meticulous-matt

Audit codebases for security vulnerabilities with four-phase workflow and Reba validation.

5|1|Updated Dec 27, 2025
One-click install
npx skills add https://github.com/HakAl/team_skills --skill meticulous-matt
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: meticulous-matt
Source: https://github.com/HakAl/team_skills/tree/main/meticulous-matt
Command: npx skills add https://github.com/HakAl/team_skills --skill meticulous-matt

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Meticulous Matt helps teams audit codebases for security vulnerabilities and ensures nothing slips through the cracks, documenting every finding for traceability.

Core Features & Use Cases

  • Exhaustive security discovery and risk mapping across codebases
  • Beads-based issue tracking and immutable change controls
  • Integration with team workflows (Peter, Neo, Reba, Gabe) for plan-driven security reviews
  • Validation and sign-off process before merges and deployments
  • Safety-first posture: enforces immutable sections and thorough documentation

Quick Start

Invoke Matt in your project context to start a full security audit and bead-based plan.

Frequently Asked Questions about meticulous-matt

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit my codebase for security vulnerabilities and ensure nothing is missed?

To audit codebase security, you run a four-phase workflow that discovers vulnerabilities, maps risks, and documents findings. It uses beads-based tracking and immutable sections to guarantee every issue is traced and resolved before release.

What is beads-based issue tracking and how does it secure code review?

Beads-based issue tracking maps individual security findings through a four-phase audit workflow. It enforces immutable sections to prevent changes to documented vulnerabilities, ensuring thorough risk triage and traceability during code review.

How do I integrate security triage into team workflows before deployment?

Security triage integrates into team workflows by applying plan-driven reviews across retrospectives and release readiness checks. A validation and sign-off process enforces safety-first posture before any code merges or deployments proceed.

Can I use this security audit for release readiness and retrospective planning?

Yes, security audits apply directly to release readiness and retrospective planning. The workflow supports plan-driven security reviews across team contexts, enforcing immutable change controls and validation sign-offs before deployment.

How do I enforce immutable change controls during a vulnerability detection process?

Immutable change controls are enforced by applying immutable sections to documented vulnerability findings. This prevents undocumented modifications during risk triage, maintaining a safety-first posture and ensuring thorough documentation throughout the audit.

What is the best way to plan before fixing security vulnerabilities in code?

The best way to plan before fixing security vulnerabilities is applying a four-phase workflow with risk triage. This plan-before-fix approach uses beads-based tracking to map issues and validate fixes through a formal sign-off process.