knowledge-packs — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited knowledge-packs (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This play makes Bristol OS more powerful by connecting the right tools and pulling in the right open-source knowledge. Two reference files live in bristol-os/catalog/:
TOOL-CATALOG.md — every recommended connector, tiered and mapped to plays.GITHUB-PACK.md — verified GitHub repos (skills, MCP servers, RE/finance/maps data).If a task would be materially better with a tool the user doesn't have, say so and offer to set it up — don't silently do a weaker job. Example: asked for rent comps with only web search, deliver what you can, then: "If you connect Yardi Matrix or I help Rob set up the free Census data server, I can make this much sharper — want that?"
Settings → Connectors in plain English. NEVER ask them to install a GitHub MCP server.GITHUB-PACK.md.TOOL-CATALOG.md and say what it'll do for them.onboarding/connector-setup.md).anthropics/skills, hesreallyhim/awesome-claude-code): you may git clone or fetch specific files into a local knowledge/ folder to learn patterns or reuse a skill (like the official docx/xlsx skills for deliverables). Pull only what's relevant; don't clone everything.If Bristol needs something not in the catalog, consult the MCP directories in GITHUB-PACK.md (modelcontextprotocol/servers, punkpeye/awesome-mcp-servers), find a candidate, verify it exists and is maintained (check stars/last update), and only then recommend it. Never invent a tool or repo.
CLAUDE.md so the setup stays self-aware.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.