cp-skill-ingest — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cp-skill-ingest (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Ingest one source into a kb/sources/*.ingest.md report. The source may be a URL or an existing Markdown snapshot under kb/sources/.
Target: $ARGUMENTS
The direct output is the .ingest.md report next to the source snapshot. URL snapshotting and connection discovery may write their own delegated artifacts. Do not directly write any other library artifacts.
Interpret "our" through the installed KB's goals and local collection contracts. In this repository, "our" means agent-operated KB methodology. In another installed KB, it means that project's declared system, work, codebase, policy, product, or domain.
Read and follow kb/sources/types/ingest-report.md before drafting the report. If this skill and the type spec conflict about report content, the type spec wins.
$ARGUMENTS is empty, list recent kb/sources/*.md files excluding.json and .ingest.md, then ask which one to ingest.
http:// or https://, invokecp-skill-snapshot-web on the URL. Parse the Snapshot saved: line from its output; that path is the source snapshot for the next step.
Invoke cp-skill-connect on the source snapshot path. Wait for it to finish. For source snapshots, read kb/reports/connect/sources/<snapshot-name>.connect.md.
From the generated connect report, note:
Treat Maintenance Observations as non-actionable context: mention durable signals in the ingest report only when relevant, and do not act on or promote them during ingest.
The connect report is generated, gitignored working context. Do not cite it, link to it, or name its path in the durable ingest report. Summarize its findings and link only durable KB artifacts or source snapshots.
Write the analysis as an ingest-report, using the source snapshot and the connection context. The report must classify the source, summarize it, explain how it connects to the current KB, extract goal-relative value, state limitations, and recommend one advisory next action.
If the source is not relevant to this KB, say so in the report. Keep the report short, explain the mismatch, and recommend no promotion or source-only filing as appropriate.
kb/sources/some-article.mdkb/sources/some-article.ingest.mdRun:
commonplace-validate kb/sources/some-article.ingest.mdIf this run created or edited the source snapshot, validate that snapshot too. Fix validation failures in files this skill is allowed to write before stopping.
Tell the user where the ingest report was saved and state the recommended next action.
cp-skill-connect before classification or value extraction..ingest.md report directly.context.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.