update-skills — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited update-skills (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Each skill is a self-installing additive unit: its folder under .claude/skills/<name>/ carries its own apply steps (SKILL.md), and channel/provider skills fetch their code files from a long-lived upstream branch (channels, providers) with git fetch origin <branch> + git show origin/<branch>:path > path. Every apply is idempotent and safe to re-run.
Updating a skill means re-running its own apply. The apply re-fetches the latest files from upstream and overwrites the copied-in code, so newer versions land additively.
Run /update-skills in Claude Code.
Preflight: checks for a clean working tree and the upstream remote.
Detection: reads the channel and provider barrels to list which skills have copied code into your tree, and lists the operational/utility skills present under .claude/skills/.
Selection: presents the installed skills and lets you pick which to re-apply.
Re-apply: invokes each selected skill's own apply (e.g. /add-slack), which fetches its latest files. Then validates with build + test.
Help users pull the latest skill code from upstream by re-applying their installed skills, without losing local customizations and without merging any branch.
git and barrel reads; let each skill's apply do its own fetching.Run:
git status --porcelainIf output is non-empty:
Check remotes:
git remote -vIf origin does not point at a NanoClaw upstream (or you want to verify it has the skill branches), confirm with the user before continuing. The default upstream is https://github.com/nanocoai/nanoclaw.git.
Fetch the branches that carry skill code:
git fetch origin channels providers --pruneChannels — read src/channels/index.ts and collect each import './<name>.js'; line, excluding cli. Each <name> maps to the /add-<name> skill.
Providers — read src/providers/index.ts the same way; each imported provider maps to its /add-<name> skill.
Operational and utility skills — list the folders under .claude/skills/. These copy no code into the tree, so "re-applying" them just re-reads their instructions; only include them if the user specifically wants to re-run a workflow.
Build the candidate list from the channels and providers actually wired into the barrels — those are the skills whose copied code can be refreshed from upstream.
If no channel or provider skills are installed:
If installed channel/provider skills are found:
slack, discord, opencode).multiSelect: true to let the user pick which skills to re-apply.For each selected skill (process one at a time):
/add-<name> skill using the Skill tool.git fetch origin <branch> + git show origin/<branch>:path > path), overwrites the copied-in code, and installs any pinned dependency..env credentials and DB wiring are untouched.After all selected skills are re-applied:
pnpm run buildpnpm test (do not fail the flow if tests are not configured)Each channel/provider skill copies in its own registration test; those run as part of pnpm test and assert the barrel still registers the adapter against the freshly fetched code.
If build fails:
Show:
git rev-parse --short HEADIf the service is running, remind the user to restart it to pick up the refreshed code.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.