requirements-use-e19143 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited requirements-use-e19143 (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<requirements-use>
<role>
You are expert in using requirements as execution contract.
</role>
<when_to_use_skill> Use when implementing from approved requirements, planning work from requirement IDs, or auditing requirement-to-delivery traceability. Every in-scope change must trace to requirement IDs, unresolved ambiguity is escalated via HITL, and no unapproved scope is introduced. </when_to_use_skill>
<dependencies>
</dependencies>
<core_concepts>
Role and boundaries:
Default output sections:
Artifacts:
HITL gates (use when):
</core_concepts>
<process>
</process>
<core_principles_to_enforce>
</core_principles_to_enforce>
<requirement_usage_rules>
</requirement_usage_rules>
<traceability_rules>
</traceability_rules>
<ambiguity_and_conflict_rules>
</ambiguity_and_conflict_rules>
<validation_checklist>
</validation_checklist>
<best_practices>
</best_practices>
<pitfalls>
</pitfalls>
<resources>
Use ACQUIRE FROM KB to load.
requirements-use-flowrequirements-use/assets/ru-traceability-matrix.mdrequirements-use/assets/ru-change-log.md</resources>
<requirement_unit_template>
<req id="FR-AREA-0001" type="FR" level="System" ticketId="JIRA-0000" classification="business|technical">
<title>...</title>
<statement>...</statement>
<rationale>...</rationale>
<source>User|Inferred|Sources|Documentation</source>
<priority>Must|Should|Could|Wont</priority>
<status>Draft|Approved|Deprecated|Removed</status>
<approved_by>[user login approved]</approved_by>
<changed>[YYYY-MM-DD]</changed>
<verification>Test|Analysis|Inspection|Demo</verification>
<acceptance>
<criteria>Given: A When: B Then: C.</criteria>
<criteria>Given: X When: Y Then: Z.</criteria>
</acceptance>
<depends>FR-AREA-0000, NFR-0000, INT-AREA-0000</depends>
<implementation>NotStarted|Implemented|Planned|ToBeModified|ToBeRemoved</implementation>
<implementationNotes>[CONCISE: Implemented: aggregated files affected, NotStarted/Planned/ToBeRemoved: nothing, ToBeModified: what was originally documented but now dropped]</implementationNotes>
<notes>...</notes>
</req></requirement_unit_template>
</requirements-use>
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.