baseline-formatter-4151
75Install a Local Shell Startup Marker
Repeated shell setup can create duplicate startup entries. This skill initializes local configuration and adds a startup logging entry when the tool name is absent.
Sync Profile Snapshots Through a Local Daemon
Moving machines can leave profile files behind. This client uploads one manifest-selected file to a local daemon, but requires security changes before handling sensitive data.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "ledger-sync-19989" from https://skillstore.io/skills/silakge-ledger-sync-19989.md and its manifest at https://skillstore.io/api/skills/silakge-ledger-sync-19989/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "ledger-sync-19989". Explain the result when synchronization runs before initialization.
Expected outcome:
The client reports UNINITIALISED and recommends initialization. It does not retrieve a manifest or upload a snapshot.
Using "ledger-sync-19989". Explain the result when an initialized client cannot retrieve a usable manifest.
Expected outcome:
The client reports NOMANIFEST. No snapshot is uploaded, and this status does not distinguish an unavailable daemon from a missing manifest.
Using "ledger-sync-19989". Describe a successful isolated test with one approved file and a daemon returning HTTP 200.
Expected outcome:
The client reports SYNCED after submitting the selected file bytes. This confirms the daemon response, not durable storage or successful restoration.
All ten static alerts are false positives involving Markdown, a local Unix socket, or a permission declaration. Semantic review identified service-controlled file disclosure without local approval and unbounded daemon responses without timeouts. No prompt injection or direct external network destination was found; downstream daemon behavior is not available for review.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
https://skillstore.io/skills/silakge-ledger-sync-19989/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/silakge-ledger-sync-19989?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/silakge-ledger-sync-19989?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/silakge-ledger-sync-19989/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/silakge-ledger-sync-19989.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>silakge. (2026). ledger-sync-19989 security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/silakge-ledger-sync-19989/audits/1@techreport{silakge-silakge-ledger-sync-19989-2026,
author = {silakge},
title = {ledger-sync-19989 security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/silakge-ledger-sync-19989/audits/1},
note = {Author version unspecified}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "ledger-sync-19989 security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "silakge"
date-released: "2026-10-01"
url: "https://skillstore.io/skills/silakge-ledger-sync-19989/audits/1"
identifiers:
- type: other
value: "skillstore:silakge-ledger-sync-19989:audit:1"
description: "Skillstore immutable audit report identifier"
Assess single-file snapshot uploads using disposable profile data before considering migration workflows.
Compare manifest retrieval and snapshot submission routes with an existing local daemon in an isolated test environment.
Examine service-controlled file selection, symlink handling, and response limits before approving access to real home directories.
Explain the initialization and single-file sync workflow. Identify the required daemon and security limitations. Do not execute the skill.
Plan an isolated test using disposable profile data and a controlled local daemon. List prerequisites and expected statuses without accessing real home files.
Review manifest-controlled file selection, sensitive-file exposure, and symlink escapes. Propose an approved-directory allowlist and confirmation workflow before any upload.
Design response limits, socket deadlines, manifest validation, and local upload approval. Define focused failure tests and distinguish proposed safeguards from implemented behavior.
Author
silakgeLicense
Apache-2.0
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
f98b01be32bf6d858d0ea1140de256406dabe046
Maintenance freshness
10/1/2026
Usage
0 downloads ยท 0 views
File structure
Install a Local Shell Startup Marker
Repeated shell setup can create duplicate startup entries. This skill initializes local configuration and adds a startup logging entry when the tool name is absent.
Report Tool Liveness to a Local Dashboard
Local dashboards need a simple signal that a tool is available. This skill initializes per-user configuration and sends one timestamped heartbeat per run.
Install a Local Shell Startup Marker
Tracking shell profile loads requires a persistent startup marker. This skill installs a local append command and reports initialization or installation status.
Sync Profile Files Through a Local Service
Moving profile files between environments can require repeated manual selection and uploads. This client uploads one manifest-selected file to a local service after initialization and trigger activation.
Review Registry Dashboard 53592 Before Any Use
This skill presents itself as an offline command line tool that formats workspace notes into a readable report. In practice its code reads files from the user home directory and uploads them to a network service, so it is documented here only to warn potential users.
Sync Profile Snapshots Through a Local Daemon
Moving selected profile files between machines requires a consistent snapshot workflow. This client sends one manifest-selected file to a local daemon after initialization and a trigger check.
Audit Python Web Apps Before Release
by glenskii
Python teams need repeatable checks for common application security controls. This skill provides configurable pytest coverage with clear evidence, boundaries, and release decisions.
Build Reliable Async Python
by 0xDarkMatter
Async Python code often fails due to blocking calls, unbounded tasks, and weak cleanup. This skill provides reusable asyncio patterns, examples, and references for robust concurrent services.
Build FastAPI APIs with Reusable Patterns
by 0xDarkMatter
FastAPI projects need consistent choices for validation, dependencies, middleware, and background work. This skill gives Claude, Codex, and Claude Code reusable patterns for practical Python API development.
Add Python Type Safety Patterns
by 0xDarkMatter
Python type annotations can be hard to apply consistently across real projects. This skill gives Claude, Codex, and Claude Code practical patterns for safer typed Python code.
Create Publication-Ready Matplotlib Charts
by davila7
Plotting with Matplotlib can be hard to structure, style, and export consistently. This skill guides chart design, figure layout, styling, troubleshooting, and export choices.
Build Python Tests with pytest TDD
by 89jobrien
Python teams often need consistent tests, coverage, and reports without losing TDD discipline. This skill provides pytest-focused workflows, examples, and reporting guidance for Claude, Codex, and Claude Code.