Start with the matrix. Open this section when you need to understand audit grades, top threats, control gaps, and best-value highlights.
Open notes
Suggested baseline
Suggested skills to compare
Security Ownership Map
Repository: openai/skills
Author: openai · Source status: Clear source
Score 82Clear source
Manual review
Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization.
Score basis:Clear source · High execution risk · Claude · Evidence completeness 67%
Author unclaimed
Claude
Search to add skills, or paste 2–4 comma-separated slugs.
How differences are detected
A row is marked different when selected skills have distinct values. Only-differences mode hides rows that are identical.
How best values are highlighted
Pre-install score, evidence completeness, and community signal prefer higher values; execution risk and install friction prefer lower values.
How to read risk tags
Risk tags come from SAS-v2.1 public-evidence signals and point to command, network, secret, context, or supply-chain items to review before install.
Selected audit signals
git-commit
C · Review first
Execution risk:High
Threat tags:unexpected code execution, data exfiltration, human approval gap
Control gaps:missing license, broad permissions, shell without guardrails
ArcGIS-JavaScript-AI-Component
C · Review first
Execution risk:High
Threat tags:unexpected code execution, identity privilege abuse, data exfiltration
Control gaps:missing license, broad permissions, shell without guardrails
skill-seekers
D · Limited evidence
Execution risk:High
Threat tags:unexpected code execution, identity privilege abuse, data exfiltration
Control gaps:missing license, broad permissions, shell without guardrails
Dimension
git-commit
ArcGIS-JavaScript-AI-Component
skill-seekers
Pre-install decision
Pre-install score
79 · Manual review
82 · Manual review
88 · Evidence missing
Score basis
Clear source, High execution risk, Claude
Clear source, High execution risk, Universal
Clear source, High execution risk, Claude
Execution risk
High
High
High
Threat tags
unexpected code execution, data exfiltration, human approval gap
unexpected code execution, identity privilege abuse, data exfiltration
unexpected code execution, identity privilege abuse, data exfiltration
Control gaps
missing license, broad permissions, shell without guardrails
missing license, broad permissions, shell without guardrails
missing license, broad permissions, shell without guardrails