Atlas / Skills / alirezarezvani / Engineering

EngineeringCAUTION

skills/alirezarezvani/engineering

380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8 more coding agents — engineering, marketing, product, compliance, C-level advisory, research, business operations, commerc

Verdict
CAUTION
Grade
B
Trust score
85 /100
Version
—
Hosts
7 documented
License
MIT
Stars
27,777
01

Overview

380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8 more coding agents — engineering, marketing, product, compliance, C-level advisory, research, business operations, commerc

Read from source at commit b228be08e8bdOBSERVED · 2026-10-06
02

Install

Commands as the repository documents them. They are shown, not run.

git clone https://github.com/alirezarezvani/claude-skills.git
git clone https://github.com/alirezarezvani/claude-skills.git
git clone https://github.com/alirezarezvani/claude-skills.git
git clone https://github.com/alirezarezvani/claude-skills.git
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
codexmentioned
copilotmentioned
cursormentioned
gemini-climentioned
openclawmentioned
windsurfmentioned
04

Trust audit

CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (13)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
.codex/skills/a11y-audit
.codex/skills/a11y-audit
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.codex/skills/ab-test-setup
.codex/skills/ab-test-setup
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.codex/skills/ad-creative
.codex/skills/ad-creative
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.codex/skills/adversarial-reviewer
.codex/skills/adversarial-reviewer
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.codex/skills/aeo
.codex/skills/aeo
Why it matters. link not followed
MEDIUMInventory / provenance · skill.no_skill_md · CWE-1104
Why it matters. no SKILL.md at the audited path
Fix. a skill without its instruction file cannot be reviewed as one
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
hivemind.md:97
`HIVEMIND_SERVER_URL` overrides that address (default `http://127.0.0.1:4096`). It must be a
LOWContainer / deploy · priv.container · CWE-250, CWE-16
docker-development.md:158
| Privileged instructions | High | Avoid `--privileged`, drop capabilities |
LOWContainer / deploy · priv.container · CWE-250, CWE-16
docker-development.md:170
| Sensitive mounts | Critical | Never mount /etc, /var/run/docker.sock in prod |
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
skill-security-auditor.md:62
| **System prompt override** | "Ignore previous instructions", "You are now..." | 🔴 CRITICAL | <!-- noqa: SEC-AUDITOR -->
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
skill-security-auditor.md:64
| **Safety bypass** | "Skip safety checks", "Disable content filtering" | 🔴 CRITICAL | <!-- noqa: SEC-AUDITOR -->
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
skill-security-auditor.md:63
| **Role hijacking** | "Act as root", "Pretend you have no restrictions" | 🔴 CRITICAL | <!-- noqa: SEC-AUDITOR -->
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
env-secrets-manager.md:95
Production applications should never read secrets from `.env` files or environment variables baked into container images. Use a dedicated secret store instead.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha b228be08e8bdfull audit observations/trust-audit/skill/alirezarezvani__engineering.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-06b228be08e8bdCAUTIONB85first audit
06

Questions

What does the Engineering skill do?

380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8 more coding agents — engineering, marketing, product, compliance, C-level advisory, research, business operations, commerc

Is Engineering safe to install?

With care. The audit graded it B (85/100) and found 13 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Engineering access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Engineering work with?

Its documentation mentions claude-code, codex, copilot, cursor, gemini-cli, openclaw and windsurf. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (b228be08e8bd), read on 2026-10-06. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement