Aegis Operator — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Aegis Operator (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
Aggregate score unchanged between these scans.
The primary manifest — the file an agent reads to learn what this artifact does.
Operate Aegis state through MCP tools only, not by guessing state from conversation or by falling back to the local CLI, REST API, curl, database queries, repository files, or shell probes.
aegis_mcp_status.
aegis_board before changing anything. Addaegis_members, aegis_nudges, or aegis_team_health when relevant.
layer is missing: MCP config, auth, server, Gateway, provider planner, connected local worker, or tool-ready local worker.
aegis_* MCP tool is not callable in the current host, stopand report mcp_unavailable or the concrete missing layer. Do not use aegis CLI commands, direct HTTP calls, local access-token files, or repo inspection as a substitute for Aegis MCP state.
Only create WorkItems for durable work requiring follow-up, assignment, lifecycle status, evidence, or review.
Do not put ordinary questions, completed weather/time/web/script requests, casual chat, or simple personal reminders on the board unless the user explicitly says to track them as work.
aegis_search_tools when unsure which Aegis MCP tool applies;aegis_lifecycle when unsure about statuses or transitions.
aegis_create_item, then optionally aegis_comment_item.aegis_inbox, aegis_advance_item, aegis_transition_item,aegis_move_item.
aegis_board, then aegis_clear_item for non-work/accidentalboard items, or aegis_delete_item when the owner explicitly requests deletion.
aegis_members, aegis_add_member, aegis_assign_item.aegis_recruiting_catalog, aegis_hire, aegis_dispatch, oraegis_switchboard.
aegis_team_health, aegis_nudges, aegis_report,aegis_statuses.
aegis_memory_review, aegis_approve_memory,aegis_reject_memory, aegis_rebuild_context, aegis_run_compact.
aegis_gateway_status, aegis_gateway_accounts,aegis_gateway_deliveries.
Return concise operator-facing prose:
Never claim that WebFetch, server-side tools, or MCP calls were a local script. For Aegis board, report, Gateway, member, memory, or worker-state requests, there is no non-MCP fallback. Other tools may help diagnose why MCP is missing, but they must not be used to answer Aegis state as if the plugin operated normally.
Read references/aegis-mcp-workflows.md when the task needs exact tool grouping, cleanup guidance, memory review, or Gateway diagnosis.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.