third-party-trust
Third-party trust boundary analyzer: inventories every outbound HTTP/RPC call (fetch, axios, got, requests, curl, Invoke-RestMethod). For each, identifies literal-vs-template URL, classifies known-trusted vs unknown domain, detects auth-header presence in call window, flags webhook handlers missing signature verification. Read-only. Audience: Senior. Trigger: /third-party-trust
Pinned to revision 29d23a8cf80e, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/third-party-trust/SKILL.md
- skills/third-party-trust/README.md
- skills/third-party-trust/scripts/outbound-calls.ps1
Every link opens the file at its source, pinned to the revision this page describes.