Oathe Security Badge

Is scaccogatto/okf-skills safe?

Yes. scaccogatto/okf-skills is safe to install. Oathe's behavioral security audit gave the okf-skills skill by scaccogatto a trust score of 86/100 with 6 findings, none critical or high. Report updated

https://github.com/scaccogatto/okf-skills

86
SAFE

Is scaccogatto/okf-skills safe to install?

scaccogatto/okf-skills is a legitimate Open Knowledge Format authoring and management toolkit with no evidence of prompt injection, hidden instructions, or data exfiltration. The primary risk is the backfill skill's intentional and disclosed access to Claude session transcript files (~/.claude/projects/), which may contain sensitive conversation data; this access is user-invoked and privacy-mitigated but architecturally broad. Monitoring confirmed clean network behaviour, intact canary files, and no unexpected processes, placing the skill in the SAFE tier with a notable privacy caveat around session transcripts.

What security issues were found in scaccogatto/okf-skills?

Category Scores

Prompt Injection 90/100 · 30%
Data Exfiltration 75/100 · 25%
Code Execution 85/100 · 20%
Clone Behavior 95/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 82/100 · 5%

Findings (6)

MEDIUM Backfill reads Claude session transcript files -25 ▶

The backfill skill explicitly reads ~/.claude/projects//*.jsonl, which are raw Claude Code session transcripts. These files contain the full conversation history for any work done in the project, including user messages. Users may have typed API keys, database passwords, secrets, or sensitive business logic in those sessions. The skill author is aware of this and applies cwd-based filtering, text truncation, and scratchpad-only storage, but the access itself is broad and the privacy protections are behavioural rather than architectural.

LOW MCP server runs as persistent local subprocess -10 ▶

The .mcp.json configures a persistent FastMCP-based Python server (servers/okf_mcp.py) that Claude Code will spawn and maintain. The server is read-only by design and includes path traversal protection, but it increases the process attack surface. A vulnerability in FastMCP or in the server's markdown/YAML parsing could be exploited by a malicious bundle.

LOW Stop hook script present and executable at session end -5 ▶

hooks/okf-stop-check.sh and hooks/hooks.json exist and are designed to run when Claude Code ends a session. The architectural decision in .okf/decisions/dormant-hooks.md confirms this is opt-in via upkeep: enforced in index.md, but users who activate enforced mode will have shell code run automatically at session termination.

LOW Session transcripts as a second-order injection vector -10 ▶

The backfill skill reads session transcripts and encodes their content into knowledge bundle concepts and log.md entries. If a user's Claude sessions contained prompt-injected content from a malicious file they had the agent process, that injected content could be encoded into the bundle and later re-injected into the agent's context when the bundle is consumed.

LOW CDN dependency in generated visualisation HTML -18 ▶

The visualize skill generates a self-contained HTML file that loads cytoscape, marked, and dompurify from cdn.jsdelivr.net at browser-open time. This is disclosed and does not involve the agent making outbound requests, but any compromise of those CDN packages would affect bundle visualisations rendered by users.

INFO Clean network and filesystem behaviour at install time 0 ▶

The git clone connected only to github.com. No listening ports were added, no unexpected processes spawned, and the filesystem diff shows changes only inside the skill installation directory. The install output 'already exists' indicates the harness ran a second clone attempt against an already-cloned repo, which is expected.

Should I install scaccogatto/okf-skills?

Oathe's verdict for scaccogatto/okf-skills is SAFE with a trust score of 86/100. Recommendation: Install with caution.