onboard — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited onboard (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Sets up the workspace by guiding the PM through populating context files.
/onboardRoute input to the right file using these structures:
Read all 4 context files (context/company.md, context/competitors.md, context/personas.md, context/product.md). Classify each as empty (only heading), thin (missing key sections), or solid (most sections filled). Don't tell the PM this classification yet. Use it to guide your questions.
Start open. Don't ask structured questions yet.
If the PM seems unsure what to share: "Do you have any of these lying around? A pitch deck, company website, existing PRD, investor update, competitor list, interview notes, strategy doc. Paste, link, or drop files in data/. Any of these will speed things up."
After the PM shares, process everything in one pass:
[Assumption, verify][Source: web, verify] so the PM knows what to check.[Updated: YYYY-MM-DD] Previously X, now Y.Before asking more questions, play back what you captured. This builds trust and catches misunderstandings early.
"Here's what I got from that: [2-4 sentence summary of what you wrote]. I flagged a couple of things as assumptions. Does this sound right, or should I fix anything?"
Show the progress checklist:
Context status:
- [x] Company — solid
- [ ] Competitors — thin (missing strengths/weaknesses)
- [ ] Personas — empty
- [x] Product — solidNow ask questions, but targeted, not a form. Pick 2-3 questions max based on the biggest gaps. Follow the outside-in order (company → market → competitors → personas → product) but don't force it.
Question style:
Don't interrogate. After 2-3 questions, process the answers (step 3-4 again) before asking more. The rhythm is: braindump → summarize → 2-3 questions → summarize → 2-3 questions.
Minimum viable context to do useful work:
When met, say so and offer the next step. Follow this order:
Don't force it. If the user wants to keep going, keep going. The goal is to show value early.
When all files are solid: "Context is looking good. You could run /analyze-competitors to go deeper on competition, or /prd to start speccing something out."
Progressive deepening: Don't try to fill everything during onboarding. Get to "good enough" and let other skills deepen context as a side effect of real work. When /prd finds thin personas, it asks 1-2 questions. When /analyze-competitors finds no competitors listed, it asks. Context grows through use, not just onboarding.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.