Weekly dependency vulnerability audit
Every Monday morning, run the dependency vulnerability audit, open one PR fixing what auto-fix can handle safely, and file issues for the rest.
/schedule every Monday at 8am, run `npm audit`, open a single PR applying only non-breaking fixes with tests passing, and file one issue per remaining high or critical advisory with its CVE link and affected paths
claude-code · codex
Implementation note
Splitting auto-fixable from breaking changes keeps the weekly PR trivially mergeable. Issues give the breaking upgrades a paper trail.
More security loops
Audit the system from evidence
Read-only pass that verifies architecture, security, platform behavior, ops, and business logic from current evidence, not assumptions.
Audit [project] from its actual code and configuration, not framework assumptions. For architecture, platform compatibility, security, privileged areas, performance, deployment, jobs, business logic, and code quality, record proved, no issue, weak, or N/A with direct evidence; verify external limits from current primary sources and calculate numbers. Ask before changing code. Stop when every area is logged with severity, or return unverified areas as blocked. Finish with a plain-language overview and area-to-evidence table.
Cadence: weekly. you are my expectation-gap auditor. read…
Community loop loop for security, sourced from submission. Verified exit condition, evaluator-gated.
/loop cadence: weekly. you are my expectation-gap auditor. read expectation-gap-STATE.md: gaps found, pages fixed, tickets already processed. pull the week's support tickets and refund reasons [Zendesk MCP / your support export]. each round, take ONE "i thought" moment where the customer expected something the product doesn't do; find the sentence on my site that planted the expectation and log both side by side. for the pain that cost the most (refunds, angriest tickets), draft the page fix (exact promise) or flag me if the product should change instead. append pairs, sources and the drafted fix to expectation-gap-STATE.md; never edit shipped pages yourself, draft only. verification: a round is valid only when the pair and drafted fix are appended and readable in expectation-gap-STATE.md. stop after 15 iterations, or until every new gap this week is logged, whichever comes first; if the support source is unreachable, BLOCK and say so.
Secrets scan until clean
Run a secrets scanner over the working tree and drive the findings to zero: real secrets get flagged for rotation, false positives get baselined.
/goal `gitleaks detect --no-git` reports zero findings — for each finding, tell me whether it looks like a real credential (flag it for rotation and replace it with an env var lookup) or a false positive (add it to the baseline with a comment); never print the secret value itself; stop after 8 turns