filing-bug-reports — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited filing-bug-reports (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Generate a self-contained bug report as a Markdown file that gives a receiving developer everything needed to reproduce the issue — without prescribing root cause or solution.
code-review skill insteadissues/BUG-<NNN>-<slug>.md (next available number, kebab-case slug from title)issues/ directory if it doesn't existSkill state vocabulary. The skill spec uses progressive disclosure: metadata (name + description) is always in context; the body loads only when triggered. These terms describe the observable states and are agent-agnostic — they hold for any host that implements the Agent Skills standard, not just Claude Code:
description in metadata. (Default state, no glyph.)description field is absent from the agent's registration entry. Record which skills are name-only and stop there. Do not read SKILL.md files on disk to verify whether descriptions exist — the available-skills listing is the only state the bug report records. Reading the source frontmatter is cause-investigation, which is out of scope.Note: some host agents drop descriptions from the listing automatically when total skill text exceeds an internal budget — for example, Claude Code allocates a character budget that scales with context window size and strips descriptions from least-recently-invoked skills first when the budget is exceeded. Name-only is therefore often expected host behavior in a session with many skills loaded, not a SATK defect. Record the state, but don't frame the bug report as "SATK skill registration is broken" unless the same skill is name-only in a session where the budget clearly isn't exhausted (few skills present, or the host reports no truncation).
SKILL.md exists on disk under the toolkit's skills-catalog/ but is absent from the available-skills list. ✗ is scoped to SATK only — we don't track unregistered skills from other sources.With those definitions:
references/bug-report-template.md.model-based-design-core skills whose bodies are already in your context, and only if you noticed a conflict between them while doing the work that's plausibly related to this bug. Don't re-read skill bodies to hunt for conflicts; if nothing surfaced naturally, write N/A — <reason>.SATK-specific (when Simulink MCP tools are available):
VERSION file at the SATK root. If it doesn't exist and a .git/ folder is present, read the latest commit hash and note "development build (<hash>)". If neither exists, ask the user what version of Simulink Agentic Toolkit they are usingevaluate_matlab_code → disp(version); ver('simulink'); disp(pwd); disp(computer('arch'))satk_initialize.m status: evaluate_matlab_code → which('model_read') (empty = not run)evaluate_matlab_code → try; disp(connector.securePort); catch; disp('not running'); end.vscode/mcp.json for server mode and binary pathreferences/bug-report-template.md. Fill every required section. Mark optional sections N/A if not applicable.[Area] — Action — Unexpected result<REDACTED>references/bug-report-template.md — The output template (always use this structure)----
Copyright 2026 The MathWorks, Inc.
----
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.