agentic/code/frameworks/security-engineering/skills/binary-blob-audit/SKILL.md
Scan tracked repository files for committed binary blobs and report reviewability/provenance exceptions
npx skillsauth add jmagly/aiwg binary-blob-auditInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Scan source repositories for committed binary blobs. This enforces the no-binary-blobs rule and maps curl Practice 6 into an AIWG security-engineering control.
git ls-files -z to enumerate tracked files..so, .dll, .dylib, .exe, .bin, .dat, .o, .a, .jar, .war.test/fixtures/** and tests/fixtures/** under the configured size cap.assets/** images under the configured size cap.Each finding includes path, MIME type, byte size, last touched commit, exception status, and remediation.
Run in report-only mode first:
aiwg run skill binary-blob-audit
Gate new violations after baselining:
aiwg run skill binary-blob-audit -- --fail-on-violation
agentic/code/frameworks/security-engineering/rules/no-binary-blobs.md.aiwg/security/curl-checklist-gap-analysis.md row 1, Practice 6data-ai
Report which research-corpus radar sidecars are overdue for refresh. Computes staleness (days since last refresh vs the cadence window) for every radar, sorted most-overdue-first. Runs via `aiwg corpus radar-status`.
data-ai
Aggregate research-corpus radar sidecars into a corpus or per-cluster freshness report — totals, overdue count, per-cluster / per-GRADE / per-trajectory breakdowns, an overdue table, and per-radar rationale snippets. Runs via `aiwg corpus radar-report`.
testing
Scaffold radar/freshness sidecars for research-corpus REFs. Pulls title/authors from the citation sidecar and GRADE from the analysis doc, defaults the refresh cadence from GRADE and the cluster from a corpus-local map, and stamps documentation/radar/REF-XXX-radar.md. Runs via `aiwg corpus radar-init`.
data-ai
Compute an entity's publication trajectory — per-year paper counts, topic drift, hot-streak detection (≥3 consecutive A-grade years), and career phase. Runs via `aiwg corpus profile-temporal`.