setup — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited setup (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Principle: "You are responsible." This skill discovers and proposes. The manager validates and decides what's accurate.
Interactive onboarding that builds the foundation every other skill relies on. Crawls connected sources, extracts context, and validates with the manager before saving.
If any MCP connector is unavailable, follow the connector unavailability protocol in references/operating-principles.md.
Ensure these MCP connectors are available:
If any connector is missing, note it and proceed with what's available. Flag gaps at the end.
Run phases sequentially. Each phase discovers, validates with the manager, then persists. Read references/discovery-phases.md for detailed instructions per phase.
Identify the manager (name, role, teams), crawl sources for direct reports, validate the team list, discover internal terminology, find development goals and performance data, map ways of working, and identify customer/project context if applicable.
Persist: manager-context/manager-profile.md, manager-context/team/[name].md per report, manager-context/terminology.md, manager-context/sources.md
Discover how the org evaluates performance and managers. Search for existing framework docs, then walk the manager through defining their dimensions, rating scale, promotion readiness labels, review cadence, goal cadence, and management competencies. See references/performance-framework.md and references/management-framework.md for how skills use these frameworks.
Persist: manager-context/performance-framework.md, manager-context/management-framework.md
Ask if the org has defined values. If yes, search for documentation, extract value names and behaviours, ask what signals to look for per value. If no, skip the values lens.
Persist: manager-context/values.md
Present defaults (language, tone, file format, folder structure) and let the manager adjust.
Persist: manager-context/output-preferences.md
Capture upward context: OKRs, who they report to, key deadlines.
Persist: manager-context/manager-goals.md
Capture VIP people, hot channels, deprioritise list, privacy boundaries.
Persist: manager-context/triage-rules.md
Capture review cycle dates, calibration sessions, promotion windows, goal cadence.
Persist: manager-context/review-calendar.md
Capture 1:1 style and suggest a skill rhythm (daily triage, weekly health check, etc.).
Persist: manager-context/skill-preferences.md
Flag any discovered data older than ~2 months. Ask the manager to confirm or update.
Save all validated context. Read references/context-templates.md for file templates. Present a summary of what was captured, flag gaps, and suggest first skills to try.
When called with --refresh:
manager-context/ filesRead references/operating-principles.md for shared principles (data scope, DM flagging, connector unavailability).
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.