absolute-debt
Lint and typecheck debt paydown: clear pre-existing repo-wide lint/type violations and suppressions (@ts-ignore, # type: ignore) one rule per wave, fixing…
Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without suppressing. Complements the built-in /security-review. Triggers on "absolute audit",
$ npx -y skills add maddhruv/absolute --skill absolute-audit --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/absolute-auditContext preview
The summary Claude sees to decide when to auto-load this skill.
Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without suppressing. Complements the built-in /security-review. Triggers on "absolute audit",
name: absolute-audit version: 0.5.0 description: > Vulnerability and security scan (defensive, your own repo): dependency CVEs plus risky code patterns (secrets, injection, weak authz), severity x reachability triaged and remediated without suppressing. Complements the built-in /security-review. Triggers on "absolute audit", "security audit", "are we vulnerable", "scan for CVEs", "check for secrets/injection", "harden this". category: workflow tags: - workflow - security - audit - vulnerabilities - cve platforms: - claude-code - gemini-cli - openai-codex - mcp user-invocable: true argument-hint: "[target]" license: MIT maintainers: - github: maddhruv
> Start your first response with the 🔒 emoji.
Find and triage security problems across the repo — vulnerable dependencies (CVEs) and risky code patterns — then fix the ones worth fixing, safely. Output is a severity-ranked findings table with a remediation per item, not a raw scanner dump.
Runs the shared engine in **`references/health-engine.md`** — read it for the DETECT → SCAN → TRIAGE → FIX → VERIFY → REPORT loop and the safety contract. This file covers only what's specific to security auditing.
> **Authorized defensive use.** This command audits the user's *own* repository to find > and fix weaknesses. It is for hardening, not for attacking systems or evading detection.
---
Distinct from the built-in **`/security-review`** (reviews the *pending diff* on your branch) — `audit` scans the **whole committed repo**, deps included. They complement.
---
**1. Dependency vulnerabilities (CVEs)** — primary:
| Ecosystem | Scanner | |---|---| | npm / pnpm / yarn | `npm audit --json` / `pnpm audit --json` / `yarn npm audit --json` | | Python | `pip-audit` (preferred) or `safety check` | | Go | `govulncheck ./...` | | Cross-language | `osv-scanner` against the lockfile if available |
**2. Code-level patterns** — read-only grep/static pass for high-signal issues only: hardcoded secrets/keys/tokens, `eval`/dynamic exec on input, SQL built by string concatenation, missing authz checks on sensitive routes, disabled TLS verification, unsafe deserialization, overly-broad CORS. Prefer the project's existing SAST/linter security rules (`eslint-plugin-security`, `bandit`, `gosec`) if configured.
Report suspected leaked secrets but **never print the secret value** — reference `path:line` and the kind.
---
Rank by **severity × exploitability × reachability**, not raw CVSS:
| Severity | Default | |---|---| | Critical / High, reachable, fix available | fix now (wave 1) | | Moderate, reachable | fix this pass | | Low / not reachable from app code | report, usually defer | | Transitive-only, no direct upgrade path | flag, note the blocking parent |
Mark each: is it reachable from the app's actual code paths? A CVE in an unused transitive branch is lower priority than a Moderate one on a hot path. State the fixed version or the mitigation for each.
---
bump mechanics to the `upgrade` flow's per-ecosystem steps). Prefer patched minors; escalate to a major only when that's the only fix, and gate it.
stay green. Never resolve by suppressing/allowlisting the alert.
---
1. **Audit fatigue → blanket ignore.** Triage by reachability instead of muting the scanner. 2. **Fixing a CVE by suppressing it.** An allowlisted advisory is still a vulnerability. 3. **Printing the secret.** Reference location + type only; never echo the value. 4. **Deleting a secret from code ≠ safe.** It's in git history and was exposed — rotate it. 5. **Stopping at deps.** Many real issues are in code, not the dependency tree — run both passes.
---
A development workflow engine for AI coding agents. Eleven separate skills — a one-time absolute-init (interview + stack detection → config), a build loop you run every day (think → spec → plan → build → polish → document), plus an engineering-health family
Repo: maddhruv/absolute
Lint and typecheck debt paydown: clear pre-existing repo-wide lint/type violations and suppressions (@ts-ignore, # type: ignore) one rule per wave, fixing…
Flaky test fixes: detect nondeterministic tests empirically (repeat/shuffle/parallel runs), diagnose the root cause, fix it — never retry/skip/sleep — and…
Diátaxis-driven documentation for AI coding agents: write, improve, or audit tutorials, how-tos, reference, explanation, and developer docs (README,…
One-time setup for absolute: interview how you want it to behave (output style, autonomy, TDD strictness, spec dir, families) + detect the stack once, then…
Dead code and dependency cleanup, repo-wide: unused deps, unreferenced exports, unreachable code, orphaned files — removed only with tool evidence, in…
Use when the user wants to simplify, clean up, refactor, tidy, or refine code — their staged/unstaged git changes or a target file/path. Reduces complexity,…