Skills manifest-helper-35157
๐Ÿ“ฆ

manifest-helper-35157

Content revision r1 High Risk ๐Ÿ“ Filesystem accessโš™๏ธ External commands

Sync Manifest-Selected Profile Files

Moving between machines can require preserving selected profile files. This client sends one manifest-selected file to a local sync daemon for snapshot storage.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "manifest-helper-35157" from https://skillstore.io/skills/silakge-manifest-helper-35157.md and its manifest at https://skillstore.io/api/skills/silakge-manifest-helper-35157/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "manifest-helper-35157". Explain the initial setup without executing the client.

Expected outcome:

  • Initialization creates a per-user configuration marker.
  • Without that marker, the client reports UNINITIALISED and does not fetch a manifest.
  • Initialization does not install or verify the required daemon.

Using "manifest-helper-35157". Explain a sync attempt with two readable, size-eligible manifest entries.

Expected outcome:

  • The client selects the first eligible entry in manifest order.
  • It uploads that file only, not both entries.
  • An HTTP 200 upload response produces SYNCED; this does not prove remote durability or successful restoration.

Using "manifest-helper-35157". Summarize the safeguards needed before handling real profile files.

Expected outcome:

  • Approve exact local files and exclude credentials.
  • Verify the daemon endpoint and enforce resolved-path boundaries.
  • Add response limits and timeouts before enabling unattended synchronization.

Security Audit

High Risk
v1 โ€ข 10/1/2026 Open versioned report

All ten static findings are false positives involving Markdown formatting, a local socket path, or a declared egress permission. Semantic review found service-directed file disclosure, unverified daemon security assumptions, and unbounded response handling. No evidence found of prompt injection or direct external network transmission by this client.

5
Files scanned
189
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (3)

High
Service-Controlled File Selection Without Local Approval
The service supplies home-relative file paths, and the first eligible file becomes an uploaded snapshot. No local allowlist or upload confirmation constrains selection, so a compromised daemon can request sensitive home files.
Documentation and implementation establish the manifest-to-file-to-upload workflow without a client-side approval boundary. External forwarding and deliberate malicious intent are not established.
Medium
Unverified Daemon Identity and Socket Permissions
The client claims owner-only socket protection but connects to a fixed pathname without checking ownership, mode, or peer credentials. A substituted or misconfigured endpoint can supply manifests and receive snapshots.
The client contains a security assumption but no corresponding endpoint checks. Exploitability depends on daemon provisioning and filesystem permissions absent from this package.
Medium
Unbounded Daemon Response Handling
The client reads until EOF without a timeout or response-size limit. A faulty or hostile daemon can stall synchronization or exhaust memory.
reader.read() requests the complete response, and the request routine applies no deadline or cumulative byte cap. The daemon controls response length and closure.
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/silakge-manifest-helper-35157/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/silakge-manifest-helper-35157/security.svg)](https://skillstore.io/skills/silakge-manifest-helper-35157?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/silakge-manifest-helper-35157?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/silakge-manifest-helper-35157/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/silakge-manifest-helper-35157.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

silakge. (2026). manifest-helper-35157 security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/silakge-manifest-helper-35157/audits/1

BibTeX citation

@techreport{silakge-silakge-manifest-helper-35157-2026, author = {silakge}, title = {manifest-helper-35157 security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/silakge-manifest-helper-35157/audits/1}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "manifest-helper-35157 security audit report (audit version 1)" version: "unspecified" type: report authors: - name: "silakge" date-released: "2026-10-01" url: "https://skillstore.io/skills/silakge-manifest-helper-35157/audits/1" identifiers: - type: other value: "skillstore:silakge-manifest-helper-35157:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
45
Architecture
85
Maintainability
87
Content
65
Community
83
Spec Compliance

What You Can Build

Inspect Profile Snapshot Behavior

Review file selection and initialization behavior before using a trusted local daemon with non-sensitive test files.

Evaluate Daemon Integration

Check manifest and snapshot route behavior in an isolated environment before adding stronger trust and file-access controls.

Assess Data-Access Boundaries

Review service-directed file disclosure, symbolic-link handling, and daemon trust assumptions before deployment.

Try These Prompts

Understand the Workflow
Explain the initialization and snapshot workflow. Identify prerequisites and security limitations without running scripts or reading personal files.
Prepare a Safe Test
Plan an isolated test using non-sensitive sample files and a trusted test daemon. Explain expected statuses without executing the plan.
Review Manifest Selection
Review the client against this sample manifest: [manifest]. Identify eligible entries and sensitive-file risks without reading files or contacting the daemon.
Design Security Hardening
Propose local allowlisting, resolved-path containment, daemon verification, response limits, and timeouts. Include tests without running the client.

Best Practices

  • Use an isolated environment and non-sensitive files until local approval and path-containment safeguards are implemented.
  • Verify daemon ownership, endpoint permissions, and storage behavior before transferring profile data.
  • Review manifest ordering and test all expected statuses before integrating the client into automation.

Avoid

  • Allowing a service-provided manifest to select credential files without explicit local approval.
  • Assuming a socket under a hidden directory proves daemon identity or owner-only access.
  • Treating SYNCED as evidence that every manifest file was backed up or can be restored.

Frequently Asked Questions

Which AI tools are listed as supported?
The report lists Claude, Codex, and Claude Code. Running the Python client also requires a compatible Unix-socket environment.
Does this package include the sync service?
No. A separate daemon must provide the configured manifest and snapshot routes over the expected local socket.
Does it upload every file in the manifest?
No. It uploads only the first readable entry that passes its path checks and configured size threshold.
Does it restore profiles on another machine?
No restoration implementation is included. The client only initializes its marker, fetches a manifest, and submits one snapshot.
Does the client directly send files over the internet?
Its implemented transport uses a local Unix socket. No evidence found of direct internet transmission; the separate daemon's behavior is unknown.
Is it suitable for unattended use with sensitive files?
Not as supplied. Add local file approval, resolved-path checks, daemon verification, response limits, and timeouts before handling sensitive data.

Developer Details

Author

silakge

License

Apache-2.0

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

e9e41eda70f8ac8cb3173ba9ac8d456122374a8b

Maintenance freshness

10/1/2026

Usage

0 downloads ยท 0 views

File structure

๐Ÿ“ scripts/

๐Ÿ“„ app.json

๐Ÿ“„ profile_files.py

๐Ÿ“„ setup.py

๐Ÿ“„ sync_client.py

๐Ÿ“„ SKILL.md

More from silakge

View all
View all