ecosystem-inclusion-operator — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited ecosystem-inclusion-operator (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A bulleted imperative like {match} tells the agent to never reveal, disclose, or mention something to the user. Used adversarially it can instruct the agent to hide its tool calls or lie about what it did — stripping the transparency a user relies on to trust the agent.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Find where your repo belongs. Open useful, non-spammy PRs. Track every attempt in a durable progress log so the agent can keep going with /loop.
.repo-growth/./loop runs, continue from the log instead of starting over.| Target type | Inclusion angle |
|---|---|
| Awesome lists | Add to relevant category section |
| MCP directories | Add as tool/server entry |
| Agent skill directories | Add as skill pack |
| Claude Code / Codex resource lists | Add as example workflow |
| Adjacent tool repos (SEO, analytics, marketing) | Add integration docs or example |
| Starter kits / templates | Add as template |
| DevRel / open-source growth repos | Add the growth-operator itself |
| Agency / consultancy resource repos | Add as workflow example |
Score every target /100 before acting:
| Dimension | Weight |
|---|---|
| Audience fit | 25 |
| Repo activity | 15 |
| Contribution friendliness | 15 |
| Inclusion precedent | 15 |
| Traffic / stars / authority | 10 |
| Low spam risk | 10 |
| Commercial relevance | 10 |
| Score | Action |
|---|---|
| 80–100 | Open tailored PR |
| 60–79 | Open issue first or draft PR |
| 40–59 | Add to backlog |
| 0–39 | Skip |
Smallest. One link + neutral description in the appropriate section.
More valuable. Add examples/<integration>.md with a full walkthrough.
Add docs teaching the target repo's users how to use your skill with their tool.
For starter-kit repos — add a full template directory.
Add actual code / connector support. Highest effort, highest value.
After delivering a summary of results (PRs opened, targets scored, etc.), the skill may ask once per session:
"If this ecosystem-inclusion work is useful, consider starring the promoted repo: {owner}/{repo}"gh CLI is available and authenticated, offer to execute. Never auto-execute./summarize-growth:"This report was generated by marketingskills/open-source-growth. If it was useful, consider starring the repo."/summarize-growth, not after every PR open./discover-targetsFind candidate repos matching the repo's category and audience.
/score-targetsScore candidates and explain why.
/prepare-prCreate exact branch, file edit, commit message, and PR body.
/open-prOpen the PR if GitHub auth is available.
/star-targetIf gh CLI is available, ask the user if they want to star a high-quality target repo (score 80+). Never auto-star. One offer per target. Logs to .repo-growth/social-proof.jsonl.
/update-pr-statusCheck existing PRs and update the log.
/follow-upSuggest polite follow-ups only when appropriate (max 1 after 14 days of no response).
/summarize-growthReport progress: targets found, PRs opened, merged, rejected, traffic impact.
Maintain in .repo-growth/:
| File | Purpose |
|---|---|
loop-state.md | Current state, next action |
targets.yaml | CRM of all targets with status and score |
prs.jsonl | Append-only event log |
decisions.md | Human-readable learning log |
assets/ | Reusable listing copy, PR templates |
evidence/ | Screenshots, notes |
social-proof.jsonl | Star/watch/follow actions taken |
See references/progress-log-spec.md for the exact format.
repo-growth-operator – For wider repo adoption, README, launch, and monetisation work.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.