Skip to content
Back to skills

Binary Blob Audit

ASecurity

Scan tracked repository files for committed binary blobs and report reviewability/provenance exceptions

  • 207 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added May 27, 2026
data-aigobashgitsecurity

Security analysis

A100/100

Scanned May 27, 2026

npx -y skills add jmagly/aiwg --skill binary-blob-audit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Binary Blob Audit?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Binary Blob Audit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/jmagly-binary-blob-audit/badge)](https://www.skillsdirectory.com/skills/jmagly-binary-blob-audit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
namespace: aiwg
name: binary-blob-audit
platforms: [all]
description: Scan tracked repository files for committed binary blobs and report reviewability/provenance exceptions
requires:
  - git: repository with tracked files
  - file: file(1) utility for MIME classification
ensures:
  - report: binary files listed with MIME type, size, exception class, and last touched commit
  - exit-code: non-zero when violations found and --fail-on-violation is set
errors:
  - not-git-repo: current directory is not a git repository
  - file-missing: file(1) utility unavailable
invariants:
  - never deletes files
  - acceptable binary exceptions are reported, not silently ignored
commandHint:
  argumentHint: "[--fail-on-violation] [--max-fixture-bytes N] [--format text|json]"
  allowedTools: Read, Bash, Grep
  model: sonnet
  category: security
  orchestration: false
---

# Binary Blob Audit

Scan source repositories for committed binary blobs. This enforces the `no-binary-blobs` rule and maps curl Practice 6 into an AIWG security-engineering control.

## Execution Flow

1. Run `git ls-files -z` to enumerate tracked files.
2. For each file, collect size, MIME classification, and last touched commit.
3. Flag binary MIME types and extension-blocklisted files: `.so`, `.dll`, `.dylib`, `.exe`, `.bin`, `.dat`, `.o`, `.a`, `.jar`, `.war`.
4. Classify exceptions:
   - `test/fixtures/**` and `tests/fixtures/**` under the configured size cap.
   - `assets/**` images under the configured size cap.
   - SBOM/attestation files with a signature or provenance note.
5. Emit a report with violations and allowed exceptions.

## Output

Each finding includes path, MIME type, byte size, last touched commit, exception status, and remediation.

## CI

Run in report-only mode first:

```bash
aiwg run skill binary-blob-audit
```

Gate new violations after baselining:

```bash
aiwg run skill binary-blob-audit -- --fail-on-violation
```

## References

- `agentic/code/frameworks/security-engineering/rules/no-binary-blobs.md`
- `.aiwg/security/curl-checklist-gap-analysis.md` row 1, Practice 6

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…