lenny-skillpack-creator — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited lenny-skillpack-creator (Agent Skill) and scored it 87/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 3 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 3 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Your job is to refactor “insight-heavy” Refound/Lenny skills into agent-executable skill packs: boundary-clear, artifact-driven, and testable.
This skill is designed to be compatible with both:
You are NOT writing a blog post. You are producing an installable folder with SKILL.md + references/ (+ optional scripts/).
Language requirement: The generated skill pack (SKILL.md and all referenced templates/checklists) must be written in English.
For a given source skill, output an installable skill directory:
<skill-slug>/SKILL.md (short, executable, high-signal)<skill-slug>/references/ (templates, checklists, rubrics, question bank, examples, source notes)<skill-slug>/scripts/ (optional: lint, scaffolding, batch tools)<skill-slug>/README.md (install + invoke + examples)Follow the spec in references/SKILL_PACK_SPEC.md.
Ask for the minimum information needed to proceed. If missing, proceed with explicit assumptions.
Required: 1) The source skill content (SKILL.md or copied text from the Refound page) 2) The intended user / agent context (e.g., “PM agent”, “Hiring assistant”, “Founder operator”, etc.) 3) The intended outputs (what artifacts should exist at the end)
Optional but helpful:
Every generated SKILL.md must include:
Use references/TRANSFORMATION_RULES.md as the canonical conversion playbook.
Keep SKILL.md operational. Move long content into references/ and cite the files.
Heuristic:
references/: everything else (templates, deep notes, long checklists)Use references/SECURITY_GUIDE.md.
If the environment supports file operations, create the folder structure and write files. Otherwise, output a complete file tree in-chat (one file at a time), clearly labeled.
Optional helper scripts (in this skill folder):
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.