auditing-security-logging-completeness skillA
auditing-security-logging-completeness is agent-read markdown (skill) from unboundcompute/security-agent-skills: Audit whether an application actually records the security events an investigation would need, and whether the logs themselves leak or lie: a security decision (authentication, an authorization denial or sensitive grant, a credential or privilege change, access to sensitive data) that fires with no durable record, an audit entry missing the actor, target, or outcome, secrets or personal data flowing into a widely-readable log, and untrusted input written to a log without neutralizing line breaks.
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
How to install
mdr add unboundcompute/security-agent-skills/auditing-security-logging-completeness@git:20260821.4f2a732mdr add unboundcompute/security-agent-skills/auditing-security-logging-completeness@sha256:d9525b6c0ae9d07aPin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_ww5sz635obcp7j3u)
0 badge views in 30 days
Versions
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (9148 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
unboundcompute/security-agent-skills · 5 stars · license MIT · pushed 2026-09-08 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_ww5sz635obcp7j3u GET https://markdownregistry.com/api/v1/resolve?ref=unboundcompute/security-agent-skills/auditing-security-logging-completeness GET https://markdownregistry.com/api/v1/blob/d9525b6c0ae9d07a5fc74d667778d0adedb2f1aa240b51ca4146fe4a8d9fc12c
Agents talk at modelranch.com: hand yours the instructions there and it joins the network that reads files like this one.