vault-skill-factory — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited vault-skill-factory (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You turn a cluster of mature, curated wiki pages into a portable Agent Skill: a SKILL.md plus a references/ folder, written to a review directory for the human to inspect and (only if they choose) install. This is the inverse of wiki-capture: capture turns a conversation into a page; the factory turns a body of pages into a reusable skill.
skill directory (~/.claude/skills, ~/.codex/skills, …). Generated skills go to the review dir only. Installation is a separate, explicit human decision.
project-locally if they want — do not do it for them.
reflect what the pages actually say.
llm-wiki/SKILL.md): get OBSIDIAN_VAULT_PATH,OBSIDIAN_WIKI_REPO, OBSIDIAN_LINK_FORMAT, the QMD vars, and:
SKILL_FACTORY_OUTPUT_DIR — where generated skills land. Default:$OBSIDIAN_VAULT_PATH/_generated-skills (a vault-level, underscore-prefixed excluded dir — like _raw/_staging/_sources, NOT the skills/ knowledge category). This co-locates generated skills with the vault they were distilled from. Create it if missing. Note: _generated-skills/ holds runtime Agent-Skill bundles (name + description frontmatter), not wiki pages — never write them into skills/ (that category is for knowledge pages and is graph-/lint-/index-tracked).
SKILL_FACTORY_MATURITY — comma list of lifecycle: values that count as "mature".Default: reviewed,verified. Pages with tier: core also qualify.
index.md to understand what the vault holds.Decide which pages become the skill. The user may name a topic, tag, or project; otherwise propose candidates.
QMD_WIKI_COLLECTION), run qmd query "<topic>" -c "$QMD_WIKI_COLLECTION" --files(or vsearch) to gather semantically related pages — this is the intended way to find the full cluster, not just exact-tag matches.
Grep/Glob by tag and wikilink-neighbourhood (pages linked from the seed pages).lifecycle: is in SKILL_FACTORY_MATURITY orwhose tier: is core. Drop draft pages unless the user explicitly includes them.
~3 mature pages match, say so — a skill from one thin page isn't worth it; offer to proceed anyway or widen the net.
From the cluster, decide:
french-theory-expert,peptide-protocols). Must not collide with an existing skill in .skills/.
skill-creator): state when to use it(all the phrasings a user might say) and what it does. This field is what makes the skill fire.
method it applies, the caveats it respects. Distil this from the pages' synthesis, not a copy-paste.
references/ files.Create $SKILL_FACTORY_OUTPUT_DIR/<name>/ with:
<name>/
├── SKILL.md # frontmatter (name + pushy description) + reasoning approach + key knowledge
├── references/ # depth material distilled from the cluster
│ ├── <topic>.md # one per sub-theme; declarative knowledge, not chat
│ └── sources.md # provenance: which vault pages this was built from (+ their sources)
└── SKILL_FACTORY.md # provenance manifest (see below) — NOT part of the installed skillSKILL.md body should be lean (the trigger logic + a compact reasoning guide), pushing depth into references/. Follow the structure of existing skills in this repo. Preserve ^[inferred] / ^[ambiguous] markers when carrying over uncertain claims — a generated skill must not launder synthesis into fact.
`references/sources.md` lists every vault page used (by [[wikilink]]) and their upstream sources: — so the skill stays auditable back to the vault and original sources.
`SKILL_FACTORY.md` (factory metadata, kept out of the installable skill) records: generation date, the cluster pages + their lifecycle/tier, the maturity filter used, and the vault commit/hash if available. This lets a regenerate-on-update workflow diff later.
Optional, if the user asks: append/update a marketplace.json entry in the output dir (the OpenKB one-line-install convention) — still not an install, just a manifest.
skill-creator ships reusable scripts ($OBSIDIAN_WIKI_REPO/.skills/skill-creator/scripts/):
improve_description.py — tighten the generated description for better triggering.package_skill.py — bundle the skill dir into a distributable archive.quick_validate.py — sanity-check the skill's structure.Use them when the user wants a polished/validated artifact; don't reinvent them.
Tell the user:
$SKILL_FACTORY_OUTPUT_DIR/<name>/description ln -s ../../.skills/<name> <repo>/.claude/skills/<name> # after copying <name>/ into .skills/, sans SKILL_FACTORY.mdNote explicitly: review first; do not run setup.sh (it fans skills into global dirs); never global-install without explicit agreement.
Do not install it yourself. Do not write to .skills/. Done.
$SKILL_FACTORY_OUTPUT_DIR, never .skills/ or a global dirSKILL_FACTORY_MATURITY / tier: core)description is pushy and accurate (when + what)references/^[inferred]/^[ambiguous] markers preserved; no synthesis laundered into factreferences/sources.md traces back to vault pages + their sourcesSKILL_FACTORY.md provenance manifest present (excluded from the installable skill)~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.