keystone-source-installer — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited keystone-source-installer (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Adds a new external source binding so the harness can pull rules, reasoning, skills, or commands from a third-party system (markdown folder, github, confluence, notion, jira, linear, slack, repo).
The user wants to wire up a new source — a shared standards repo, the team's Notion handbook, a Jira project, a Slack channel — that the harness should pull context from at session time.
markdown, folder, repo, github, confluence, notion, jira, linear, slack, harness. If the user names something else, surface the supported list and stop.
markdown / folder — local path (absolute or relative to theproject root).
repo — owner/repo and a version (tag, sha, or branch).github / confluence / notion / jira / linear / slack —base URL, auth token reference (env:VAR, never a literal).
to which payload kind? Defaults exist for most types; surface them and let the user override.
guides, actions,playbooks, sensors, skills, corpus):
canonical: [...] — items the source owns exclusively. Noproject file may override.
required: [...] — items the source references but does notship. A project file (or a deeper source) must supply the body.
that will land in .keystone/context.yaml. Pause for explicit acceptance.
.keystone/context.yaml (or create it ifmissing). NEVER write a secret directly — every credential goes through env:VAR.
keystone://harness/verify to confirm thecascade looks correct. Surface any new canonical conflicts or required gaps for the user to resolve.
An updated .keystone/context.yaml with the new source declared, plus a verify report.
env:VAR references.becomes unreachable, what becomes a violation) before writing.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.