PheroPath is a stigmergy-based communication protocol that allows AI Agents to leave invisible "pheromones" (signals) on files to coordinate tasks, warn of risks, or share insights without modifying the file content itself.
SaferSkills independently audited PheroPath (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
PheroPath allows you to attach context (DANGER, TODO, SAFE, INSIGHT) to files using Extended Attributes (or a sidecar fallback).
Script: scripts/secrete.py
When to use:
Bash Examples (Few-Shot):
# Example 1: Mark a file as dangerous due to a race condition
python3 scripts/secrete.py "src/concurrency.py" "DANGER" "Rate limit race condition under high load" --intensity 1.0
# Example 2: Leave a TODO note for refactoring
python3 scripts/secrete.py "src/legacy_api.py" "TODO" "Needs migration to v2 API schema"
# Example 3: Mark a test file as verified
python3 scripts/secrete.py "tests/test_auth.py" "SAFE" "Passed all penetration tests"
# Example 4: Add architectural insight
python3 scripts/secrete.py "src/core/engine.py" "INSIGHT" "Core loop logic derived from paper X" --ttl 168Script: scripts/sniff.py
When to use:
DANGER.Bash Examples (Few-Shot):
# Example 1: Sniff a specific file
python3 scripts/sniff.py "src/main.py"
# Example 2: Sniff an entire directory (recursive) to gather context
python3 scripts/sniff.py "src/" --min-intensity 0.1
# Example 3: Parse output (it is JSON)
python3 scripts/sniff.py "src/" | jq '.[].message'Script: scripts/cleanse.py
When to use:
DANGER).TODO).Bash Examples (Few-Shot):
# Example 1: Remove signal from a specific file (e.g. after fixing it)
python3 scripts/cleanse.py "src/concurrency.py"
# Example 2: Prune weak signals (intensity < 0.2) from a directory
python3 scripts/cleanse.py "src/" --prune 0.2
# Example 3: Clear ALL signals from a directory (Reset)
python3 scripts/cleanse.py "src/" --all~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.