data-pipelines — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited data-pipelines (Agent Skill) and scored it 92/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 2 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 2 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A data pipeline moves/transforms data between systems. The failure modes are about correctness and recovery, not just throughput.
the same result (upsert by key, not blind insert) and can resume from a checkpoint rather than restarting from zero.
what to do with bad records — reject, quarantine, or repair — never silently drop.
or per-record key) so incremental runs don't double-count or miss late data.
dataset into RAM. Stream where you can.
silently processes 0 rows is a common, costly bug. Alert on anomalies.
gracefully (defaults, versioning) rather than crashing the whole run.
and keep raw inputs so you can reprocess after a transform bug.
Red flag: a non-resumable pipeline that must restart from scratch on any failure, or one with no record counts so you can't tell correct from silently-empty.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.