DashboardSAFE
A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw
Overview
A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw
80a0afd96301OBSERVED · 2026-10-07What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: dashboard description: View all tracked vulnerabilities and their current status user-invocable: true allowed-tools: Read, Glob, Grep model: haiku --- # Vulnetix Vulnerability Dashboard This skill reads `.vulnetix/memory.yaml` and displays a comprehensive vulnerability status report. It is read-only and does not modify any files. ## Workflow ### Step 1: Load Memory 1. Use **Glob** to check if `.vulnetix/memory.yaml` exists in the repo root 2. If it does not exist, display: **"No vulnerability data found. Run `/vulnetix:vuln <package>` or `/vulnetix:exploits-search` to start tracking."** and stop. 3. Use **Read** to load the full contents of `.vulnetix/memory.yaml` ### Step 2: Parse and Categorize From the `vulnerabilities:` section, categorize each entry: **Open (unresolved):** - `status: affected` -- "Vulnerable" - `status: under_investigation` -- "Investigating" **Resolved:** - `status: fixed` -- "Fixed" - `status: not_affected` -- "Not affected" - Entries with `decision.choice: risk-accepted` -- "Risk accepted" - Entries with `decision.choice: deferred` -- "Deferred" From the `manifests:` section, collect manifest tracking info. ### Step 3: Display Summary Header ``` Vulnetix Security Dashboard ============================ Open: <N> (<X> vulnerable, <Y> investigating) Resolved: <N> (<X> fixed, <Y> not affected, <Z> risk-accepted, <W> deferred) Manifests tracked: <N> (last scan: <timestamp>) ``` If there are zero vulnerabilities and zero manifests, display: **"Clean slate -- no vulnerabilities tracked yet."** ### Step 4: Open Vulnerabilities Table If there are open vulnerabilities, display them sorted by CWSS priority (P1 first), then by severity: ``` Open Vulnerabilities -------------------- | ID | Package | Severity | Status | Priority | Decision | |----|---------|----------|--------|----------|----------| | CVE-2021-44228 | log4j-core | critical | Vulnerable | P1 (87.5) | investigating | | GHSA-xxxx-yyyy | express | high | Investigating | P2 (62.0) | investigating | ``` For each column: - **ID**: Primary vulnerability key - **Package**: `package` field - **Severity**: `severity` field - **Status**: Developer-friendly status (see VEX mapping above) - **Priority**: `cwss.priority` and `cwss.score` if available, otherwise "--" - **Decision**: `decision.choice` if available, otherwise "--" ### Step 5: Resolved Vulnerabilities Table If there are resolved vulnerabilities, display them: ``` Resolved Vulnerabilities ------------------------ | ID | Package | Severity | Resolution | Decision | Date | |----|---------|----------|------------|----------|------| | CVE-2023-1234 | lodash | high | Fixed | fix-applied | 2024-01-15 | ``` For the **Date** column, use the most recent `history` entry timestamp, or `discovery.date` as fallback. ### Step 6: Manifest Tracking If manifests are tracked, display: ``` Tracked Manifests ----------------- | Manifest | Ecosystem | Last Scanned | Vulns Found | |----------|-----------|--------------|-------------| | package.json | npm | 2024-01-15T10:30:00Z | 3 | | go.mod | go | 2024-01-15T10:31:00Z | 0 | ``` ### Step 7: Suggested Actions For each open vulnerability (up to 5), suggest a next action based on its state: - Has no `threat_model` or `cwss`: `"/vulnetix:exploits <id>"` -- get exploit analysis and priority scoring - Has `cwss` but no fix applied: `"/vulnetix:fix <id>"` -- get fix intelligence - General: `"/vulnetix:remediation <id>"` -- get a full remediation plan If there are more than 5 open vulns, add: `"Use /vulnetix:exploits-search to find exploited vulnerabilities across your ecosystem."` Always end with: `"Use /vulnetix:vuln <id> for detailed info on any vulnerability."`
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
80a0afd96301full audit observations/trust-audit/skill/davepoon__dashboard.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 80a0afd96301 | SAFE | B | 89 | first audit |
Questions
What does the Dashboard skill do?
A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw
Is Dashboard safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Dashboard access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (80a0afd96301), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.