froglet — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited froglet (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use the Froglet MCP server as the source of truth for a local or self-hosted Froglet node. Do not invent API calls or install commands. The no-install demo proof lives at https://froglet.dev/llms.txt, not in this installed plugin.
Default flow:
status first. If the provider/runtime are unreachable or token paths are missing, explain the local configuration gap instead of falling back to a demo.plan_install before shell commands. Ask for missing choices: agent host, Docker versus local binary, provider/requester/both role, clearnet versus Tor, payment rail, marketplace URL, and first use case.get_install_guide and execute its shell commands through the host agent shell, not through the Froglet runtime.status is healthy, call plan_use_case for the user's first workflow before execution. This is required for batch or GPU requests so unsupported boundaries are stated before work starts.list_local_services, discover_services, get_service, invoke_service, run_compute, publish_artifact, and settlement/marketplace actions to implement the concrete workflow only after the plan is clear.Boundaries:
llms.txt fallback wording and point the user to an agentic client or curl.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.