All skills
simota avatar

/cull

@8e1f365
by shingo imotasimota/agent-skills85 stars
15

Scanning and eradicating supply-chain malware (Shai-Hulud/S1ngularity npm/PyPI worms): IoC scan, OS/IDE persistence, safe credential rotation. Not for SAST (Sentinel) or skill/MCP audit (Chain).

Use this Skill: https://skilld.dev/gh/simota/agent-skills/cull

This session only. Nothing lands on disk.

referenceautorun-schema.md

≈321 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Cull — AUTORUN _STEP_COMPLETE Schema

See _common/AUTORUN.md for the protocol (_AGENT_CONTEXT input, mode semantics, error handling).

Cull-specific _STEP_COMPLETE.Output schema:

_STEP_COMPLETE:
  Agent: Cull
  Task_Type: scan | shai-hulud | lockfile | eradicate | rotate | harden | propagation
  Status: SUCCESS | PARTIAL | BLOCKED | FAILED
  Output:
    grade: CLEAN | SUSPECTED | CONFIRMED | ACTIVELY_BLEEDING
    target: "<host | repo path | container image | CI runner ID>"
    findings:
      - ioc_family: "<e.g. mini-shai-hulud-2nd>"
        surface: persistence | droplet | lockfile | process | network | git-log
        path_or_evidence: "<path / package@version / process cmdline / git-log line>"
        sha256: "<if file, else null>"
        source: "<advisory URL + date>"
    eradication_status: not_started | in_progress | verified | blocked
    rotation_status: not_eligible | ready | issued | verified
    hardening_applied: ["--ignore-scripts", "min-release-age=7", "provenance=true"]
  Validations:
    persistence_stopped_before_delete: true | false | n/a
    ioc_database_version: "<date or commit>"
    callback_probe_avoided: true
  Next: triage | sentinel | chain | gear | vigil | lore | DONE
  Reason: "<why this next step>"

Source: SKILL.md on GitHub

1 alert1mo3 checks · Risk CRITICAL
  • Gen Agent Trust Hub1mo

    This skill is a security auditing tool designed to detect and remove supply-chain malware. While it accesses sensitive files and performs potentially destructive system commands, these actions are consistent with its purpose. A low severity is assigned due to the inherent risks of indirect prompt injection when processing untrusted system data.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: LOW · No issues

Signed by skilld at 8e1f365. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated last month

README badge

README badge for simota/agent-skills/cull