Freeze the source
A report records the reviewed revision, files, scripts and declared permissions.
amaniagent · open agent tooling
A skill is executable trust — you install someone’s instructions and their scripts into an agent that can touch your files, your keys, your machine. A supply chain needs a gate — and good skills to run behind it. Here are both.
read-only by design · targets are never executed
The trust model
“Audited” is not a magic badge. Every result should point back to inspectable source, named checks and a report a human can challenge. The auditors read target repositories; they do not run them.
A report records the reviewed revision, files, scripts and declared permissions.
The auditors read the target — instructions, scripts and declared permissions. They never execute it.
The score summarizes a report; it never replaces findings, limitations or human judgment.
Score 0–8
Score any skill, repo, or agent answer 0–8 with file:line evidence, before you trust it.
The catalog
Search locally by category or skill name. Every entry remains visible without JavaScript; filtering is a progressive enhancement.
10 categories · 46 skills
Filter by area
answer-verifier · dependency-auditor · mcp-auditor · prompt-injection-detector · repo-auditor · settings-auditor · skill-auditor
context-optimization · context-thrift · lean-replies · output-sandbox
composable-wiki-rag
layered-agent-memory
app-integration · app-planning-per-platform · apple-fitness · healthkit · metal-shaders · widgets · xcode-mcp
embedded-swift · react-native-to-swift · repo-to-swift-native · swift-on-android · swift-vapor
grill-me · superpowers-tdd · superpowers-writing-plans
cli-anything-browser · cli-anything-chromadb · cli-anything-exa · cli-anything-mermaid · cli-anything-obsidian · cli-anything-ollama · cli-anything-zotero · github-org-automation · use-cli-anything · use-crawl4ai · use-gortex · use-hermes · use-n8n · use-ntfy · use-tailscale
seo-white-hat · web3-wallet-integration
led-grow-controller
Learn the gate
The useful question is not simply whether a repository looks suspicious. Ask what authority it requests, what code can cross the boundary and which claims you can verify yourself.