Summary
Two related problems from #318 / #319: the /audit-security skill silently passes checks it never ran, and several security documents state things that are not true of the current repository.
Found while verifying the merged result. The audit tooling problem matters most — a check that looks green without running is worse than no check.
/audit-security: broken steps
Step 6 — the injection scan is a silent no-op on macOS. It uses \s inside awk, which BSD/BWK awk does not support. It matches nothing and reports clean regardless of input. Every maintainer on macOS gets a false pass.
Step 8 — the URL check reports false failures. The sed cleanup misses a trailing single quote, so 10 of 12 URLs report a bogus 404. Real breakage would be invisible in the noise.
Step 3/5 — determinism check is self-defeating. Step 3 tells the maintainer to regenerate into the same directory that step 5 then diffs against, so the comparison can pass trivially.
Also worth fixing while there: step 6's permissions grep under-reports what it finds.
Documentation drift
| Claim |
Reality |
SECURITY.md: "Every supported component release carries a CycloneDX SBOM" |
7 of 9 latest component releases have none — see #323 |
security/README.md: gh api .../dependency-graph/sbom returns "0 packages" |
It returns HTTP 404. The conclusion (the graph is empty) is right; the command shown is wrong |
security/README.md: "Nothing else needs to change" when adding a releasable component |
Wrong — TAG_PREFIXES is a second hardcoded list that must also learn the new tag |
security/README.md: /audit-security re-checks all three known gaps |
It checks one |
security/openchain.md: MAINTAINERS.md missing (4.1.2) |
It exists and predates the document |
security/openchain.md: per-package LICENSE files a known gap |
12 of 13 packages have one |
security/SBOM.md: "The name always equals the published package's own name" |
False for apple (openiap-apple vs published openiap) |
security/SBOM.md: consumer verification snippet |
Omits --repo, so it fails outside a clone |
security/SBOM.md: worked reproduction recipe |
Fails on the only release it names |
Docs site
compliance.tsx's CRA deadline row contradicts Article 14 and the repo's own CRA.md table. The final-report deadline does not run from awareness.
overview.tsx presents OpenIAP's internal SLA as the statutory CRA deadlines, contradicting the explicit disclaimer in SECURITY.md.
overview.tsx attributes release-state audits to "merge to main"; they run on every pull request.
Suggested approach
- Fix the three broken
/audit-security steps first — they are what would have caught most of the rest.
- Add a regression check for the skill itself, so a command that silently matches nothing fails loudly.
- Correct the documentation claims. Several are counts that were true when written; prefer a described property or a command that prints the live number.
Verified correct (no action)
For the record, adversarial verification confirmed these are fine: SBOM schema validity, provenance attestation and tag binding, determinism, absence of secrets and local paths, the component/tag table, licence exception handling, CRA legal claims in CRA.md, internal links, docs routes, and test-coverage claims. 18 further candidate findings were raised and refuted during verification.
Summary
Two related problems from #318 / #319: the
/audit-securityskill silently passes checks it never ran, and several security documents state things that are not true of the current repository.Found while verifying the merged result. The audit tooling problem matters most — a check that looks green without running is worse than no check.
/audit-security: broken steps
Step 6 — the injection scan is a silent no-op on macOS. It uses
\sinsideawk, which BSD/BWK awk does not support. It matches nothing and reports clean regardless of input. Every maintainer on macOS gets a false pass.Step 8 — the URL check reports false failures. The
sedcleanup misses a trailing single quote, so 10 of 12 URLs report a bogus 404. Real breakage would be invisible in the noise.Step 3/5 — determinism check is self-defeating. Step 3 tells the maintainer to regenerate into the same directory that step 5 then diffs against, so the comparison can pass trivially.
Also worth fixing while there: step 6's permissions grep under-reports what it finds.
Documentation drift
SECURITY.md: "Every supported component release carries a CycloneDX SBOM"security/README.md:gh api .../dependency-graph/sbomreturns "0 packages"security/README.md: "Nothing else needs to change" when adding a releasable componentTAG_PREFIXESis a second hardcoded list that must also learn the new tagsecurity/README.md:/audit-securityre-checks all three known gapssecurity/openchain.md:MAINTAINERS.mdmissing (4.1.2)security/openchain.md: per-package LICENSE files a known gapsecurity/SBOM.md: "The name always equals the published package's own name"apple(openiap-applevs publishedopeniap)security/SBOM.md: consumer verification snippet--repo, so it fails outside a clonesecurity/SBOM.md: worked reproduction recipeDocs site
compliance.tsx's CRA deadline row contradicts Article 14 and the repo's ownCRA.mdtable. The final-report deadline does not run from awareness.overview.tsxpresents OpenIAP's internal SLA as the statutory CRA deadlines, contradicting the explicit disclaimer inSECURITY.md.overview.tsxattributes release-state audits to "merge to main"; they run on every pull request.Suggested approach
/audit-securitysteps first — they are what would have caught most of the rest.Verified correct (no action)
For the record, adversarial verification confirmed these are fine: SBOM schema validity, provenance attestation and tag binding, determinism, absence of secrets and local paths, the component/tag table, licence exception handling, CRA legal claims in
CRA.md, internal links, docs routes, and test-coverage claims. 18 further candidate findings were raised and refuted during verification.