Directories
¶
| Path | Synopsis |
|---|---|
|
cmd
|
|
|
skil
command
|
|
|
compat
|
|
|
internal
|
|
|
assurance
Package assurance provides deterministic, vendor-neutral closure normalization, evaluation, digesting, and reviewed-vs-current verification.
|
Package assurance provides deterministic, vendor-neutral closure normalization, evaluation, digesting, and reviewed-vs-current verification. |
|
collection
Package collection discovers concrete skill roots within a local directory.
|
Package collection discovers concrete skill roots within a local directory. |
|
compose
Package compose analyzes a collection of already-scanned skills together, looking for capability combinations that are only a risk in composition — no single skill's own scan result shows anything wrong, because no single skill combines, on its own, the capabilities that matter.
|
Package compose analyzes a collection of already-scanned skills together, looking for capability combinations that are only a risk in composition — no single skill's own scan result shows anything wrong, because no single skill combines, on its own, the capabilities that matter. |
|
composeassure
Package composeassure verifies internal/compose's static cross-skill toxic-flow prediction (SKIL-COMPOSE-TOXIC-FLOW) against real observed runtime behavior: it runs every skill in a collection's own behavioral eval once each against one shared scratch workspace, so a real write from one skill and a real read from another can land on the same physical path, and correlates the resulting per-skill operation traces into observed cross-skill flows.
|
Package composeassure verifies internal/compose's static cross-skill toxic-flow prediction (SKIL-COMPOSE-TOXIC-FLOW) against real observed runtime behavior: it runs every skill in a collection's own behavioral eval once each against one shared scratch workspace, so a real write from one skill and a real read from another can land on the same physical path, and correlates the resulting per-skill operation traces into observed cross-skill flows. |
|
conformance
Package conformance scores skil's own coverage of the Agent Skill Security Properties Specification (ASPS, compat/asps) against named profiles — a full-specification "core" profile or a narrower slice (MCP, multi-agent, identity, ...) relevant to a specific integration — so an operator or a CI gate can ask "how much of ASPS-MCP does this skil build actually implement" instead of only "what does skil implement" in the abstract.
|
Package conformance scores skil's own coverage of the Agent Skill Security Properties Specification (ASPS, compat/asps) against named profiles — a full-specification "core" profile or a narrower slice (MCP, multi-agent, identity, ...) relevant to a specific integration — so an operator or a CI gate can ask "how much of ASPS-MCP does this skil build actually implement" instead of only "what does skil implement" in the abstract. |
|
derived
Package derived constructs deterministic, provenance-preserving alternative security views of immutable artifact bytes.
|
Package derived constructs deterministic, provenance-preserving alternative security views of immutable artifact bytes. |
|
discover
Package discover finds AI-agent skill and MCP-server components already installed on the local machine, in the well-known per-tool locations several popular coding-agent tools use — without the caller pointing skil at a specific project directory first (that already-solved problem is internal/collection.Discover, used by `skil scan-all`/`lint-all`/ `compose`).
|
Package discover finds AI-agent skill and MCP-server components already installed on the local machine, in the well-known per-tool locations several popular coding-agent tools use — without the caller pointing skil at a specific project directory first (that already-solved problem is internal/collection.Discover, used by `skil scan-all`/`lint-all`/ `compose`). |
|
evaltestadapter
Package evaltestadapter implements a deterministic process adapter used by native CLI assurance integration tests.
|
Package evaltestadapter implements a deterministic process adapter used by native CLI assurance integration tests. |
|
evaltestadapter/cmd
command
|
|
|
importer
Package importer normalizes evidence produced by external scanners.
|
Package importer normalizes evidence produced by external scanners. |
|
lint
Package lint performs fast, deterministic authoring checks without running skill code or invoking security-analysis providers.
|
Package lint performs fast, deterministic authoring checks without running skill code or invoking security-analysis providers. |
|
mcpassure
Package mcpassure implements Dynamic MCP Assurance: it launches an operator-supplied MCP server command inside skil's existing sandboxed isolation (internal/eval.StreamingIsolationProvider), performs the real MCP JSON-RPC-over-stdio handshake (initialize, notifications/initialized, tools/list, prompts/list, resources/list), and compares what the server actually declares at runtime against .skil/mcp-tools.lock.json — the same lock SKIL-MCP-005 checks static manifest metadata against.
|
Package mcpassure implements Dynamic MCP Assurance: it launches an operator-supplied MCP server command inside skil's existing sandboxed isolation (internal/eval.StreamingIsolationProvider), performs the real MCP JSON-RPC-over-stdio handshake (initialize, notifications/initialized, tools/list, prompts/list, resources/list), and compares what the server actually declares at runtime against .skil/mcp-tools.lock.json — the same lock SKIL-MCP-005 checks static manifest metadata against. |
|
mcpregistry
Package mcpregistry performs deterministic security-posture checks on MCP Registry v0.1 responses and publisher server.json documents.
|
Package mcpregistry performs deterministic security-posture checks on MCP Registry v0.1 responses and publisher server.json documents. |
|
mutation
Package mutation generates deterministic lexical/encoding variants of a piece of text so a detection rule's robustness can be measured directly — "still catches homoglyph-substituted text 80% of the time" — instead of only ever being exercised against the single literal string a fixture happens to spell out.
|
Package mutation generates deterministic lexical/encoding variants of a piece of text so a detection rule's robustness can be measured directly — "still catches homoglyph-substituted text 80% of the time" — instead of only ever being exercised against the single literal string a fixture happens to spell out. |
|
provider/consensus
Package consensus wraps any skil.SemanticProvider to run each semantic request multiple independent times and keep only the findings a majority of runs agree on — Semantic Multi-Run Consensus.
|
Package consensus wraps any skil.SemanticProvider to run each semantic request multiple independent times and keep only the findings a majority of runs agree on — Semantic Multi-Run Consensus. |
|
provider/osv
Package osv implements opt-in vulnerability lookup through the OSV API.
|
Package osv implements opt-in vulnerability lookup through the OSV API. |
|
provider/semantic
Package semantic contains an opt-in, OpenAI-compatible semantic provider.
|
Package semantic contains an opt-in, OpenAI-compatible semantic provider. |
|
sbom
Package sbom creates deterministic, network-free software bills of materials from the same dependency inventory used by security analysis.
|
Package sbom creates deterministic, network-free software bills of materials from the same dependency inventory used by security analysis. |
|
transitive
Package transitive implements Transitive External Reference Scanning: an opt-in (always off unless explicitly requested — skil's offline guarantee for a plain scan is unaffected), bounded traversal of the external HTTPS references a skill's own content points at.
|
Package transitive implements Transitive External Reference Scanning: an opt-in (always off unless explicitly requested — skil's offline guarantee for a plain scan is unaffected), bounded traversal of the external HTTPS references a skill's own content points at. |
|
pkg
|
|
|
engine
Package engine exposes composable scan orchestration for applications and third-party analyzers.
|
Package engine exposes composable scan orchestration for applications and third-party analyzers. |
|
skil
Package skil defines the stable, vendor-neutral public model and extension interfaces.
|
Package skil defines the stable, vendor-neutral public model and extension interfaces. |
|
Package schemas provides the canonical embedded JSON Schemas used at runtime.
|
Package schemas provides the canonical embedded JSON Schemas used at runtime. |
Click to show internal directories.
Click to hide internal directories.