All skills
openai avatar

/security-ownership-map

@5c8f1e2 official
by openaiopenai/skills28k stars
1,891

Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. Trigger only when the user explicitly wants a security-oriented ownership or bus-factor analysis grounded in git history (for example: orphaned sensitive code, security maintainers, CODEOWNERS reality checks for risk, sensitive hotspots, or ownership clusters). Do not trigger for general maintainer lists or non-security ownership questions.

Use this Skill: https://skilld.dev/gh/openai/skills/security-ownership-map

This session only. Nothing lands on disk.

referencesneo4j-import.md

≈607 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Neo4j Import Notes

Use these steps when persisting the ownership graph to Neo4j.

Quick import (LOAD CSV)

  1. Copy people.csv, files.csv, and edges.csv into the Neo4j import directory.
  2. Run the following Cypher from Neo4j Browser or cypher-shell:
CREATE CONSTRAINT person_id IF NOT EXISTS FOR (p:Person) REQUIRE p.id IS UNIQUE;
CREATE CONSTRAINT file_id IF NOT EXISTS FOR (f:File) REQUIRE f.id IS UNIQUE;

LOAD CSV WITH HEADERS FROM 'file:///people.csv' AS row
MERGE (p:Person {id: row.person_id})
SET p.name = row.name,
    p.email = row.email,
    p.first_seen = row.first_seen,
    p.last_seen = row.last_seen,
    p.commit_count = toInteger(row.commit_count),
    p.touches = toInteger(row.touches),
    p.sensitive_touches = toFloat(row.sensitive_touches),
    p.primary_tz_offset = CASE row.primary_tz_offset WHEN '' THEN null ELSE row.primary_tz_offset END,
    p.primary_tz_minutes = CASE row.primary_tz_minutes WHEN '' THEN null ELSE toInteger(row.primary_tz_minutes) END,
    p.timezone_offsets = CASE row.timezone_offsets WHEN '' THEN null ELSE row.timezone_offsets END;

LOAD CSV WITH HEADERS FROM 'file:///files.csv' AS row
MERGE (f:File {id: row.file_id})
SET f.path = row.path,
    f.first_seen = row.first_seen,
    f.last_seen = row.last_seen,
    f.commit_count = toInteger(row.commit_count),
    f.touches = toInteger(row.touches),
    f.bus_factor = toInteger(row.bus_factor),
    f.sensitivity_score = toFloat(row.sensitivity_score),
    f.sensitivity_tags = row.sensitivity_tags;

LOAD CSV WITH HEADERS FROM 'file:///edges.csv' AS row
MATCH (p:Person {id: row.person_id})
MATCH (f:File {id: row.file_id})
MERGE (p)-[r:TOUCHES]->(f)
SET r.touches = toInteger(row.touches),
    r.recency_weight = toFloat(row.recency_weight),
    r.first_seen = row.first_seen,
    r.last_seen = row.last_seen,
    r.sensitive_weight = toFloat(row.sensitive_weight);

LOAD CSV WITH HEADERS FROM 'file:///cochange_edges.csv' AS row
MATCH (f1:File {id: row.file_a})
MATCH (f2:File {id: row.file_b})
MERGE (f1)-[r:COCHANGES]->(f2)
SET r.cochange_count = toInteger(row.cochange_count),
    r.jaccard = toFloat(row.jaccard);

Visualization tips

  • Use Neo4j Bloom or Browser with MATCH (p:Person)-[r:TOUCHES]->(f:File) RETURN p,r,f.
  • Filter by f.sensitivity_score > 0 to highlight security-relevant clusters.
  • For Gephi, import edges.csv as edges and files.csv / people.csv as nodes.

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The 'security-ownership-map' skill is designed to analyze git repository history to identify code ownership patterns and bus factor risks. It operates locally on a specified repository and produces data artifacts for analysis. No malicious patterns or security vulnerabilities were identified.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer7mo

    7/8 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 5c8f1e2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Activeupdated 8 months ago

README badge

README badge for openai/skills/security-ownership-map

Analyzes git history to map people and files into a bipartite graph, computes bus factor for sensitive code paths, and exports CSV/JSON for Neo4j or Gephi visualization. Identifies orphaned auth/crypto code, hidden owners, and ownership drift against CODEOWNERS files using configurable sensitivity rules and co-change clustering.

Generated from the current SKILL.md.

What does this skill compute from git history?
It builds a bipartite graph of people and files from git commits, computes bus factor (single points of failure) for each file, identifies co-change clusters using Jaccard similarity, detects communities via NetworkX, and flags orphaned or stale sensitive code based on configurable patterns.
Can I use this to find security risks in code ownership?
Yes. The skill identifies orphaned sensitive code (stale + low bus factor), hidden owners controlling auth/crypto paths, sensitive hotspots with only one maintainer, and ownership drift versus CODEOWNERS files.
What output formats does this generate?
CSV files for graph databases (people, files, edges, co-change edges), JSON summary with security findings, communities.json with maintainers per cluster, and optional GraphML for visualization in Gephi or Neo4j.
Does this require any external dependencies?
Yes. Python 3 and the NetworkX library are required. Install with `pip install networkx`. The skill can export to Neo4j, but Neo4j is optional.
Can I exclude noisy commits or authors from analysis?
Yes. By default, merge commits and Dependabot are excluded. You can override with `--include-merges`, `--author-exclude-regex`, and `--cochange-exclude` to filter build glue files like Kbuild or lockfiles from co-change clustering.

Generated from the current SKILL.md. These answers refresh after source changes.