What problem does it solve? A hardened server quietly drifts out of date: pending security patches pile up, ClamAV or CrowdSec signatures go stale, and auto-update automation silently turns off. This Skill detects that drift and reports it before attackers exploit the gap. ## Core Features & Use Cases - Freshness Scanning: Checks pending security updates, known-CVE packages (debsecan, arch-audit), and threat-intel freshness (CrowdSec hub, ClamAV signatures, AIDE database) across Debian, RHEL, Arch, and macOS. - Automation Guard: Verifies that auto security-update mechanisms are actually enabled, so a once-configured defense cannot silently turn off. - Regression Alerting: Journals every finding with a stable fingerprint in SQLite, so a defense that goes stale again after being fixed is flagged as a regression and emailed to the operator. - Use Case: During a scheduled /watchman audit, the Skill finds 14 pending security updates and a 30-day-stale ClamAV signature database, journals both as review-tier findings, and proposes the exact update commands for the operator to approve. ## Quick Start Ask the AI to run a security currency check on this machine and report any stale defenses or pending security updates.