create-apm-package — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited create-apm-package (Agent Skill) and scored it 87/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 3 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 3 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill scaffolds a new APM-native package using the "Source in .apm/" pattern. It is used for greenfield projects where APM is the primary distribution format from day one.
.apm/ directory.docs/governance.md.scripts/scaffold_apm.py.convert-plugin-to-apm.--allow-hybrid flag in scaffold script.<package-name>/
apm.yml
README.md
.gitignore
.apm/
skills/
agents/
instructions/
prompts/
hooks/
mcp/
scripts/
tests/
docs/
governance.md
attribution.md
package-lifecycle.md
scripts/
tests/After scaffolding, always run:
python scripts/validate_apm_package.py --path ./<package-name>.apm/skills while also having skills/ in the same package.docs/ folder in a team or enterprise lane.apm.yml.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.