redhat-et/ripwire · skills/ripwire-security-scan/SKILL.md

ripwire-security-scan skillB

ripwire-security-scan is agent-read markdown (skill) from redhat-et/ripwire: Security review: (1) vet an untrusted SKILL.md or .mcp.json BEFORE installing it — the injection/exfiltration scanner; CRITICAL blocks the install; (2) audit code on an untrusted-input path (a deserializer, parser, exec of user data, network endpoint): taint reach, untested seams. One scan pass is the verdict..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

How to install

Latest version
mdr add redhat-et/ripwire/ripwire-security-scan@git:20260914.d09bb1b
Exact content
mdr add redhat-et/ripwire/ripwire-security-scan@sha256:316bd85ca2e807ca

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_dwqx3heygtpgaqg7.svg)](https://markdownregistry.com/a/art_dwqx3heygtpgaqg7)

0 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260914.d09bb1b latest2026-09-14 d09bb1b 11,233 BB view · diff
git:20260913.30a5a3c2026-09-13 30a5a3c 11,199 BB view · diff
git:20260907.9e1e9f92026-09-07 9e1e9f9 11,131 BB view · diff
git:20260821.4f48b532026-08-21 4f48b53 11,901 BB view · diff
git:20260820.0ae66542026-08-20 0ae6654 11,345 BB view · diff
git:20260810.cc63a3b2026-08-10 cc63a3b 9,270 BB view · diff
git:20260805.9a729ad2026-08-05 9a729ad 9,168 BB view

Audit of the latest version

B  16 of 17 checks passed. Deterministic, no model, same answer every run.
  • fail: No prompt-injection phrasing (matched: Ignore previous instructions)
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (11233 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

redhat-et/ripwire · 2,166 stars · license Apache-2.0 · pushed 2026-09-15 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_dwqx3heygtpgaqg7
GET https://markdownregistry.com/api/v1/resolve?ref=redhat-et/ripwire/ripwire-security-scan
GET https://markdownregistry.com/api/v1/blob/316bd85ca2e807ca792b5e8bedec2c0ac99780391a358805d08f5691b81b3c3d