ordito-move-block — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited ordito-move-block (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Ordito の 書き込みスキル(仕様 §7.1)。既存ブロックを同一ドキュメント内で並べ替え/再配置する(§3.3)。
ordito-update-block)/追加・削除(ordito-add-block / ordito-remove-block)/ナビの並びを変える(ordito-edit-collection)。{ "doc": "guides/quickstart", "block_id": "b8", "position": { "before": "b4" } }doc(必須) / block_id(必須): 動かす既存ブロック id。position(必須): 移動先。at:<index> / after:"<bid>" / before:"<bid>"、タブ内へは in_tab:{ "block_id","tab_index" }。基準ブロックに自分自身は指定不可。ir_dir(任意) / dry_run(任意)。{ ok, doc, block_id, moved, position, updated_at, generated:false, note } 移動後に語彙スキーマ検証が通らなければ書き込まずエラー。
echo '{"doc":"guides/quickstart","block_id":"b8","position":{"before":"b4"}}' \
| node "${CLAUDE_SKILL_DIR}/move-block.js"~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.