Skip to content
Back to skills

Vulnerability Pre Action Diode

DSecurity

WHOOP / The New Stack vulnerability triage elimination pattern is FORMAT, not a ThumbGate clone. Intercepts untrusted installs, pipe-to-bash, and unpinned supply-chain artifacts in PreToolUse (<5ms) instead of 3-day post-mortem triage. Calculates quantifiable enterprise ROI. Slash: /vulnerability-pre-action-diode.

  • 27 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 7, 2026
ai-agentsrustgoshellbashnodeexpress

Works with

  • cli

Security analysis

D46/100
  • criticalPipes output to a shell interpreter
  • criticalDownloads and executes remote scripts — classic supply chain attack
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned October 7, 2026

npx -y skills add IgorGanapolsky/ThumbGate --skill vulnerability-pre-action-diode --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Vulnerability Pre Action Diode?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Vulnerability Pre Action Diode
[![Security: D — Skills Directory](https://www.skillsdirectory.com/api/skills/igorganapolsky-vulnerability-pre-action-diode/badge)](https://www.skillsdirectory.com/skills/igorganapolsky-vulnerability-pre-action-diode)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: vulnerability-pre-action-diode
description: >
  WHOOP / The New Stack vulnerability triage elimination pattern is FORMAT,
  not a ThumbGate clone. Intercepts untrusted installs, pipe-to-bash, and
  unpinned supply-chain artifacts in PreToolUse (<5ms) instead of 3-day post-mortem
  triage. Calculates quantifiable enterprise ROI. Slash: /vulnerability-pre-action-diode.
---

# Vulnerability Pre-Action Diode — compare, do not clone

## Goal

Provide deterministic pre-action interdiction on agent dependency installations
and shell commands before execution occurs, eliminating the 96-hour post-facto
manual triage cycle reported in enterprise environments (WHOOP/TNS).

## Constraints

| NEVER | ALWAYS |
| --- | --- |
| Clone Datadog Bits AI or workflow orchestrators | Enforce deterministic PreToolUse diodes in <5ms |
| Allow pipe-to-bash (`curl \| bash`) | Block remote script pipes immediately |
| Allow plaintext `http://` package registries | Enforce HTTPS encrypted package endpoints |
| Allow untrusted package lifecycle scripts | Block `--ignore-scripts false` overrides |
| Claim fake MTTR savings | Cite the empirical 96-hour WHOOP/TNS benchmark |

## CLI Procedures

```bash
# Evaluate a tool call
node scripts/vulnerability-pre-action-diode.js --check="npm install express" --json

# Run enterprise ROI calculation
node scripts/triage-savings-calculator.js --vulnerabilities=4 --interdictions=24 --tier=enterprise --json

# Run unit tests
npm run test:vulnerability-diode
```

## Rubric

- critical violations (`pipe_to_bash`, `insecure_protocol_dependency`, `known_compromised_package`) return `verdict: 'block'`
- unpinned installs return `verdict: 'review'`
- pinned installs return `verdict: 'allow'`
- triage hours saved computed accurately ($125/hr blended rate)
- test suite passes: `npm run test:vulnerability-diode`

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…