forki — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited forki (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Pattern: binary → roles → trade-off → forced choice. This is a decision skill, not an explanation skill. If the user already has a verdict and only needs slides, route to galmuri:deck (preset decision-sandwich-6); if they need a summary of a decision doc, route to galmuri:distill / explain / doc.
If invoked with no context (no decision topic, no problem description): → Ask: "어떤 결정이 필요한가요? 고민 중인 상황을 설명해주세요. e.g. `Postgres vs SQLite for the new service`, `hire vs contract for the data role`." → Wait for user response before proceeding to Step 0.
| Category | Steps | LLM authority |
|---|---|---|
| Auto query | 0 (query) | Full |
| Flow gate | 0 (decision) | None — trust / reopen |
| Verdict gate | 1, 3, 6 | None — user states it |
| Confirmation gate | 2, 5 | Propose only |
| Scaffold (skippable) | 4, 7 | Propose, user skip |
| Side effect (opt-out) | 8 | y / n |
LLM proposes; user confirms before next step. No autonomous mode.
| File | First loaded at | Used for |
|---|---|---|
references/protocol.md | Step 1 (first HITL) | All HITL prompts, response rule parsing, report templates |
references/asset.md | Step 0 entry, or Step 8 entry if Step 0 was skipped | Bash query/record blocks for .galmuri/ |
Each reference is loaded at most once per forki invocation and reused across all subsequent steps. See Context Budget below for the exhaustive read/write inventory.
→ Load references/asset.md and execute the Step 0 query block as documented there. The full branching logic (trust / reopen / skip on absent / skip on no match) lives in asset.md.
Exactly 2 options. 3+ → collapse to "do A vs everything else". "It depends" → ask user to constrain.
→ HITL via Step 1 prompt in references/protocol.md. Wait for explicit confirmation. Output: A vs B, one line.
Compress to one sentence: "Who executes X?" / "Who owns X?" / "What changes when X?"
→ HITL via Step 2 prompt in references/protocol.md. Reject → propose alternative. Reject again → back to Step 1 (binary is wrong).
On entry, output first line: Step 3 attempt {n}/3. {n} starts at 1 on first Step 3 entry; +1 on each back-jump from Step 5/6/7. On attempt 3/3, this is the last allowed run (2 back-jumps total). If forki would back-jump to Step 3 again from this attempt, abort instead: "forki could not converge after 2 back-jumps. Gather more context outside this skill."
Fill all 4 roles per option:
| Role | Question |
|---|---|
| Decision | Who judges? |
| Execution | Who acts? |
| Validation | Who verifies? |
| Recovery | Who fixes when broken? |
→ HITL via Step 3 prompt in references/protocol.md. LLM may draft; user confirms or overrides each cell. Empty ? → re-ask only those cells.
→ HITL via Step 4 prompt in references/protocol.md. Skip when concrete enough or user says skip. Record skip in report.
A: gains {X}, loses {Y}
B: gains {Y}, loses {X}Axes: flexibility↔stability, speed↔safety, autonomy↔control.
→ HITL via Step 5 prompt in references/protocol.md.
Choice: Option {A|B}. Reason: {one structural reason}.
→ HITL via Step 6 prompt in references/protocol.md. LLM must not answer for the user, must not signal a preference. "You choose" → reply: "forki cannot decide for you."
User truly cannot choose → back-jump to Step 3.
→ HITL via Step 7 prompt in references/protocol.md. Cannot answer all 3 → back-jump to Step 3. Skip on skip.
Trigger: runs only after Step 6 reaches a verdict (and Step 7 if not skipped). If forki aborts at any earlier step (counter 3/3, user Stop, Step 0 trust reuse, etc.), Step 8 does not run.
→ Load references/asset.md for sub-steps 8.0 / 8.1 / 8.2 (pre-check, HITL, write+record).
Side effect, not gate: the Step 6 verdict stands regardless of Step 8 outcome.
forki is a thinking skill, not a reading skill.
Reference loading: see References section above (single source of truth).
Filesystem I/O:
| Operation | When |
|---|---|
Read .galmuri/assets/*.jsonl (tag-filtered) | Step 0 only. Skip if directory absent. |
Write /tmp/forki-{ts}.md | Step 8 sub-step 8.2 only, after y confirmation. |
Append .galmuri/assets/decision-{ts}.jsonl (1 line) | Step 8 sub-step 8.2 only, via scripts/record-asset.sh. |
Maximum 2 references in context simultaneously (protocol.md + asset.md).
yes / ok / 응 as confirmation. Always re-ask.Both / depends / later as final choice.galmuri/ from forkin. Honor opt-out.references/protocol.md~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.