elnora-admin — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited elnora-admin (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Authentication, API key management, account settings, health checks, audit logs, feedback, and shell completions.
Elnora is available via two methods. Use whichever is configured.
Option A — CLI via Bash (preferred)
Run commands via your Bash/Shell tool as elnora <group> <action> .... Verify with elnora --version. CLI uses ~5× fewer tokens than MCP.
Option B — MCP tools (when CLI isn't installed)
Look for tools prefixed mcp__elnora__ in your available tools. Call them with structured parameters (camelCase — e.g. projectId, not project-id). See the "MCP Tool Names" table below for the mapping.
If neither is available, tell the user to install one:
curl -fsSL https://cli.elnora.ai/install.sh | bash (macOS/Linux)or irm https://cli.elnora.ai/install.ps1 | iex (Windows)
claude mcp add elnora --transport http --scope user https://mcp.elnora.ai/mcpthen /mcp to authenticate.
Never fabricate tool names. Valid commands are in the Commands section; their MCP equivalents are in the MCP Tool Names table.
CLI="elnora"$CLI --compact auth login --api-key <KEY>
$CLI --compact auth login --api-key <KEY> --profile university--api-key is required — there is no interactive prompt. Keys must start with elnora_live_ and be 20+ characters. Saves to ~/.elnora/profiles.toml.
Response: {"profile":"default","verified":true,"configPath":"/Users/<you>/.elnora/profiles.toml"}
$CLI --compact auth status
# -> {"profile":"default","authenticated":true,"projectCount":N}$CLI --compact auth logout
$CLI --compact auth logout --allWithout --all, removes the current profile. With --all, removes all saved profiles from profiles.toml.
$CLI --compact auth profiles
# -> {"profiles":[{"name":"default","apiKey":"elnora_live_...abcd"}]}Shows all configured profiles with masked API keys.
$CLI --compact auth validate
$CLI --compact auth validate --token <TOKEN>Validates the current API key (or a specific token).
$CLI whoami
$CLI --json whoamiShows current profile, masked API key, and organization name.
$CLI --compact api-keys create --name "CI Pipeline"
$CLI --compact api-keys create --name "Agent Key" --scopes "read,write"IMPORTANT: The key value is only shown once in the response. Store it securely.
$CLI --compact api-keys list$CLI --compact api-keys revoke <KEY_ID>
# -> {"revoked":true,"keyId":"..."}Destructive — confirm with user first.
$CLI --compact api-keys get-policy
# -> {"policy":"all_members"}$CLI --compact api-keys set-policy --policy admins_only
$CLI --compact api-keys set-policy --policy all_membersOrg admin/owner only. Values: all_members or admins_only.
$CLI --compact account get <USER_ID><USER_ID> is positional. Get user IDs from account users.
$CLI --compact account update <USER_ID> --first-name Jane --last-name DoeMust provide at least one of --first-name or --last-name.
$CLI --compact account agreements$CLI --compact account accept-terms <DOCUMENT_VERSION_ID><DOCUMENT_VERSION_ID> is positional.
$CLI --compact account delete
$CLI --compact account delete --yesDANGEROUS: Permanently deletes the user's account. Irreversible. Requires typing "DELETE" to confirm. Use --yes to skip (non-interactive/CI only).
$CLI --compact account users
$CLI --compact account users --state Active
$CLI --compact account users --state Deleted --ref-code ABC123Optional filters: --state (Active, Pending, Deleted), --ref-code.
$CLI --compact account add-legal-doc --document-type TermsOfService --version "2.0" --content "Terms text..." --effective-date 2026-04-01| Flag | Required | Notes |
|---|---|---|
--document-type | Yes | e.g. TermsOfService, PrivacyPolicy |
--version | Yes | Version string |
--content | Yes | Document content |
--effective-date | No | ISO 8601 date |
$CLI --compact account update-legal-doc <VERSION_ID> --content "Updated terms..."
$CLI --compact account update-legal-doc <VERSION_ID> --effective-date 2026-05-01<VERSION_ID> is positional. Must provide at least one of --content or --effective-date.
$CLI --compact account delete-legal-doc <VERSION_ID> --yes<VERSION_ID> is positional. Requires confirmation unless --yes.
$CLI --compact flags list$CLI --compact flags get --key enable-new-editor--key is a required flag (not positional).
$CLI --compact flags set --key enable-new-editor --value true --yes| Flag | Required | Notes |
|---|---|---|
--key | Yes | Flag key name |
--value | Yes | true or false |
--yes | No | Skip confirmation prompt |
WARNING: Affects ALL users on the platform. Always use --yes in agent context.
$CLI healthNo auth required. Returns {"status":"ok","timestamp":"..."} on success. Exits 1 if unreachable (network error).
$CLI doctorRuns 10 diagnostic checks across three sections: CLI (API reachability, authentication, version currency, config permissions, AI server reachability, PATH configured), Claude Code (plugin enabled, skills installed, plugin version match), and MCP (server reachable). Each check reports pass / fail / warn / skip; the summary line shows the tally.
elnora open # Opens platform (default)
elnora open docs # Opens documentation
elnora open keys # Opens API keys page
elnora open billing # Opens billing page
elnora open github # Opens GitHub repo$CLI --compact audit list --org <ORG_ID>
$CLI --compact audit list --org <ORG_ID> --action "project.created" --user-id <USER_ID>
$CLI --compact audit list --org <ORG_ID> --page 2 --page-size 50--org is a required flag. Optional filters: --action, --user-id.
$CLI --compact feedback submit --title "Feature request" --description "Add batch export"Both --title and --description are required.
elnora completion bash >> ~/.bashrc
elnora completion zsh >> ~/.zshrc
elnora completion fish > ~/.config/fish/completions/elnora.fishAll commands in this skill are auto-registered as MCP tools. The mapping is elnora <group> <action> → elnora_<group>_<action> (camelCase preserved; only dots are replaced with underscores).
| CLI command | MCP tool name |
|---|---|
auth login | _CLI only — writes to local ~/.elnora/profiles.toml_ |
auth logout | _CLI only — removes from local profile store_ |
auth status | _CLI only — reports local profile state_ |
auth profiles | _CLI only — reads local profile store_ |
auth validate | _CLI only — uses local profile fallback_ |
api-keys create | elnora_api-keys_create |
api-keys list | elnora_api-keys_list |
api-keys revoke | elnora_api-keys_revoke |
api-keys get-policy | elnora_api-keys_getPolicy |
api-keys set-policy | elnora_api-keys_setPolicy |
account get | elnora_account_get |
account update | elnora_account_update |
account agreements | elnora_account_agreements |
account accept-terms | elnora_account_acceptTerms |
account add-legal-doc | elnora_account_addLegalDoc |
account update-legal-doc | elnora_account_updateLegalDoc |
account delete-legal-doc | elnora_account_deleteLegalDoc |
account delete | elnora_account_delete |
account users | elnora_account_users |
flags list | elnora_flags_list |
flags get | elnora_flags_get |
flags set | elnora_flags_set |
audit list | elnora_audit_list |
feedback submit | elnora_feedback_submit |
health check | elnora_health_check |
Note: whoami, doctor, open, completion, update, setup, and all auth sub-commands are CLI-only — no MCP equivalents. Auth commands manage local profile storage and interactive prompts, which don't translate to a remote MCP server.
Verify setup:
$CLI health && $CLI --compact auth statusRotate an API key:
$CLI --compact api-keys create --name "Replacement Key"
# Update .env with the new key, then:
$CLI --compact api-keys revoke <OLD_KEY_ID>~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.