update-dependencies

REVIEW · 59
Registry indexed

Weekly dependency update workflow for Sesori Apps Monorepo. Updates every pubspec.yaml across the bridge and client workspaces plus standalone packages, regenerates all lockfiles, re-resolves iOS/macOS SwiftPM native dependencies (Package.resolved), updates Fastlane/Gemfile versi

Verified installs0
Stars105
Version1.0.0
Quality66/100 · Promising
Trust59/100 · Do not auto-install
Audit75/100 · Needs review

Supply asset profile

Research and knowledge work

Deep research, source comparison, literature review, RAG, knowledge search, and reports.

Browse track

Scenario

Research agents

I need my agent to research a topic, compare sources, and produce a concise report.

Agent fit

Claude Code + OpenAI Agents + Cursor

Codex, Claude Code, Cursor, CLI, or custom agents.

Install

Ready

npx skills add sesori-ai/sesori_apps_monorepo --skill update-dependencies

Maintenance

fresh

Pushed today

Risk

Needs review

Dependency or permission surface needs review

GitHub quality

105

66/100 Quality · 67/100 Trust

Coverage tags

ResearchResearch agentsagent-skill

Review notes

Dependency or permission surface needs review · Permission surface may require sandboxing

Agent adoption scorecard

Trust, audit, and install readiness at a glance

These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.

Quality

Promising
66

Useful candidate, but compare it with alternatives before adopting.

Trust

Do not auto-install
59

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

Audit

Needs review
75

A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.

OpenAgentSkill Trust Score v5

Human review before install

Choose a stronger alternative or inspect the source manually before any install attempt.

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

105 GitHub stars

Repo activity

105 stars, 6 forks

Maintenance

Pushed today

License

NOASSERTION

Install

npx skills add sesori-ai/sesori_apps_monorepo --skill update-dependencies

Install safety

standard package or runtime install path

Permission surface

secrets or environment access, shell or command execution

Agent outcomes

No agent outcome data yet

Docs

Strong README/SKILL.md context

Risk summary

Review before production

  • Repository license is NOASSERTION, which may limit reuse and clarity for downstream users.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Stars/forks activity: 105 stars, 6 forks; issue activity unavailable in current metadata

Install readiness

Install path available

  • Install path is available
  • Repository evidence is available
  • License is declared
  • No Agent Proven outcome evidence yet

Agent-readable metadata

Machine-readable decision data for this skill.

Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.

Open JSON

Suited tasks

  • Research agents workflows
  • Claude Code teams
  • builders willing to evaluate younger projects
  • Search sources

Suited agents

CodexClaude CodeCursorOpenAgentSkill CLIOpenAI AgentsCLI

Install decision

Command
npx skills add sesori-ai/sesori_apps_monorepo --skill update-dependencies
Policy
block
Human review
yes

Trust and risk

Trust
59/100
Audit
75/100
Risk level
Needs review

Outcome loop

Endpoint
/api/agent/outcome
Event ID
resolve
Outcomes
5

Install command

npx skills add sesori-ai/sesori_apps_monorepo --skill update-dependencies

Do not use when

  • teams that need a vendor-supported SLA
  • production agents without a repository review
  • Repository license is NOASSERTION, which may limit reuse and clarity for downstream users.
  • No OpenAgentSkill engagement data yet
  • High-risk permission hints: Shell or command execution, Secrets or environment access

Agent safety v2

31/100 · Avoid automatic install

Blocked for auto-installblock

This skill should not be selected by an agent without explicit human security review.

Do not auto-install. Inspect the source, dependencies, and permission surface first.

Resolve via API

high

Shell or command execution

Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.

medium

Browser automation

Skill may drive a browser or interact with web pages.

medium

Network access

Skill likely fetches remote pages, APIs, repositories, or external services.

medium

Filesystem access

Skill may read or write project files, documents, generated artifacts, or local workspace state.

  • High-risk permission hints: Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

Install targets

Install this skill in your agent workflow

Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install sesori-ai-update-dependencies

Agent resolve plan

Let an agent verify fit before installing.

The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.

Open text plan

Agent should check

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Copy prompt

Task: Use update-dependencies in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20update-dependencies%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/sesori-ai-update-dependencies/install
Install command: npx skills add sesori-ai/sesori_apps_monorepo --skill update-dependencies
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent handoff

Give an agent the install path, not another directory page.

Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.

