oma-skill-creator — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited oma-skill-creator (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Create, revise, and validate OMA skills using the SSL-lite Markdown structure derived from Scheduling-Structural-Logical skill representation while keeping the result readable, executable, and maintainable.
.agents/skills/*/SKILL.md..agents/skills/{name}/SKILL.mdCanonical command path or Canonical workflow path to an execution-heavy skillresources/$CODEX_HOME/skills -> use Codex's built-in skill installer (external; not an OMA skill)skill_name: target directory name, preferably oma-{domain}skill_goal: capability the skill should addtrigger_intents: user prompts or domains that should activate the skillboundaries: when the skill should not be used and which skill should handle those casesexecution_model: whether the skill is command-heavy, workflow-heavy, judgment-heavy, or reference-heavySKILL.md using the SSL-lite top-level sectionsresources/*.md, config/*.yaml, scripts/*, or assets/* only when progressive disclosure or deterministic execution requires them.agents/skills/*/SKILL.mdresources/ssl-lite-template.mdresources/validation-checklist.mdSKILL.md and what belongs in resources/, config/, scripts/, or assets/.### Canonical command path inline.### Canonical workflow path inline.resources/ and reference them explicitly.| Failure | Recovery |
|---|---|
| Skill scope overlaps heavily with another skill | Add a clear When NOT to use boundary and cross-route |
| Execution path is vague | Add canonical command or workflow path inline |
SKILL.md becomes too long | Move detailed examples to resources/ and keep navigation in References |
| No reliable validation command exists | Use structural grep/awk checks and manual checklist validation |
| User input is underspecified | Make conservative assumptions and list them, unless the target behavior would be unsafe |
| Action | SSL primitive | Evidence |
|---|---|---|
| Read analogous skills | READ | Existing .agents/skills/*/SKILL.md |
| Select skill type | SELECT | Command/workflow/judgment/reference-heavy classification |
| Infer boundaries | INFER | Trigger intents and adjacent skill overlap |
| Write skill file | WRITE | New or updated SKILL.md |
| Add resources | WRITE | resources/, config/, scripts/, or assets/ |
| Validate structure | VALIDATE | Heading and canonical-path checks |
| Report result | NOTIFY | Changed files and validation summary |
rg, find, awk, sed, git diff --checkapply_patch for manual file editsresources/ssl-lite-template.md for the canonical section skeletonresources/validation-checklist.md for acceptance criteriaSKILL.md from resources/ssl-lite-template.md.### Canonical command path for fragile or repeatable commands### Canonical workflow path for decision, review, design, or research flowresources/.| Scope | Resource target |
|---|---|
CODEBASE | .agents/skills/*/SKILL.md, adjacent resources, project skill conventions |
LOCAL_FS | New skill directories and resource files |
PROCESS | Validation commands and optional generator/check scripts |
MEMORY | User requirements, assumptions, and validation notes |
.agents/skills/ when project rules would otherwise protect .agents/..agents/skills/.Scheduling, Structural Flow, Logical Operations, References.name and description; routing depends on description quality. Run oma skills audit after editing description to confirm the new wording does not collide with adjacent skills (warn ≥ 60%, fail ≥ 75% TF-IDF cosine).When NOT to use boundaries and cross-routes to adjacent skills.outputs: block when artifacts can be globbed so oma verify can perform a closure check.PREPARE, ACQUIRE, REASON, ACT, VERIFY, RECOVER, FINALIZE.READ, SELECT, VALIDATE, INFER, WRITE, CALL_TOOL, NOTIFY, and TERMINATE.resources/, not in the main skill body.resources/ssl-lite-template.mdresources/validation-checklist.md../_shared/core/context-loading.md../_shared/core/quality-principles.md.agents/eval/<skill>/ so oma skills eval can measure whether the skill improves task outcomes. See web/docs/guide/skill-eval.md for the fixture schema and checker types.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.