asking-questions — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited asking-questions (Agent Skill) and scored it 92/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 2 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 2 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Ask clarifying questions when the answer materially changes what you'll build. This skill helps identify when to ask, how to structure questions effectively, and when to proceed autonomously.
Ask questions for:
Don't ask when:
[Context: What you found/analyzed]
[Present 2-5 specific options with brief trade-offs]
[Direct question asking for preference]
[Optional: Offer to make reasonable default choice] I can implement this in several ways:
1. **Global middleware** - Catches all errors centrally (simplest)
2. **Wrapper functions** - More granular control per endpoint
3. **Custom error classes** - Typed errors with status codesLayer questions instead of asking everything upfront:
Good ✓
Bad ✗
"I see you're using JWT authentication. To add refresh tokens, I can:
What works best for your use case?"
"How should I implement the authentication refresh token storage mechanism considering security implications, XSS vulnerabilities, mobile compatibility, UX impacts, and compliance considerations?"
Too verbose, no clear options, asks everything at once
"You mentioned 'clean up migrations.' Do you want me to archive them to /old-migrations or delete them entirely? (Note: deletion can break databases that haven't run them yet)"
"What do you mean by clean up?"
Too vague, doesn't guide the decision
Ask only when the answer materially changes what you'll build. Avoid building the wrong thing, not asking questions for the sake of asking.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.