Capability Audit

skillerr/capability-audit

Submitted by @sam_okoro · Sam Okoro

Jul 10, 2026 · minted Jul 14, 2026

sha256:f6a148a85ad1
FreeNot anchoredmintedinspectablecapabilitiesdigest-pinnednative

85/ 100 · Strong seal

WIP · 2.0-signals

Skill Score is actively being developed and will get sharper over time.

  • Sealed package20/20

    Minted .skill blob in the registry

  • Digest published15/15

    sha256 pin published on skillerr.com

  • Permissions declared15/15

    Capabilities / permissions declared

  • Source attested10/10

    Namespace, submitter, or source URL (not a vendor endorsement)

  • Transparency log0/15

    Not anchored

  • Release profile15/15

    evaluateReleaseProfile passed

  • Registry signal5/5

    1540 install(s) on registry

  • Not revoked5/5

    No revocation on log

Not a malware scan. Not “safe to run.” Transparent registry signals only. Inclusion is not endorsement.

npx @skillerr/add skillerr/capability-audit

Registry pin: sha256:f6a148a85ad1 (shown on TrustView; install by name resolves to this sealed blob)

Sealed install targets

Writes capability-audit.skill (sealed ZIP) plus optional skillerr.json. Not a bare SKILL.md.

Download capability-audit.skill

Sealed ZIP with digest + skillerr.json. Not a bare SKILL.md.

Free skills install with npx @skillerr/add. Sign in for account history.

Install and download deliver a digest-pinned open .skill package (docs.skillerr.com). Pasting a SKILL.md from the internet has none of this proof.

  • capability-audit.skill ZIP

    Open-protocol .skill ZIP (skill.json + workflow), not a public raw SKILL.md URL

  • Registry digest pin

    sha256:f6a148a85ad1…

  • Inspect before run

    TrustView on skillerr.com; SKILL.md is a lossy adapter inside the package

  • Permissions surface

    Capabilities declared for review before install

  • Transparency log

    Inclusion proof in the skillerr.com registry log

  • fsFilesystemelevated

    Read or write files in the workspace

Declarations for humans and agents. Not a runtime sandbox guarantee.

Confirm the digest on this page matches the live registry. This checks identity pins only: not a security scan.

expect sha256:f6a148a85ad1aba7
npx @skillerr/add info skillerr/capability-audit
curl -sS https://skillerr.com/api/v1/skills/skillerr/capability-audit | grep -o '"digest":"[^"]*"'

List declared capabilities across all installed skills in a project.

Scan installed sealed skills and produce a capability matrix: which packages declare fs, net, shell, and any undeclared or mismatched claims. Use before granting broader agent permissions or when reviewing an org skill set for least privilege.

TrustView preview on skillerr.com. Install and download serve the sealed package: there is no public raw SKILL.md URL.

---
name: capability-audit
title: Capability Audit
description: List declared capabilities across all installed skills in a project.
---

# Capability Audit

List declared capabilities across all installed skills in a project.

## Description

Scan installed sealed skills and produce a capability matrix: which packages declare fs, net, shell, and any undeclared or mismatched claims. Use before granting broader agent permissions or when reviewing an org skill set for least privilege.

## Capabilities

- fs
Public Ledger
Not anchored
published_at
2026-02-18T14:00:00.000Z
version
0.1.0
updated_at
2026-05-30T12:00:00.000Z
license
MIT
minted_at
2026-07-14T16:10:10.000Z
permanence
in registry log
digest
sha256:f6a148a85ad1aba73289fbdd1dda3d1eeeed272a86b69697a9553165547c2b6c

Public permanence uses Sigstore Rekor. The ledger link is shown when a real logIndex was recorded at mint. Green Anchored requires an offline inclusion proof verify. Catalog claims alone never paint Anchored. Inclusion is not endorsement.