aegis — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited aegis (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use Aegis as an operating system for work, not as a keyword command layer. The agent should reason normally, then use explicit Aegis MCP tools for state changes and evidence. Aegis state must not be answered from the local CLI, direct REST/curl calls, local token files, database queries, repository files, or chat-history inference.
can you do", call aegis_mcp_status first when available.
aegis_board,aegis_members, and aegis_nudges are the usual starting point.
worker readiness. Use tool output or say the state is unknown.
aegis_* MCP tool is unavailable in the current host, reportthe MCP/readiness gap and stop. Do not substitute aegis CLI output, local API responses, or repository inspection for MCP state.
Create or update a WorkItem only for durable work that needs follow-up, assignment, lifecycle status, evidence, or later review.
Do not create WorkItems for simple Q&A, weather/date lookups, script/tool requests that complete immediately, casual chat, or personal reminders unless the user explicitly asks to track them as work. For those, answer directly or use the relevant automation/tool path if the host exposes one.
When the user asks to clean bad items, prefer:
aegis_board to identify candidates.aegis_search_tools and aegis_lifecycle if the right cleanup/status toolis unclear.
aegis_transition_item to park/block real work; aegis_move_item when atarget lifecycle status needs multiple legal steps.
aegis_clear_item for non-work/accidental board items.aegis_delete_item with confirm=true only when the user explicitly asks todelete accidental items.
aegis_create_item.aegis_inbox, aegis_advance_item, aegis_transition_item,aegis_move_item, aegis_comment_item.
aegis_members, aegis_add_member, aegis_assign_item.aegis_recruiting_catalog, aegis_hire, aegis_dispatch.aegis_switchboard with explicit instructions and atarget of auto, aegis-coder, claude-code, or codex.
aegis_team_health, aegis_nudges, aegis_report,aegis_statuses, aegis_leaderboard.
aegis_rebuild_context, aegis_run_compact,aegis_memory_review, aegis_approve_memory, aegis_reject_memory.
aegis_gateway_status, aegis_gateway_accounts,aegis_gateway_deliveries.
accepts it. Moving to testing means "ready for review", not "released".
changed when the reason matters.
connected workers from tool-ready workers. A connected worker without a tool catalog is not the same as a usable local execution path.
"write a script to check weather" request, say what actually happened and provide the script only if the user still wants a file.
weather should default to local date/time and Celsius unless the user asks otherwise.
Read only what the task needs:
references/tool-map.md for exact MCP tool groups and inputs.references/workflows.md for end-to-end operator flows.references/boundaries.md for board-vs-chat, evidence, persona, and safetyrules.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.