Audits cchb Rust source code for subprocess execution, path handling, JSONL parsing, sensitive-data leakage, and Rust safety/panic issues. Returns structured JSON findings. Read-only — no edits, no shell execution beyond grep/find/read. Used by the checking-cchb-security skill in parallel with…
Audits cchb supply chain (Cargo.toml/Cargo.lock direct dependencies) and CI/CD workflows for known CVEs, outdated versions, EOL GitHub Actions, and release-pipeline hardening. Performs active vulnerability lookup against RUSTSEC and the GitHub Security Advisories API. Returns structured JSON findings. Read-only — no…
Runs before the agent uses a tool for Write, Edit, MultiEdit and Bash tool calls, executing protect-config.sh and block-destructive.sh via bash (2 commands). From iselegant/cchb.
11 27d agoA
tokens not measured
originalApache-2.0