Open install API

Agent prompt

Use update-dependencies for this task. Review https://www.openagentskill.com/api/skills/sesori-ai-update-dependencies/install, then install with: npx skills add sesori-ai/sesori_apps_monorepo --skill update-dependencies

Registry metadata

Agent-readable profile for automatic skill selection.

This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.

Open manifest

Agent fit

65/100

Research agents

Platforms

Claude Code, OpenAI Agents, Cursor

Audit report

Needs review · 75/100

A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.

View audit reportView eval report

Agent decision cockpit

Fallback candidate for Research agents

Prototype with this skill first; keep a fallback candidate ready.

65
Readiness
Prototype
Stage

Role in stack

Fallback candidate

Primary fit

Research agents

Trust label

Prototype first

Install path

Command ready

Use when

  • Research agents workflows
  • Claude Code teams
  • builders willing to evaluate younger projects

Evidence

  • recent repository activity
  • install command or GitHub repo available
  • 66/100 quality profile

review first

  • Repository license is NOASSERTION, which may limit reuse and clarity for downstream users.
  • No OpenAgentSkill engagement data yet

Implementation path

  1. 1Install it in a sandbox agent and run one Research agents task end to end.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Trust profile

Do not auto-install

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

59
OpenAgentSkill Trust Score

GitHub adoption

INFO

105 GitHub stars

Stars/forks activity

CHECK

105 stars, 6 forks; issue activity unavailable in current metadata

Recent maintenance

PASS

Pushed today

License clarity

PASS

NOASSERTION

Good signals

  • AI review approved
  • Install path is available
  • Repository evidence is available
  • Recently maintained repository
  • Install command has no obvious high-risk pattern
  • Outcome loop is ready but needs first real agent run

Review before install

  • Repository license is NOASSERTION, which may limit reuse and clarity for downstream users.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Stars/forks activity: 105 stars, 6 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution
  • No real agent outcome reports yet
  • Human review required before unattended installation

Recommended action

Choose a stronger alternative or inspect the source manually before any install attempt.

Quality profile

Promising candidate for agent workflows

Useful candidate, but compare it with alternatives before adopting.

66
GitHub stars
105
Freshness
Today
Install ready
Yes
License
NOASSERTION
Review before install: Repository license is NOASSERTION, which may limit reuse and clarity for downstream users.

Workflow fit

Use this skill in these scenarios

Workflow fit

Add it to a complete workflow

Alternative shortlist

Compare before you install

Similar skills that may fit this task.

Compare all

Overview

--- name: update-dependencies description: Weekly dependency update workflow for Sesori Apps Monorepo. Updates every pubspec.yaml across the bridge and client workspaces plus standalone packages, regenerates all lockfiles, re-resolves iOS/macOS SwiftPM native dependencies (Package.resolved), updates Fastlane/Gemfile versions, handles conflicts, and verifies via analyze/test/codegen. ---

<objective> Systematically update all project dependencies across both Dart workspaces and standalone packages while maintaining stability, tracking conflicts, and ensuring proper commit hygiene. </objective>

<project_structure> <workspaces> The repo has two Dart workspaces and two standalone packages. Workspace members share a single resolution; standalone packages resolve independently.

**Client workspace** (`client/pubspec.yaml` is the workspace root, has `flutter` env constraint):

- `client/pubspec.yaml` — workspace root, env only - `client/module_auth/pubspec.yaml` - `client/module_core/pubspec.yaml` - `client/module_prego/pubspec.yaml` (Flutter package — theme/assets) - `client/module_desktop_core/pubspec.yaml` (pure Dart desktop business logic) - `client/design_catalog/pubspec.yaml` (Flutter design-system catalog) - `client/app/pubspec.yaml` (Flutter app — Firebase, flutter_bloc, etc.) - `client/desktop/pubspec.yaml` (Flutter desktop app)

**Bridge workspace** (`bridge/pubspec.yaml` is the workspace root, pure Dart):

- `bridge/pubspec.yaml` — workspace root, env only - `bridge/sesori_plugin_interface/pubspec.yaml` - `bridge/sesori_bridge_foundation/pubspec.yaml` (depends on `sesori_plugin_interface`; bridge-wide shared primitives) - `bridge/sesori_plugin_runtime/pubspec.yaml` (depends on `sesori_plugin_interface`) - `bridge/sesori_plugin_opencode/pubspec.yaml` - `bridge/sesori_plugin_codex/pubspec.yaml` - `bridge/sesori_plugin_acp/pubspec.yaml` - `bridge/sesori_plugin_cursor/pubspec.yaml` - `bridge/sesori_plugin_omp/pubspec.yaml` - `bridge/sesori_plugin_claude/pubspec.yaml` - `bridge/sesori_plugin_pi/pubspec.yaml` - `bridge/sesori_plugin_hermes/pubspec.yaml` - `bridge/app/pubspec.yaml` (CLI relay server)

