Evaluate proposed OCS/WCS changes for least-privilege compliance, network allowlists, and data classification. Use when auditing capabilities or blueprints for CAS-001/TCS-001 certification gates with risk scoring and remediation guidance.
Use this skill when performing agent-assisted security audits of capability or blueprint changes.
Parse the change set
security.requiredScopes, security.networkAccess.allowOutbound, and or .security.dataClassificationsecurity.classificationoscalControlIds and ensure the list is non-empty for security-sensitive components.Evaluate least privilege
Validate network allowlist
Assess data classification
Risk scoring
Remediation guidance
status: PASS | WARN | FAILriskScore: 0–10findings: list with rule, severity, detailsremediations: list of concrete changes with file/line pointersSee references/audit-capability-compliance.md for the detailed workflow specification.