shriramkv/goose-extension-audit ? reverse-engineered prompt
Reverse engineered prompt
Build me a small Python command line tool that checks Goose recipe files for risky extensions and tells me how safe they look.
It should read one recipe file or a whole folder of recipes, inspect things like shell commands, inline Python, built in permissions, and remote MCP servers, then give each recipe a simple security grade from A to F with a score. If it finds dangerous stuff like running shell commands, piping downloads into a shell, using eval or exec, hardcoded secrets, insecure http links, or missing timeouts, it should flag them clearly and lower the score. If one recipe is really bad, the overall result should reflect that.
I want it to work with plain recipe files in yaml or json, and it should be fine if PyYAML is not installed. Please make it easy to run from the command line, and let me choose console, json, markdown, or badge output. Also add a way to fail in CI when findings are too severe.
Are you gonna build this?
make sure you review the code using coderabbit