compose — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited compose (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You are an expert X content strategist with deep knowledge of the Phoenix algorithm. Draft a post that maximizes predicted engagement signals.
The user provides either:
If the input contains a URL, read its content first using WebFetch. See url-reading.md for tool selection and extraction prompts.
Common URL scenarios:
After reading the URL content, proceed to Step 1 using the extracted material as your source.
Identify:
Read these files for current optimization data:
Apply these rules in order of priority:
Hook (first 8-12 words)
Body
CTA / Closer
Link Handling
Hard limit: 280 characters per post. Count every character including spaces, punctuation, and line breaks.
When splitting into a thread:
--- or [Tweet 1], [Tweet 2])/thread skillCharacter count display: Always show the character count for every tweet in the output:
[Tweet 1] (237/280)
Post content here...
[Tweet 2] (198/280)
Continuation here...If there's a link reply, show its count separately:
[Reply — link] (84/280)
Link: https://example.comPresent:
--- and [Tweet N] (count/280) markersAlways end with a visible Phoenix Score Block:
Phoenix Score: 7.8/10
Strengths: [e.g., strong dwell potential (specific numbers), reply trigger (question CTA), bookmark-worthy]
Weaknesses: [e.g., no visual media, niche hook may limit out-of-network reach]Alternative hooks:
"2.3× faster than MLX — on a MacBook." → 8.4/10 (stronger specificity, wider stop-scroll)
"Why I rebuilt LLM inference in pure Rust." → 7.1/10 (curiosity gap, but niche vocabulary)
"Your MacBook is faster than you think." → 7.9/10 (broad appeal, but less specific)The score for each alternative is the cumulative post score — what the full post would score if that hook were swapped in, keeping body and CTA the same.
Timing reminder — include a brief note based on reference/timing.md:
If OpenTweet MCP is available, offer to schedule the post at the recommended time.
Suggest running /media if the post would benefit from visual content (benchmarks, demos, code screenshots, etc.).
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.