github-installer — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited github-installer (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
When a GitHub URL is pasted, follow this process. Do NOT install before classifying.
Clone the repo to /tmp/ (or $env:TEMP on Windows) and inspect the structure:
mcp, bin, or server config) → it's an MCP serverCopy the entire skill directory to .claude/skills/[skill-name]/. The directory name should match the name field in the skill's frontmatter.
Use the plugin marketplace if it's listed:
/plugin install [name]@[marketplace]
/reload-pluginsIf not on a marketplace, the user must add it as a custom plugin source.
Add the server to .claude/settings.json under a mcpServers key. Format depends on the server — read its README.
Don't install into .claude/. Clone it to the project root or a sibling directory, depending on what makes sense.
.claude/skills/~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.