performance-cycle — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited performance-cycle (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Principle: "You are responsible." This skill gathers and organises evidence. Rating decisions and development assessments are the manager's alone.
Helps managers prepare evidence-based assessments for performance review cycles. The org's performance framework dimensions measure what was achieved and how the person developed. Organizational values measure how they showed up while doing it.
Load the org's performance framework from manager-context/performance-framework.md (created during /setup). This defines:
If manager-context/performance-framework.md doesn't exist, ask the manager to run /setup first.
If any MCP connector is unavailable, follow the connector unavailability protocol in references/operating-principles.md.
Determine who to prepare for:
Determine the review period:
For the target team member, read from manager-context/team/[name].md:
Also load:
manager-context/performance-framework.md: org-specific framework dimensions and rating descriptors (falls back to references/performance-framework.md defaults)manager-context/management-framework.md: org-specific management dimensions (falls back to references/management-framework.md defaults)references/values-guide.md: values definitions and signal guidancemanager-context/values.md: the organization's specific valuesFor each dimension and sub-dimension in the org's performance framework (from manager-context/performance-framework.md), gather evidence from connected sources.
For each sub-dimension:
Common evidence patterns by dimension type:
For dimensions that are hardest to assess digitally (e.g., behavioural growth, leadership presence), explicitly flag that the manager's direct observations carry more weight.
Values are the "how": how this person delivered their results and showed up for the team. Search for evidence across the organization's values (from manager-context/values.md). See references/values-guide.md for guidance on finding value signals.
For each value defined in manager-context/values.md, search for evidence using the signal guidance stored there. Common evidence sources by value type:
Collaboration / teamwork values:
Ambition / ownership values:
Innovation / resourcefulness values:
Transparency / communication values:
Care / wellbeing values:
For each value, compile evidence as observations (not judgments):
Search Slack for recognition this person received during the review period:
For each dimension, assess evidence strength:
Read references/output-template.md for the full output template structure (individual and batch mode).
If preparing for the whole team, produce individual evidence summaries for each team member plus a team-level comparison view. See the batch mode template in references/output-template.md.
Here's the evidence I gathered for [name]'s review. I've flagged gaps where you'll want to add your own observations.
Remember: this is evidence gathering only. Rating decisions and promotion assessments are yours to make based on the full picture, including things I can't see.Spawn a sub-agent to review the evidence summary with fresh eyes. The reviewer should:
Incorporate the reviewer's feedback before presenting the final summary to the manager.
Read references/operating-principles.md for shared operating principles (data scope, DM flagging, signals vs diagnoses, connector unavailability).
Additional notes specific to this skill:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.