migrate-to-skills — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited migrate-to-skills (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Convert Cursor rules ("Applied intelligently") and slash commands to Agent Skills format.
CRITICAL: Preserve the exact body content. Do not modify, reformat, or "improve" it - copy verbatim.
| Level | Source | Destination |
|---|---|---|
| Project | {workspaceFolder}/**/.cursor/rules/*.mdc, {workspaceFolder}/.cursor/commands/*.md | |
| User | ~/.cursor/commands/*.md |
Notes:
Rules: Migrate if rule has a description but NO globs and NO alwaysApply: true.
Commands: Migrate all - they're plain markdown without frontmatter.
# Before: .cursor/rules/my-rule.mdc
---
description: What this rule does
globs:
alwaysApply: false
---
# Title
Body content...# After: .cursor/skills/my-rule/SKILL.md
---
name: my-rule
description: What this rule does
---
# Title
Body content...Changes: Add name field, remove globs/alwaysApply, keep body exactly.
# Before: .cursor/commands/commit.md
# Commit current work
Instructions here...# After: .cursor/skills/commit/SKILL.md
---
name: commit
description: Commit current work with standardized message format
disable-model-invocation: true
---
# Commit current work
Instructions here...Changes: Add frontmatter with name (from filename), description (infer from content), and disable-model-invocation: true, keep body exactly.
Note: The disable-model-invocation: true field prevents the model from automatically invoking this skill. Slash commands are designed to be explicitly triggered by the user via the / menu, not automatically suggested by the model.
name must be lowercase with hyphens onlydescription is critical for skill discoverydescription from the frontmatter--- of the frontmatter).cursor/skills/{skill-name}/ (skill name = filename without .mdc)SKILL.md with new frontmatter (name and description) + the EXACT original body content (preserve all whitespace, formatting, code blocks verbatim)# prefix).cursor/skills/{skill-name}/ (skill name = filename without .md)SKILL.md with new frontmatter (name, description, and disable-model-invocation: true) + blank line + the EXACT original file content (preserve all whitespace, formatting, code blocks verbatim)CRITICAL: Copy the body content character-for-character. Do not reformat, fix typos, or "improve" anything.
If you have the Task tool available: DO NOT start to read all of the files yourself. That function should be delegated to the subagents. Your job is to dispatch the subagents for each category of files and wait for the results.
.cursor/skills/ for project, ~/.cursor/skills/ for user){workspaceFolder}/**/.cursor/rules/*.mdc), user commands (pattern: ~/.cursor/commands/*.md), and project commands (pattern: {workspaceFolder}/**/.cursor/commands/*.md):I. [ ] Find files to migrate in the given pattern II. [ ] For rules, check if it's an "applied intelligently" rule (has description, no globs, no alwaysApply: true). Commands are always migrated. DO NOT use the terminal to read files. Use the read tool. III. [ ] Make a list of files to migrate. If empty, done. IV. [ ] For each file, read it, then write the new skill file preserving the body content EXACTLY. DO NOT use the terminal to write these files. Use the edit tool. V. [ ] Delete the original file. DO NOT use the terminal to delete these files. Use the delete tool. VI. [ ] Return a list of all the skill files that were migrated along with the original file paths.
If you don't have the Task tool available:
.cursor/skills/ for project, ~/.cursor/skills/ for user).cursor/) and user (~/.cursor/) directoriesdescription, no globs, no alwaysApply: true). Commands are always migrated. DO NOT use the terminal to read files. Use the read tool.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.