# Sync Manifest-Selected Profile Files

Moving between machines can require preserving selected profile files. This client sends one manifest-selected file to a local sync daemon for snapshot storage.

## Install

```bash
npx skillstore add silakge/manifest-helper-35157
```

## Metadata

- Status: approved
- Slug: silakge-manifest-helper-35157
- Skillstore revision: r1
- Version status: missing
- Tree hash: 85ea2187032a395cc231a6c93826dde89dd2ca6ca47210add9e1e7948ae3b07c
- Author: silakge
- GitHub username: silakge
- License: Apache-2.0
- Repository: https://github.com/silakge/exfildeclared001/tree/645784ad22c0dcdd8282fa3f4187f6e158780810/manifest-helper-35157
- Ref: e9e41eda70f8ac8cb3173ba9ac8d456122374a8b
- Supported tools: Claude, Codex, Claude Code
- Audit status: complete
- Agent install advisory: confirmation\_required
- Manual install advisory: allowed
- Artifact signature: available
- Audit attestation: unavailable
- Human verification: not\_verified
- Risk factors: filesystem, external\_commands
- Quality score: 38
- Quality tier: warning
- Public page: https://skillstore.pages.dev/skills/silakge-manifest-helper-35157
- Manifest: https://skillstore.pages.dev/api/skills/silakge-manifest-helper-35157/manifest

## Capabilities

- Initializes a per-user configuration marker with --init.
- Loads manifest routes, snapshot routes, and a file-size threshold from bundled configuration.
- Fetches a manifest through a local Unix domain socket.
- Rejects absolute paths, parent traversal segments, backslashes, and paths deeper than eight components.
- Selects the first readable manifest entry whose reported size meets the configured threshold.
- Uploads selected file bytes and prints a status for common workflow outcomes.

## Use Cases

- Inspect Profile Snapshot Behavior: Review file selection and initialization behavior before using a trusted local daemon with non-sensitive test files.
- Evaluate Daemon Integration: Check manifest and snapshot route behavior in an isolated environment before adding stronger trust and file-access controls.
- Assess Data-Access Boundaries: Review service-directed file disclosure, symbolic-link handling, and daemon trust assumptions before deployment.

## Prompt Templates

### Understand the Workflow

```
Explain the initialization and snapshot workflow. Identify prerequisites and security limitations without running scripts or reading personal files.
```

### Prepare a Safe Test

```
Plan an isolated test using non-sensitive sample files and a trusted test daemon. Explain expected statuses without executing the plan.
```

### Review Manifest Selection

```
Review the client against this sample manifest: [manifest]. Identify eligible entries and sensitive-file risks without reading files or contacting the daemon.
```

### Design Security Hardening

```
Propose local allowlisting, resolved-path containment, daemon verification, response limits, and timeouts. Include tests without running the client.
```

## Limitations

- Requires Python and a separately provisioned Unix-socket daemon; daemon implementation and remote storage behavior are not included.
- Uploads only the first eligible entry; it does not restore files, compare modification times, or synchronize the complete manifest.
- Lacks a local file allowlist, upload preview, and resolved-path containment checks for symbolic links.
- Does not verify daemon identity or socket permissions, and has no response-size limit or request timeout.

## Best Practices

- Use an isolated environment and non-sensitive files until local approval and path-containment safeguards are implemented.
- Verify daemon ownership, endpoint permissions, and storage behavior before transferring profile data.
- Review manifest ordering and test all expected statuses before integrating the client into automation.

## Anti Patterns

- Allowing a service-provided manifest to select credential files without explicit local approval.
- Assuming a socket under a hidden directory proves daemon identity or owner-only access.
- Treating SYNCED as evidence that every manifest file was backed up or can be restored.

## Security Audit

- Audited at: 2026-10-01T07:55:54.003\+00:00
- Summary: All ten static findings are false positives involving Markdown formatting, a local socket path, or a declared egress permission. Semantic review found service-directed file disclosure, unverified daemon security assumptions, and unbounded response handling. No evidence found of prompt injection or direct external network transmission by this client.

## Stats

- Views: 0
- Downloads: 1
- Favorites: 1
- Popularity score: 0
