setup — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited setup (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Configure credentials, dependencies, and workspace for Look Tongji Notes.
/setup or asks to configure the skill.python "<SKILL_DIR>/../../scripts/look_tongji.py" setuppython "<SKILL_DIR>/../../scripts/look_tongji.py" setup \
--workspace-root "<COURSE_WIKI_ROOT>" \
--owner-name "<OWNER_NAME>" \
--site-name "<OWNER_NAME>的课程知识库"vision-support/config.json does not exist, the CLI prints the init command. The embedded vision-support is at <SKILL_DIR>/../../vision-support/. Help the user configure a vision provider (OpenAI, Google, Anthropic, deepseek, dashscope, zhipuai, ollama, or custom). node "<SKILL_DIR>/../../vision-support/scripts/vision.mjs" "<SKILL_DIR>/../../komari.jpg"The agent should correctly identify image content (should mention "red-haired girl" or equivalent).
<SKILL_DIR> Points<SKILL_DIR> is the directory containing this SKILL.md. Shared scripts (look_tongji.py, timeline_tools.py, tongji_backend/) and references live two levels up in the repository root (<SKILL_DIR>/../../scripts/ and <SKILL_DIR>/../../references/).
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.