**Standalone packages** (NOT in any workspace — resolve independently with their own lockfile):

- `shared/sesori_shared/pubspec.yaml` — pure Dart; consumed by both workspaces via `path:` dep - `shared/no_slop_linter/pubspec.yaml` — pure Dart analyzer plugin; consumed by `module_prego` via `path:` dev_dep

**IMPORTANT**: Update `shared/sesori_shared` FIRST because both workspaces depend on it.

**DO NOT update `shared/no_slop_linter`** as part of this workflow. Its analyzer/`_fe_analyzer_shared` constraints span multiple majors intentionally and break easily — bumps are done manually, less often, by a human. Skip its pubspec edits in Phase 3, but still run `make analyze`/`make test` against it via the shared `Makefile` for verification. </workspaces>

<ios_files> Sesori iOS is **Swift Package Manager only** — there is no Podfile, and CocoaPods is not part of the iOS dependency graph. Do not run `pod install` or attempt to add Podfile handling here.

- `client/app/ios/Gemfile` (fastlane gem only) - `client/app/ios/Gemfile.lock` </ios_files>

<android_files>

- `client/app/android/Gemfile` (fastlane gem) - `client/app/android/Gemfile.lock` </android_files>

<swiftpm_files> iOS and macOS pull native dependencies (Firebase, Google SDKs, leveldb, gRPC, etc.) via Swift Package Manager. The resolved native versions are pinned in `Package.resolved` lockfiles. **All four tracked copies matter** — the project copy and the workspace copy, per platform:

- `client/app/ios/Runner.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved` - `client/app/macos/Runner.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved` - `client/app/ios/Runner.xcworkspace/xcshareddata/swiftpm/Package.resolved` - `client/app/macos/Runner.xcworkspace/xcshareddata/swiftpm/Package.resolved`

`flutter build --config-only` regenerates only the **project** copies. The `Runner.xcworkspace` copies are what Xcode actually consumes when a build targets the workspace — which is exactly what the iOS release lanes do (`build_app(workspace: "Runner.xcworkspace", ...)` in `client/app/ios/fastlane/Fastfile`). Leaving them stale means the shipped TestFlight/App Store build silently links the OLD native SDKs even though the PR claims to have updated them. Verified 2026-07-21: with the workspace copy stale, `xcodebuild -resolvePackageDependencies -workspace Runner.xcworkspace -scheme Runner` resolved AppCheck 11.3.0 / GoogleUtilities 8.1.1 while the project copy already said 11.3.1 / 8.1.2.

Both copies describe the same package graph, so after Phase 5.1 they must end up with identical `pins`.

These lockfiles change on most weekly runs because native SDK patch releases land continuously, **independent of pubspec.yaml**. They MUST be re-resolved every run (Phase 5). Use `flutter build --config-only` for the project copies; a bare `xcodebuild -resolvePackageDependencies` honors whatever pins already exist and silently no-ops, so it only re-resolves the workspace copies once their lockfile has been deleted. Skipping (or using the wrong resolve command) is a silent, recurring miss — e.g. one past run bumped firebase-ios-sdk but left GoogleUtilities/nanopb/promises stale; another run's bare `xcodebuild` resolve reported "no changes" while a `flutter build --config-only` picked up GTMSessionFetcher 4.5.0→5.3.0, GoogleUtilities 8.1.0→8.1.1, nanopb, and Promises. </swiftpm_files> </project_structure>

<process> <phase name="0. Preflight Discovery"> <description>Enumerate the ACTUAL dependency surface and reconcile it against the documented lists in `<project_structure>`. The hardcoded lists below WILL go stale as packages are added — a package missing from the tables is the single most common failure of this workflow (e.g. `bridge/sesori_plugin_runtime` was missed for weeks). Treat what you discover here as authoritative; the tables are only the expected reference.</description>

<step name="0.1">List every source pubspec (excludes build artifacts, codegen output, and worktrees):

```bash find . -name pubspec.yaml -not -path '*/build/*' -not -path '*/.dart_tool/*' -not -path './.worktrees/*' | sort ```

Cross-check the output against the package inventory in `<project_structure>`. If a pubspec appears that is NOT listed there (a newly added workspace member), treat it as in-scope for THIS run — add it to every per-file step below (env constraints in 1.2, outdated check in 2.1, constraint bumps in 3.1) — AND update the inventory + env table in this skill so future runs inherit it. The ONLY pubspec excluded from edits is `shared/no_slop_linter/pubspec.yaml`. </step>

<step name="0.2">List the authoritative workspace members straight from the workspace roots — every member here MUST be processed in Phases 1–3:

