ordito-remove-block — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited ordito-remove-block (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Ordito の 書き込みスキル(仕様 §7.1)。既存 IR ドキュメントからブロックを1つ削除する(§3.3)。
ordito-update-block)/位置を変える(ordito-move-block)/ページごと消す(ordito-delete-page)。{ "doc": "guides/quickstart", "block_id": "b3" }doc(必須) / block_id(必須): 削除するブロック id(tabs 内も可, §3.3.3)。ir_dir(任意) / dry_run(任意, bool: 書き込まず削除対象を before として返すだけ)。{ ok, doc, block_id, removed, before, updated_at, generated:false, note } before は削除されたブロックの内容(取り消し材料)。削除後に語彙スキーマ検証が通らなければ書き込まずエラー。
echo '{"doc":"guides/quickstart","block_id":"b3"}' | node "${CLAUDE_SKILL_DIR}/remove-block.js"~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.