folk-cli — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited folk-cli (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill when the user wants to work with folk.app CRM data through the first-party folk API and does not want a third-party connector.
The CLI command is folkctl. It is designed for OpenClaw-style agent use:
--json for machine-readable output--dry-run before mutations when you need to preview requests--all to follow pagination--no-input to fail instead of prompting--yes or --force only when the user has explicitly confirmed deletionNever print, log, or include FOLK_API_KEY in responses. Prefer environment variables over stored config in automated environments.
Run these before doing unfamiliar work:
folkctl --version
folkctl api ls
folkctl api docs people.list
folkctl people --helpWhen a command is missing or the schema is unclear, use the generic escape hatch:
folkctl api request GET /v1/users/me --json
folkctl api request POST /v1/people --data '{"firstName":"Ada"}' --dry-run --jsonFor OpenClaw, expect FOLK_API_KEY to be set in the environment:
export FOLK_API_KEY="fk_live_..."
folkctl auth statusFor local setup:
printf '%s' "$FOLK_API_KEY" | folkctl auth login --token-stdinfolkctl people list --limit 20 --json
folkctl people search "Ada Lovelace" --json
folkctl people list --filter fullName:like:Ada --jsonPreview first:
folkctl people create \
--first-name Ada \
--last-name Lovelace \
--email [email protected] \
--group-id grp_123 \
--dry-run --jsonThen run without --dry-run once confirmed.
folkctl companies create --name "Acme Inc" --url https://acme.example --group-id grp_123 --dry-run --json
folkctl companies update com_123 --name "Acme Corporation" --dry-run --jsonfolkctl groups list --json
folkctl groups fields grp_123 person --json
folkctl groups fields grp_123 company --json
folkctl groups fields grp_123 Deals --jsonfolk deals are addressed under a group and an object type, usually the name of the deal object field, for example Deals.
folkctl deals list --group-id grp_123 --object-type Deals --json
folkctl deals create --group-id grp_123 --object-type Deals --name "Project Alpha" --company-id com_123 --person-id per_123 --custom Status=Active --dry-run --jsonfolkctl notes create --entity-id per_123 --content "Met at SaaStr. Follow up next week." --visibility private --dry-run --json
folkctl reminders create --entity-id per_123 --name "Follow up" --visibility private --recurrence-rule "DTSTART;TZID=Europe/Paris:20250717T090000\nRRULE:FREQ=WEEKLY;INTERVAL=1" --dry-run --json
folkctl interactions create --entity-id per_123 --date-time 2025-07-17T09:00:00.000Z --title "Coffee" --content "Discussed the new project." --type ☕️ --dry-run --jsonfolkctl webhooks list --json
folkctl webhooks create --name "My app" --target-url https://example.com/webhook --event person.created --dry-run --jsonBefore create/update/delete commands, prefer --dry-run --json and summarize the exact resource, method, path, and body for the user.
For deletes, do not pass --yes or --force unless the user explicitly asks to delete the exact record. If the user has not confirmed, run a dry-run or ask for confirmation.
If the API returns 401/403, tell the user to verify or rotate FOLK_API_KEY. Do not ask them to paste secrets into chat.
If folkctl is missing, install it from npm (or from GitHub as a fallback):
npm install -g folkctl
# or: npm install -g github:j-edel/folkctl~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.