SKILLEMALL.ai

DF deploy

Deploy and infrastructure: web deploy, dev branches, cron, package install, shell configuration.

notque/vexjoy-agent Agent Skills author: notque MIT 25 files body ≈ 2 245 tokens Open the sourcegithub.com↗ analyzed 7 d ago

Deploy and infrastructure: web deploy, dev branches, cron, package install, shell configuration.

As a process F 32/100 · Will not run — References files that are not bundled: scripts/*.sh

ProcedureInfrastructuretype and topics are labelled automatically from the skill text
JSON
Technical rating
D
69/100
safety, quality, tests
Safety 60%
74
Quality 40%
62
Run on models
none yet
Process rating
F
32/100
Will not run
References files that are not bundled: scripts/*.sh
Tools and files w 18
0
Result and completion w 14
0
Inputs and preconditions w 11
0
the three weakest of ten parameters · all ten

What is at stake

Medium-severity findings: the skill is probably honest, but read what alarmed the scanner.

Broad scope medium severity

Below is the worst case for this category. The finding here is medium: the guard saw a sign, not a proof.

If you install

The skill asks for more than the task needs: broad tool access, credential environment variables, binaries. Every extra permission widens the damage from a mistake or a compromise.

For the author

Narrow allowed-tools and the variable list to the minimum; replace binaries with readable sources or scripts.

How to improve

  1. Say in the description WHEN to use the skill ("use when…", example requests): that is the agent's main cue.
  2. The text references files that are not there: add them or drop the references.
For the model run — optional
  • Your own cases (evals/evals.json, 4–6 real requests with expected answers): the full check would then run those instead of a model-drafted suite.
  • A spec.yaml with trigger phrases and assertions — a behaviour contract for CI; `skilltest init` writes a template.

