security-review is agent-read markdown (skill) from fmind/dot: Review and fix code security; scan secrets and vulnerabilities with Gitleaks and Trivy..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Security Review
Investigate and fix security defects with evidence. Choose code review, secret scanning, or vulnerability scanning from the task; findings need verification and scanners do not replace reasoning.
## Workflow
Read only the matching guide and its required resources. Use a known guide directly when shared prerequisites are not needed.
## Task guides
<!-- guides:start -->
- [code-review](references/code-review/GUIDE.md): Assess code and repository security; verify findings and repairs.
- [gitleaks](references/gitleaks.md): Secret scanning and verified exposure handling.
- [trivy](references/trivy/GUIDE.md): Dependency, configuration, image, license, and SBOM scanning.
<!-- guides:end -->
Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
A 17 of 17 checks passed. Deterministic, no model, same answer every run.
pass: Frontmatter block present
pass: Frontmatter declares a name
pass: Frontmatter declares a description
pass: Size between 200 bytes and 200 KB (1035 bytes)
pass: No zero-width or bidi control characters
pass: No instruction hidden inside an HTML comment
pass: No link to an exfiltration or paste host
pass: No credential-shaped string
pass: No instruction to send local credentials anywhere
pass: No text hidden with inline styles
pass: No prompt-injection phrasing
pass: No curl or wget piped into a shell
pass: No recursive delete of root, home or parent
pass: No instruction to read or print local credentials
pass: No base64 blob over 200 characters
pass: No link to a raw IP address
pass: No script tag
Source
GitHub
fmind/dot · 9 stars · license MIT · pushed 2026-09-24 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_vfugfvo44bcnpdht
GET https://markdownregistry.com/api/v1/resolve?ref=fmind/dot/security-review
GET https://markdownregistry.com/api/v1/blob/676dc60e02adb56ac5af14ece3454948ae4bd516c88bfb8c9d7a6939832f4f46
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
fmind/dot · .agents/skills/dot-verify/SKILL.md · Qualify the fmind/dot working tree before a release: review changes, sync docs, run every gate, and smoke-test the dot…
affaan-m/ecc · .agents/skills/security-review/SKILL.md · Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or…
affaan-m/ecc · .kiro/skills/security-review/SKILL.md · Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or…
affaan-m/ecc · docs/es/skills/security-review/SKILL.md · Usar este skill al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear endpoints de API o…
microsoft/power-platform-skills · plugins/power-pages/skills/security-review/SKILL.md · Runs a guided, end-to-end security review of a Power Pages site and consolidates every finding into one HTML report…