```bash sed -n '/^workspace:/,$p' bridge/pubspec.yaml sed -n '/^workspace:/,$p' client/pubspec.yaml ``` </step>

<step name="0.3">List the iOS/macOS SwiftPM lockfiles that Phase 5 will refresh (expect exactly four — a project copy and a workspace copy per platform; these are native deps and are in scope):

```bash git ls-files | grep 'Package.resolved' ``` </step> </phase>

<phase name="1. Environment Setup"> <description>Ensure Flutter/Dart is at latest stable version, align environment constraints, and clean lock files</description>

<step name="1.1">Check current Flutter version and update if needed:

```bash flutter --version asdf install flutter latest asdf set flutter latest # asdf 0.16+ canonical form; equivalent to `asdf local` on older versions flutter --version ```

If `flutter --version` still reports the old version after `asdf set`, run `asdf reshim flutter` (or open a new shell) and re-run `flutter --version`. </step>

<step name="1.2">Check and update environment constraints in all pubspec.yaml files **except `shared/no_slop_linter/pubspec.yaml`** (manually managed).

Get the current Dart SDK version bundled with Flutter:

```bash flutter --version ```

Note the Dart version (e.g., "Dart 3.11.0") and Flutter version (e.g., "Flutter 3.41.0").

For each pubspec.yaml below, read its `environment` section and update only the keys present. **Preserve the existing constraint syntax per file** — do not normalize between caret and range forms.

**SKIP `shared/no_slop_linter/pubspec.yaml` entirely** — its env constraint (and all other deps) are managed manually by a human.

| File | Has `sdk` | Has `flutter` | Constraint style | |------|-----------|---------------|------------------| | `client/pubspec.yaml` | ✅ | ✅ | caret (`^3.13.0`) + range (`">=3.47.0 <3.48.0"`) | | `client/app/pubspec.yaml` | ✅ | — | caret | | `client/module_auth/pubspec.yaml` | ✅ | — | caret | | `client/module_core/pubspec.yaml` | ✅ | — | caret | | `client/module_prego/pubspec.yaml` | ✅ | ✅ | caret + range | | `client/module_desktop_core/pubspec.yaml` | ✅ | — | caret | | `client/design_catalog/pubspec.yaml` | ✅ | ✅ | caret + range | | `client/desktop/pubspec.yaml` | ✅ | — | caret | | `bridge/pubspec.yaml` | ✅ | — | caret | | `bridge/app/pubspec.yaml` | ✅ | — | caret | | `bridge/sesori_plugin_interface/pubspec.yaml` | ✅ | — | caret | | `bridge/sesori_bridge_foundation/pubspec.yaml` | ✅ | — | caret | | `bridge/sesori_plugin_runtime/pubspec.yaml` | ✅ | — | caret | | `bridge/sesori_plugin_opencode/pubspec.yaml` | ✅ | — | caret | | `bridge/sesori_plugin_codex/pubspec.yaml` | ✅ | — | caret | | `bridge/sesori_plugin_acp/pubspec.yaml` | ✅ | — | caret | | `bridge/sesori_plugin_cursor/pubspec.yaml` | ✅ | — | caret | | `bridge/sesori_plugin_omp/pubspec.yaml` | ✅ | — | caret | | `bridge/sesori_plugin_claude/pubspec.yaml` | ✅ | — | caret | | `bridge/sesori_plugin_pi/pubspec.yaml` | ✅ | — | caret | | `bridge/sesori_plugin_hermes/pubspec.yaml` | ✅ | — | caret | | `shared/sesori_shared/pubspec.yaml` | ✅ | — | caret |

Example:

```yaml environment: sdk: ^DART_VERSION flutter: ">=FLUTTER_VERSION <NEXT_MINOR" # client/pubspec.yaml only ```

</step>

<step name="1.3">Commit if environment constraints changed:

```bash git diff .tool-versions git diff --name-only -- '*.yaml' git add .tool-versions $(git diff --name-only -- '*.yaml') git commit -m "chore: update Flutter/Dart environment constraints

- Update environment constraints in all pubspec.yaml files - Update Flutter SDK version in .tool-versions (if changed)" ```

Skip this commit if no environment changes were needed. </step>

<step name="1.4">Delete all pubspec.lock files except `shared/no_slop_linter/pubspec.lock` (the linter is excluded from this workflow — its lock must remain untouched so transitive resolution doesn't shift):

```bash find . -name "pubspec.lock" \ -not -path "./.worktrees/*" \ -not -path "./shared/no_slop_linter/*" \ -delete ```

</step> </phase>

<phase name="2. Dependency Analysis"> <description>Check for available updates across all packages</description>

<step name="2.1">Run outdated check for each package. Workspaces resolve as a unit (run from workspace root); standalone packages resolve individually.

