connect-tools — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited connect-tools (Agent Skill) and scored it 92/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 2 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 2 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The single biggest accuracy upgrade is Bristol's own data + a real comp/cap-rate feed. Rob can't connect these — only the Bristol user can. So you run this with them: ask what they have, connect it, and for tools with no connector, set up the export-and-drop path. Hands-off (HARD LAW: do it for them; for the few clicks only they can do, walk them through exactly).
Look at the connectors already enabled in this Claude. Greet what's there, then only ask about the gaps.
"To make my analysis match how Bristol actually underwrites, what does the firm already use? No wrong answers — tell me what you've got:"
Ask, and ingest whatever they'll share:
When they provide any of it, extract the real assumptions (achieved effective rents & $/SF, true hard-cost/SF by product, exit caps, hurdle rates) into `bristol-os/reference/bristol-actuals.md` (cite the source doc + date). From then on, use Bristol's actuals over generic market estimates — that's the difference between an outside read and how Bristol underwrites.
Update the person's CLAUDE.md "connected tools" line and their bristol-os/memory/<slug>.md with what's connected and what export-feeds exist, so every future session knows. If they connected a market-data feed or shared actuals, note it so underwriting-research and market-comp-analysis use it first.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.