Update Threat DbCAUTION
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Overview
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
d90170da4369OBSERVED · 2026-10-07What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: update-threat-db description: Delegate threat-intelligence research and updates to AgentSec, then validate the guide and landing mirrors. --- # Update threat intelligence through AgentSec AgentSec Triage owns the technical source of truth. This guide skill is a delegator and does not carry a private copy of the threat database. ## Workflow 1. Locate the sibling `agentsec-triage` checkout or use `AGENTSEC_REPO`. 2. Read AgentSec's `AGENTS.md` and `.claude/commands/update-threat-db.md` completely. 3. Execute the source review, red-first tests, authoring changes, and builders inside an isolated AgentSec worktree. 4. Synchronize `exports/security-feed.v1.json` to the guide and landing only after AgentSec passes locally. 5. Follow the guide's `.claude/commands/update-threat-db.md` for compatibility database updates and the landing's searchable catalogue sync/check command. A current feed badge does not prove the catalogue contains the new records. 6. Run the guide and landing mirror checks, then report each repository's status separately. Do not treat the guide's compatibility database as canonical. Do not publish, tag, or push AgentSec while its license decision blocks public release. The compatibility database still consumed by the guide commands is `examples/commands/resources/threat-db.yaml`.
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
whitepapers/recap-cards/en/_extensions
whitepapers/recap-cards/fr/_extensions
Gates applied: no_behavioural_pass.
d90170da4369full audit observations/trust-audit/skill/florianbruniaux__update-threat-db.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d90170da4369 | CAUTION | B | 89 | first audit |
Questions
What does the Update Threat Db skill do?
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Is Update Threat Db safe to install?
With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Update Threat Db access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (d90170da4369), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.