mcp-engine-onboarding — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited mcp-engine-onboarding (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill to turn "onboarding" into a regular-user setup concierge. This is an orchestration workflow over existing SemanticOps MCP tools, not a runtime MCP tool.
Core/Licensing/ProFeatures.cs as the source-of-truth checklist for Pro and Enterprise coverage.manage_policy packs or custom policy rules.manage_tests packs or starter validation tests.Use existing SemanticOps MCP surfaces only:
manage_license for license status, activation, refresh, and tier explanation.manage_model_connection for connection discovery, selection, and current state.list_model for metadata grounding after a model is connected.manage_preferences for approved runtime preference changes.manage_policy for approved policy pack previews or applications.manage_tests for approved test pack previews or applications.manage_model_changes for approved checkpoints, change history, undo/redo, and rollback planning.manage_dependencies for approved impact checks before risky changes.run_query for approved validation queries and Pro query diagnostics.manage_audit only when Enterprise is active and the user asks for audit posture or evidence.Always preview pack application first when the tool supports it:
manage_policy with operation: "packs_apply", spec.pack_id, and dry_run: true.manage_tests with operation: "packs_apply", spec.pack_id, and dry_run: true.Full guided setup is allowed only after the user approves the exact batch. Approved setup can include:
manage_license.manage_model_connection.manage_preferences.manage_policy.manage_tests.manage_model_changes.manage_dependencies.run_query.onboarding_completed preference.require_confirm policy rules as user-experience guardrails, not a portable compliance control across every MCP client.Return a compact onboarding packet:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.