cli-forge-profile — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cli-forge-profile (Agent Skill) and scored it 92/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 2 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 2 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Optimize professional identity text so it is clear, credible, searchable, and ready to paste into the target platform.
This skill is worth using when the artifact represents a person: CV/resume, LinkedIn, GitHub profile README, Reddit/community bio, portfolio case study, speaker bio, freelance profile, recommendation request, or a maintained profile fact base. For project, product, repo, or company pages, hand off to cli-forge-readme, cli-forge-doc, cli-forge-prez, or ui-ux-pro-max instead.
Write from verified facts. Separate final copy from editorial notes. Never present planned, archived, speculative, or R&D-only work as delivered experience.
Default to confidentiality. Do not name clients, sectors, regulated contexts, architectures, metrics, repositories, or security-sensitive details unless the user has explicitly made them public or approved their use. Prefer disclosable categories such as "regulated infrastructure", "PCI-DSS fintech", or "air-gapped environment" only when they do not reveal protected operational context.
When the user gives existing files, preserve their source-of-truth role:
For maintained profile systems, keep verified facts in one canonical file such as profile/career-facts.yml or an existing cv-data.yaml, then derive CV, LinkedIn, GitHub, Reddit, freelance, and portfolio files from it. Track which language is canonical when maintaining *.fr.md and *.en.md pairs.
Use this skill as the personal-identity layer. Recommend, do not auto-run:
| Situation | Better handoff |
|---|---|
| Public repo README or product README | cli-forge-readme |
| Full project documentation, onboarding, architecture docs | cli-forge-doc |
| Speaker deck, meetup talk, pitch slides | cli-forge-prez |
| Portfolio site UI or landing page design | ui-ux-pro-max |
| Proof project deserves a live demo script | cli-forge-demo |
| Public code needs authorship/IP protection | cli-watermark |
| Profile claims depend on code quality or project proof | cli-cycle on the proof repo |
If installed alongside cli-code-skills, the shared reconnaissance model in ../shared/recon.md is useful. Adapt it to a person: what they do, who reads the profile, what expensive problem they solve, headline proof, differentiator, and next action.
references/editorial-lenses.md), not only when an author is named..md working file.NEEDS-REVIEW instead of smoothing them over.references/platforms.md before writing platform-specific output or checking character/structure constraints.references/editorial-lenses.md by default for every CV / LinkedIn / profile / freelance rewrite — apply the trajectory + scan-and-recall lenses and the anti-flou table on every pass — and also whenever the request mentions narrative, attention, memorability, comprehension, Christian Jacq, Fabien Olicard, storytelling, or reader psychology.references/method-bank.md when the user asks for best practices, books, videos, methods, research-backed writing, or source-informed optimization.Use this for direct user requests such as "rewrite my LinkedIn About" or "optimize this CV bullet".
## Version recommandee
[final copy]
## Pourquoi ca marche
- [short reasoning tied to reader/search/proof]
## Points a verifier
- [only factual checks, limits, or risk]Match the user's language unless they ask for translation or bilingual output.
Use this when editing or creating .md files that are working documents.
# [Surface] - [Name] - [Language/Target]
## Statut
- Source canonique: oui/non
- Fichier faits: [profile/career-facts.yml / cv-data.yaml / other]
- Cible: [reader / mission / role]
- Derniere validation: [date if known]
- Langue canonique: [fr/en/other]
- Niveau anonymisation: [public / anonymized / confidential]
- Ne pas presenter comme realise: [guardrails]
## A copier
[platform-ready sections]
## Checklist publication
- [ ] Limits checked
- [ ] Claims verified
- [ ] Sensitive clients/sectors/metrics anonymized or approved
- [ ] Keywords present without stuffing
- [ ] CTA present
- [ ] AI-assistant process markers removed from publishable fields
- [ ] Source-of-truth updated if this is not canonical
## Notes editoriales
[rationale, variants, manual actions]Use this shape when the user wants a maintainable profile system or when claims are spread across CV, LinkedIn, GitHub, and portfolio files.
person:
canonical_language: fr
target_markets: [France, remote-eu]
public_positioning: ""
claims:
- id: claim-001
text: ""
status: verified # verified | inferred | needs-review | forbidden
evidence: ""
surfaces: [cv, linkedin, github, portfolio]
confidentiality: public # public | anonymized | private
last_checked: YYYY-MM-DDDo not invent this file if the user only wants a one-off rewrite. Suggest it when the same facts must feed multiple surfaces or languages.
Lead with findings, then fixes.
Score each dimension 0-10:
Use the same NEEDS-REVIEW label for any claim that blocks a confident rewrite.
Before delivering final copy, check:
If a gate fails, provide the best safe draft plus a Points a verifier section. Do not hide factual gaps by making the copy more generic.
When the user gives no target, optimize for LinkedIn first if the source is a profile, and for ATS CV first if the source is a resume/CV.
For senior technical profiles, default to:
End with handoffs only when useful:
cli-forge-readme for a proof repository whose README needs to support the profile.cli-forge-prez for a speaker bio that needs a talk deck.cli-forge-demo for a portfolio proof project that needs a reproducible demo.cli-watermark when public code is part of the professional proof and IP defense matters.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.