security-and-governance-review

Identifies security, governance, and compliance risks in skill packages and deployment artifacts.

Updated Apr 27, 2026
One-click install
npx skills add https://github.com/ginmp8/rhapsodia --skill security-and-governance-review
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-and-governance-review
Source: https://github.com/ginmp8/rhapsodia/tree/main/skills/security-and-governance-review
Command: npx skills add https://github.com/ginmp8/rhapsodia --skill security-and-governance-review

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps teams assess security, governance, and compliance risks across skill packages, agents, validators, templates, and deployment artifacts before release.

Core Features & Use Cases

  • Identifies gaps in security, governance controls, audit trails, and policy enforcement across skill components.
  • Evaluates authority boundaries, tool permissions, and fail-closed mechanisms for safer agent workflows.
  • Generates remediation plans with evidence-based findings and concrete validation steps for safer deployment.

Quick Start

Run a security and governance review on a target skill package to surface risks and recommended mitigations.

Frequently Asked Questions about security-and-governance-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit skill packages for security and governance compliance risks?

To audit skill packages for security and governance compliance, run a review that targets skill repositories and deployment artifacts. This surfaces supply-chain concerns, masked secrets, risk classifications, and remediation guidance before release.

What is a security and governance health check for agent workflows?

A security and governance health check for agent workflows evaluates authority boundaries, tool permissions, and fail-closed mechanisms. It identifies gaps in policy enforcement and audit trails across skill components to ensure safer deployment.

How do I identify supply-chain risks in deployment artifacts and helper scripts?

Identify supply-chain risks in deployment artifacts and helper scripts by applying a governance review to the target repositories. The process returns structured findings with concrete validation probes and evidence-based remediation steps.

Can I generate remediation plans with validation probes for skill repositories?

Yes, you can generate remediation plans with validation probes for skill repositories. The review process outputs evidence-based findings, risk classifications, and concrete validation steps to fix governance and security gaps.

Does this governance review evaluate tool permissions and fail-closed mechanisms?

Yes, the governance review evaluates tool permissions and fail-closed mechanisms. It assesses authority boundaries and policy enforcement across validators and agents to surface security gaps and recommend safer workflow configurations.