ops-integrate — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited ops-integrate (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
PREFS="${CLAUDE_PLUGIN_DATA_DIR:-$HOME/.claude/plugins/data/ops-ops-marketplace}/preferences.json"
PARTNER_REGISTRY=$(jq '.partner_registry // {}' "$PREFS" 2>/dev/null || echo '{}')Parse $ARGUMENTS:
--list → run List registered integrations then exit--list)jq -r '.partner_registry // {} | to_entries[] | "\(.key): \(.value.base_url) [\(.value.auth_type)]"' "$PREFS" 2>/dev/nullDisplay as a table:
Registered integrations:
hubspot https://api.hubapi.com [bearer]
stripe https://api.stripe.com [bearer]
sendgrid https://api.sendgrid.com [api-key]If no integrations registered: No integrations registered yet. Run /ops:integrate <service-name> to add one.
If --url not provided, use WebSearch to find:
Present findings via AskUserQuestion (≤4 options):
Found: <service-name> API — Base URL: <url> — Auth: <auth-type>
[Looks correct — continue] [Change base URL] [Change auth type] [Cancel]If "Change base URL": AskUserQuestion with free-text input for the new URL. If "Change auth type": AskUserQuestion (≤4 options): [bearer] [api-key] [basic] [oauth2]
Paste your <service-name> <auth-type> credential (it will be stored locally only)
[Paste now] [Configure later]If "Paste now": collect credential via AskUserQuestion free-text. Derive key name: <lowercase_service_name>_api_key
Write to preferences.json via atomic tmpfile swap:
tmp=$(mktemp)
jq --arg k "$KEY_NAME" --arg v "$CREDENTIAL" '.[$k] = $v' "$PREFS" > "$tmp" && mv "$tmp" "$PREFS"Curl the health/test endpoint with the credential:
# Bearer token
curl -sf -o /dev/null -w "%{http_code}" \
-H "Authorization: Bearer ${CREDENTIAL}" \
"${BASE_URL}${HEALTH_ENDPOINT}"
# API key header (X-Api-Key)
curl -sf -o /dev/null -w "%{http_code}" \
-H "X-Api-Key: ${CREDENTIAL}" \
"${BASE_URL}${HEALTH_ENDPOINT}"
# Basic auth
curl -sf -o /dev/null -w "%{http_code}" \
-u "${CREDENTIAL}:" \
"${BASE_URL}${HEALTH_ENDPOINT}"Report: ✅ if HTTP 200-299, ⚠️ with status code otherwise. If credential not yet configured, skip health check and report ⬜ health check skipped — credential not configured.
tmp=$(mktemp)
jq --arg name "${SERVICE_NAME}" \
--arg url "${BASE_URL}" \
--arg auth "${AUTH_TYPE}" \
--arg key_name "${KEY_NAME}" \
--arg health "${HEALTH_ENDPOINT}" \
'.partner_registry[$name] = {base_url: $url, auth_type: $auth, credential_key: $key_name, health_endpoint: $health, added: (now | todate)}' \
"$PREFS" > "$tmp" && mv "$tmp" "$PREFS"Confirmation output:
✅ <service-name> registered in partner registry
Auth: <auth-type>
Health: <base-url><health-endpoint>
Credential key: <key-name>
Access via: jq '.partner_registry["<service-name>"]' $PREFS# List all registered integrations
jq '.partner_registry' "${CLAUDE_PLUGIN_DATA_DIR:-$HOME/.claude/plugins/data/ops-ops-marketplace}/preferences.json"
# Look up a specific integration
jq '.partner_registry["hubspot"]' "$PREFS"
# Read a credential for a registered integration
jq -r ".$KEY_NAME" "$PREFS"
# Remove an integration from the registry
jq 'del(.partner_registry["<service-name>"])' "$PREFS" > tmp && mv tmp "$PREFS"~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.