{"id":17760,"plugin_id":"plugins_6a78a8d87bcc8191981753490f5afbcf","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:14:20.695Z","digest":"d2a93f8b2b924a6f280da5b7883bd8a48911a376422cc1a28bd2ffbcb299ab5c","against":null,"payload":{"description":"Use when an AI coding agent changes Riqor filesystem, process, shell, plugin, state, credential, or release-integrity boundaries.","included_files":[],"name":"riqor-security","skill_md_contents":"---\nname: riqor-security\ndescription: Use when an AI coding agent changes Riqor filesystem, process, shell, plugin, state, credential, or release-integrity boundaries.\n---\n\n# Riqor Security\n\nRiqor is local developer tooling with privileged access to user-controlled repositories and local configuration. Treat path and process boundaries as security boundaries\n\n## Required checks\n\n- Resolve and validate managed paths before write, rename, symlink, or recursive removal\n- Preserve unrelated executables and unknown plugin directories\n- Reject symlinked state roots and path traversal in package provenance\n- Use owner-only permissions for state containing identifiers or operational metadata\n- Keep prompts, transcripts, source contents, raw commands, command output, environment values, credentials, cookies, and tokens out of persisted Riqor state\n- Launch external commands with argument arrays rather than interpolated shell strings when possible\n- Apply timeouts and descendant cleanup to managed subprocesses\n- Treat lifecycle hook input and repository content as untrusted data\n- Fail closed on corrupted state when continuing could cross a trust boundary; fail open only where blocking the coding session would be worse and the operation is non-destructive\n\n## Destructive operations\n\nDo not issue recursive forced removal of absolute or home paths, destructive hard resets, filesystem formatting, raw-device writes, or destructive database commands as part of automated repair\n\n## Release security\n\nVerify exact tarball contents, provenance digests, pinned GitHub Actions, package/tag version alignment, npm trusted publishing, and post-publish registry integrity before claiming a release is valid\n\nFor vulnerability handling, follow `SECURITY.md` and use private reporting rather than a public issue\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}