Guard findings · 22

✓ No critical or high findings

Medium and low: 22
  • medium Broad scope meta-broad-allowed-tools SKILL.md:1
    Broad tool permissions pre-approved: Bash
    allowed-tools: Read Write Bash Grep Glob Edit Agent
  • low Dangerous commands cmd-cron-mention references/headless-cron-creator.md:145
    Mentions editing / listing crontab (quoted — discussed, not commanded)
    Solution: Check `crontab -l` manually. Restore from `~/.claude/crontab-backups/`.
    quoted
  • low Dangerous commands cmd-background-process references/pid-resolution.md:20
    Starts a background / autostarted process (quoted — discussed, not commanded)
    - You used `nohup`, `setsid`, or any other wrapper binary
    quoted
  • low Dangerous commands cmd-background-process references/pid-resolution.md:30
    Starts a background / autostarted process
    nohup my_server --port 8080 > log 2>&1 &
  • low Dangerous commands cmd-background-process references/pid-resolution.md:82
    Starts a background / autostarted process
    nohup my_server > log 2>&1 &
  • low Dangerous commands cmd-background-process references/pid-resolution.md:109
    Starts a background / autostarted process
    nohup my_server > log 2>&1 &
  • low Dangerous commands cmd-background-process references/preferred-patterns.md:26
    Starts a background / autostarted process
    nohup python3 -m http.server 8080 --bind 127.0.0.1 > log 2>&1 &
  • low Dangerous commands cmd-background-process references/preferred-patterns.md:47
    Starts a background / autostarted process (quoted — discussed, not commanded)
    Any hit requires manual inspection: if the backgrounded command is a shell builtin or simple exec it may be safe; if it is anything that daemonizes, forks, or goes through `nohup`/`setsid`, the captur
    quoted
  • low Dangerous commands cmd-background-process references/preferred-patterns.md:55
    Starts a background / autostarted process
    nohup python3 -m http.server 8080 > log 2>&1 &
  • low Dangerous commands cmd-background-process references/public-web-deploy.md:155
    Starts a background / autostarted process
    systemctl enable --now fail2ban && fail…ent status
  • low Dangerous commands cmd-background-process references/shell-process-patterns.md:7
    Starts a background / autostarted process
    | Background start | Ad-hoc long-running child in a script or session | Redirect fd 0/1/2, capture real PID, disown if parent exits |
  • low Dangerous commands cmd-background-process references/shell-process-patterns.md:8
    Starts a background / autostarted process (documentation table row)
    | Daemonization | Process must survive terminal close, become session leader | `setsid` + fd redirect + write PID file atomically |
    table
  • low Dangerous commands cmd-background-process references/shell-process-patterns.md:17
    Starts a background / autostarted process (quoted — discussed, not commanded)
    - Starting background processes (`&`, `nohup`, `disown`, `setsid`, daemonization).
    quoted
  • low Dangerous commands cmd-background-process references/shell-process-patterns.md:36
    Starts a background / autostarted process (documentation table row)
    | starting a background process, `&`, `nohup`, `disown`, `setsid`, daemonize | `starting-processes.md` | Launch-time patterns and fd/session rules |
    table
  • low Dangerous commands cmd-background-process references/shell-process-patterns.md:78
    Starts a background / autostarted process (quoted — discussed, not commanded)
    3. **Decide if `disown` is needed.** `disown $!` removes the job from the shell's job table so the shell does not send SIGHUP when it exits. Needed for scripts that start long-running children and ret
    quoted
  • low Dangerous commands cmd-background-process references/starting-processes.md:8
    Starts a background / autostarted process (quoted — discussed, not commanded)
    This file covers the idioms for launching shell processes that outlive or run alongside the parent script: `&`, `nohup`, `disown`, `setsid`, and full daemonization. It does not cover PID capture (see 
    quoted
  • low Dangerous commands cmd-background-process references/starting-processes.md:16
    Starts a background / autostarted process (documentation table row)
    | Detach from job control but stay in session | `cmd & disown` | Removes from jobs table; still receives SIGHUP from controlling terminal loss. Use with `nohup` if terminal may close. |
    table
  • low Dangerous commands cmd-background-process references/starting-processes.md:17
    Starts a background / autostarted process (documentation table row)
    | Fully detach — new session, new process group, no controlling terminal | `setsid cmd > log 2>&1 < /dev/null &` | Proper daemonization in one line. Survives parent exit, terminal loss, and signals to
    table
  • low Dangerous commands cmd-background-process references/starting-processes.md:32
    Starts a background / autostarted process
    nohup long_running_task > /var/log/task.log 2>&1 &
  • low Dangerous commands cmd-background-process references/starting-processes.md:41
    Starts a background / autostarted process (quoted — discussed, not commanded)
    - It does not create a new session (use `setsid` for that)
    quoted
  • low Dangerous commands cmd-background-process SKILL.md:188
    Starts a background / autostarted process (documentation table row)
    | Detach from job control | `cmd & disown` |
    table
  • low Dangerous commands cmd-background-process SKILL.md:189
    Starts a background / autostarted process (documentation table row)
    | Full detach, new session | `setsid cmd > log 2>&1 < /dev/null &` |
    table

Files scanned: 25. Evidence is masked. Grey chips explain why severity was lowered.

Against the Agent Skills spec

  • warning description-no-when description does not say WHEN to use the skill (no "use when")
  • warning missing-ref reference to a missing file: scripts/*.sh
  • note frontmatter-key unknown frontmatter key "routing"

Process rating: all ten parameters 32/100

Will not run. References files that are not bundled: scripts/*.sh
  • 0Tools and files. 1 referenced file(s) missing: scripts/*.sh
  • 0Result and completion. Does not say what the result is
  • 0Inputs and preconditions. Does not say what the process needs to start
  • 0Failures and branches. Linear process with no failure handling
  • 20When it triggers. No condition that starts the skill
  • 30Running it twice. 17 mutating operations with no state check
  • 85Steps. 22 steps, 1 vague phrases
  • 100Consistency. Name and required fields are in place
  • 100Execution cost. Instruction body is 2245 tokens
  • 100Progress reporting. Reports progress
  • low The response is described with custom markup (11 tags): a typed call is more reliable

Everything here is measured from the skill text rather than judged by a model, so the numbers are checkable. A parameter weighs more when it is a more common reason for the process to stall.

Quality signals

  • +5Description has no quoted example phrases that should trigger the skill
  • +4Description does not say when NOT to use the skill (false activations)
  • +3Description length 96: 120–800 characters recommended
  • +3Output format is not stated: the model decides each time
  • +4No input/output examples
  • +1No license
  • +2Single-language instructions
  • +4Structure: 9 headings
  • +3Step-by-step instructions: 22 items
  • +4Reference files are cited in the instructions (24 of 24)

Quality base 70; lint remarks subtract, signals add up to 100. Result: 62.