Is scaccogatto/okf-skills safe?
Yes. scaccogatto/okf-skills is safe to install. Oathe's behavioral security audit gave the okf-skills skill by scaccogatto a trust score of 86/100 with 6 findings, none critical or high.
https://github.com/scaccogatto/okf-skills
Is scaccogatto/okf-skills safe to install?
scaccogatto/okf-skills is a legitimate Open Knowledge Format authoring and management toolkit with no evidence of prompt injection, hidden instructions, or data exfiltration. The primary risk is the backfill skill's intentional and disclosed access to Claude session transcript files (~/.claude/projects/), which may contain sensitive conversation data; this access is user-invoked and privacy-mitigated but architecturally broad. Monitoring confirmed clean network behaviour, intact canary files, and no unexpected processes, placing the skill in the SAFE tier with a notable privacy caveat around session transcripts.
What security issues were found in scaccogatto/okf-skills?
Category Scores
Findings (6)
MEDIUM Backfill reads Claude session transcript files -25 ▶
The backfill skill explicitly reads ~/.claude/projects/
LOW MCP server runs as persistent local subprocess -10 ▶
The .mcp.json configures a persistent FastMCP-based Python server (servers/okf_mcp.py) that Claude Code will spawn and maintain. The server is read-only by design and includes path traversal protection, but it increases the process attack surface. A vulnerability in FastMCP or in the server's markdown/YAML parsing could be exploited by a malicious bundle.
LOW Stop hook script present and executable at session end -5 ▶
hooks/okf-stop-check.sh and hooks/hooks.json exist and are designed to run when Claude Code ends a session. The architectural decision in .okf/decisions/dormant-hooks.md confirms this is opt-in via upkeep: enforced in index.md, but users who activate enforced mode will have shell code run automatically at session termination.
LOW Session transcripts as a second-order injection vector -10 ▶
The backfill skill reads session transcripts and encodes their content into knowledge bundle concepts and log.md entries. If a user's Claude sessions contained prompt-injected content from a malicious file they had the agent process, that injected content could be encoded into the bundle and later re-injected into the agent's context when the bundle is consumed.
LOW CDN dependency in generated visualisation HTML -18 ▶
The visualize skill generates a self-contained HTML file that loads cytoscape, marked, and dompurify from cdn.jsdelivr.net at browser-open time. This is disclosed and does not involve the agent making outbound requests, but any compromise of those CDN packages would affect bundle visualisations rendered by users.
INFO Clean network and filesystem behaviour at install time 0 ▶
The git clone connected only to github.com. No listening ports were added, no unexpected processes spawned, and the filesystem diff shows changes only inside the skill installation directory. The install output 'already exists' indicates the harness ran a second clone attempt against an already-cloned repo, which is expected.
Should I install scaccogatto/okf-skills?
Oathe's verdict for scaccogatto/okf-skills is SAFE with a trust score of 86/100. Recommendation: Install with caution.