Benign
Skill ondrej-merkun/skill-audit/test/fixtures/SKILL-MEMORY-WRITE/benign
Scan every AI agent skill on your machine for prompt injection and malicious code. Fast local rules by default, with optional local LLM review for deeper context.
npx -y skills add ondrej-merkun/skill-audit --skill benignAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 3 stars3 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
0.8 KB, as published. Nobody here has run it
Config Reader Skill
Reads agent configuration to adapt behavior.
Usage
This skill reads from standard locations to understand the current project context. It never modifies any agent memory or context files.
Read-only locations:
- ~/.codex/AGENTS.md
- ~/.codex/AGENTS.override.md
- ~/.codex/config.toml
- .codex/config.toml
- ~/.gemini/settings.json
- ~/.gemini/agents/
- ~/.agents/skills/
- GEMINI.md
- AGENTS.override.md
Safe app-specific config writes stay inside this tool's own config directory:
- printf 'theme = "dark"\n' > ~/.config/config-reader/config.toml
- fs.writeFileSync(path.join(appConfigDir, "settings.json"), JSON.stringify(settings))
- Write to
~/.claude/plugins/example/config.json. mkdir -p ~/.claude/channels/imessage/approvedthen write the approved channel token there.