**Standalone (`shared/sesori_shared` only — `no_slop_linter` is excluded):**

```bash (cd shared/sesori_shared && dart pub outdated) ```

**Client workspace** (one resolution covers all members; run `outdated` per-member to see direct deps per package — `flutter pub outdated` for Flutter packages, `dart pub outdated` for pure-Dart members):

```bash set -e (cd client && flutter pub get) (cd client/module_auth && dart pub outdated) # pure Dart (cd client/module_core && dart pub outdated) # pure Dart (cd client/module_prego && flutter pub outdated) # Flutter (flutter: sdk: flutter) (cd client/module_desktop_core && dart pub outdated) # pure Dart (cd client/design_catalog && flutter pub outdated) # Flutter design catalog (cd client/app && flutter pub outdated) # Flutter app (cd client/desktop && flutter pub outdated)

Technical details

Version
1.0.0
License
NOASSERTION
Last updated
Aug 22, 2026
Published
Aug 22, 2026

Decision snapshot

Fallback candidate

65
Ready
Prototype
Stage

recent repository activity

Audit

Install review

Install and adoption review

75
Needs review
Security
73/100
Maintenance
100/100
Install
92/100
Open full auditView eval report

Agent-proven evidence

Agent-proven evidence

Outcome reports after resolve, review, install, and one narrow run.

0
Proven
Needs first agent runAuto-install: review firstLast: Unknown
Success rate
Recent failure
Outcomes
0
Output quality
Failed
0
Not relevant
0
Installs
0
Risk blocked
0
Setup needed
0
Production
0

No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.

Install

Add to agent workflow

Free and open source. Review the report before installing into production agents.

Growth loop

Share kit

X

Scenario-led draft for update-dependencies, ready for a manual X post.

Curator note
update-dependencies: Weekly dependency update workflow for Sesori Apps Monorepo. Updates every pubspec.yaml across...

105 stars

https://www.openagentskill.com/skills/sesori-ai-update-dependencies?ref=x
Open X draft
Optional reply with install command
Listing + install path for update-dependencies:
https://www.openagentskill.com/skills/sesori-ai-update-dependencies?ref=x

Install: npx skills add sesori-ai/sesori_apps_monorepo --skill update-dependencies

Listing source

Registry indexed

Claimable

This listing was indexed from public sources and is not marked official until a maintainer claim is approved.

Creator
sesori-ai
Indexed by
OpenAgentSkill community index

Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.

Claim this skill

Owner claim

Claim this skill listing

This Registry indexed listing is attributed to sesori-ai but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.

Creator backlink kit

Add the evidence badges to your README

Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/sesori-ai-update-dependencies?metric=listed&label=Listed)](https://www.openagentskill.com/skills/sesori-ai-update-dependencies)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/sesori-ai-update-dependencies?metric=trust&label=Trust)](https://www.openagentskill.com/skills/sesori-ai-update-dependencies)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/sesori-ai-update-dependencies?metric=audit&label=Audit)](https://www.openagentskill.com/skills/sesori-ai-update-dependencies/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/sesori-ai-update-dependencies?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/sesori-ai-update-dependencies)

Author

S

sesori-ai

@sesori-ai

Health signals

GitHub stars
105
Quality score
37/100
Last GitHub push
Aug 22, 2026
Framework hints
Unknown
OpenAgentSkill views
0
Install copies
0
Outbound clicks
0

Community signal

Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.

Trust & safety

Do not auto-install

59
  • GitHub adoption105 GitHub starsINFO
  • Stars/forks activity105 stars, 6 forks; issue activity unavailable in current metadataCHECK
  • Recent maintenancePushed todayPASS
  • License clarityNOASSERTIONPASS
  • README/SKILL.md completenessMetadata includes enough usage and workflow contextPASS
  • Dependency/runtime riskcommand execution surface, credential or environment accessCHECK