buffer before an early-exit consumer (`head -1`, `grep -m1`,
  `awk '{exit}'`), because SIGPIPE turns into exit 141.

**launchd plists**: `python3 scripts/launchd-secret-linter/lint_cli.py ~/Library/LaunchAgents/*.plist`
exits 1 on a hardcoded secret in `EnvironmentVariables`. Values are never printed. Only an
`op://` reference or `$VAR` indirection is hardened. Flag a finding, never auto-rotate. Details:
[references/launchd-secrets.md](references/launchd-secrets.md).

---

Workflows

/cyber:mcp-audit/cyber:pr-review/cyber:repo-scan