headless-ghidra-batch-decompile — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited headless-ghidra-batch-decompile (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
P4 consumes the current selected batch, applies enriched metadata, runs the approved Ghidra decompilation path, and records per-function substitution artifacts.
ghidra-agent-cli ghidra apply-renamesghidra-agent-cli ghidra verify-renamesghidra-agent-cli ghidra apply-signaturesghidra-agent-cli ghidra verify-signaturesghidra-agent-cli ghidra decompileghidra-agent-cli ghidra rebuild-projectghidra-agent-cli substitute addghidra-agent-cli substitute validateghidra-agent-cli gate check --phase P4Locking and Ghidra invocation are handled internally by the CLI. The public workflow surface is the CLI plus the YAML outputs below. When substitution/next-batch.yaml is ready, process only functions with clear P3 names and signatures.
artifacts/<target-id>/baseline/*.yamlartifacts/<target-id>/runtime/fixtures/artifacts/<target-id>/runtime/hotpaths/call-chain.yamlartifacts/<target-id>/third-party/identified.yamlartifacts/<target-id>/third-party/pristine/<library>@<version>/artifacts/<target-id>/third-party/compat/<library>@<version>/ if neededartifacts/<target-id>/metadata/renames.yamlartifacts/<target-id>/metadata/signatures.yamlartifacts/<target-id>/substitution/next-batch.yamlartifacts/<target-id>/substitution/functions/<fn_id>/capture.yamlartifacts/<target-id>/substitution/functions/<fn_id>/substitution.yamlwhen the workflow records them
substitute.
substitution.yaml with provenance, fixtures,and status.
substitution/functions/<fn_id>/.when the backend requires it.
ghidra-agent-cli for supported apply/verify/decompile,substitution, fixture, or gate actions.
third-party/compat/.
and ask the user first.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.