Security loops
Bounded security sweeps: dependency audits, secret scans, and CVE burn-downs that report before they touch anything.
5 graded loops in this category.
Burn down critical security findings
Run your static analyzer on the security ruleset, fix one high-severity finding at a time, re-verify, and loop until zero remain or 10 turns pass.
Secrets scan until clean
Run a secrets scanner over the working tree and drive the findings to zero: real secrets get flagged for rotation, false positives get baselined.
Lock down Supabase RLS policies
Replace overpermissive 'always true' policies with org-scoped RLS across six tables until security advisor clears all findings.
Cadence: weekly. you are my expectation-gap auditor. read…
Community loop loop for security, sourced from submission. Verified exit condition, evaluator-gated.
→ run /audit-skills every Monday morning
Community schedule loop for security, sourced from github. Verified exit condition, evaluator-gated.