wick-security-review — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited wick-security-review (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Security-specific review lens. Focused on what can be exploited, not on what's merely ugly.
tools/wick-scrub.mjs)## CRITICAL (ship-blocking)
- [file:line] Issue, exploit scenario, fix
## HIGH
- [file:line] Issue, impact, fix
## MEDIUM / LOW
- [file:line] Issue, hardening recommendation
## Recommended followups
- Run `tools/wick-scrub.mjs` on memory/ and repo before push
- Consider [specific hardening measure] as a follow-upPreparation-for-adversity, weaponized — imagine an adversary has already gotten in. What do they see? What can they reach? Inversion (Munger) — "how would I guarantee compromise?" Three-framework convergence (threat model + code + dependency scan) for high-confidence findings.
This skill is a well-read generalist's first-pass review. It does not replace:
If the stakes warrant those, name them explicitly in the output so the user doesn't mistake this review for the real audit.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.