Back to skills
SKILL.md
Vulnerability Pre Action Diode
DSecurityWHOOP / The New Stack vulnerability triage elimination pattern is FORMAT, not a ThumbGate clone. Intercepts untrusted installs, pipe-to-bash, and unpinned supply-chain artifacts in PreToolUse (<5ms) instead of 3-day post-mortem triage. Calculates quantifiable enterprise ROI. Slash: /vulnerability-pre-action-diode.
- 27 stars
- 0 votes
- 0 copies
- 0 views
- Added October 7, 2026
Works with
Security analysis
46/100- Pipes output to a shell interpreter
- Downloads and executes remote scripts — classic supply chain attack
- Installs packages at runtime which could introduce malicious dependencies
npx -y skills add IgorGanapolsky/ThumbGate --skill vulnerability-pre-action-diode --agent claude-codeAre you the author of Vulnerability Pre Action Diode?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/igorganapolsky-vulnerability-pre-action-diode)---
name: vulnerability-pre-action-diode
description: >
WHOOP / The New Stack vulnerability triage elimination pattern is FORMAT,
not a ThumbGate clone. Intercepts untrusted installs, pipe-to-bash, and
unpinned supply-chain artifacts in PreToolUse (<5ms) instead of 3-day post-mortem
triage. Calculates quantifiable enterprise ROI. Slash: /vulnerability-pre-action-diode.
---
# Vulnerability Pre-Action Diode — compare, do not clone
## Goal
Provide deterministic pre-action interdiction on agent dependency installations
and shell commands before execution occurs, eliminating the 96-hour post-facto
manual triage cycle reported in enterprise environments (WHOOP/TNS).
## Constraints
| NEVER | ALWAYS |
| --- | --- |
| Clone Datadog Bits AI or workflow orchestrators | Enforce deterministic PreToolUse diodes in <5ms |
| Allow pipe-to-bash (`curl \| bash`) | Block remote script pipes immediately |
| Allow plaintext `http://` package registries | Enforce HTTPS encrypted package endpoints |
| Allow untrusted package lifecycle scripts | Block `--ignore-scripts false` overrides |
| Claim fake MTTR savings | Cite the empirical 96-hour WHOOP/TNS benchmark |
## CLI Procedures
```bash
# Evaluate a tool call
node scripts/vulnerability-pre-action-diode.js --check="npm install express" --json
# Run enterprise ROI calculation
node scripts/triage-savings-calculator.js --vulnerabilities=4 --interdictions=24 --tier=enterprise --json
# Run unit tests
npm run test:vulnerability-diode
```
## Rubric
- critical violations (`pipe_to_bash`, `insecure_protocol_dependency`, `known_compromised_package`) return `verdict: 'block'`
- unpinned installs return `verdict: 'review'`
- pinned installs return `verdict: 'allow'`
- triage hours saved computed accurately ($125/hr blended rate)
- test suite passes: `npm run test:vulnerability-diode`
Attribution
Comments
Loading comments…