Atlas / Skills / maxritter / Blog

BlogBLOCK

skills/maxritter/blog

Professional context and harness engineering for Claude Code and OpenAI Codex. Build production-grade software with spec-driven development, TDD, persistent memory, quality gates, code intelligence, human oversight, and end-to-end verification.

Verdict
BLOCK
Grade
D
Trust score
66 /100
Version
—
Hosts
6 documented
License
NOASSERTION
Stars
2,084
01

Overview

Professional context and harness engineering for Claude Code and OpenAI Codex. Build production-grade software with spec-driven development, TDD, persistent memory, quality gates, code intelligence, human oversight, and end-to-end verification.

Read from source at commit 7e3c9718babeOBSERVED · 2026-10-08
02

Install

Commands as the repository documents them. They are shown, not run.

npm install -g @anthropic-ai/claude-code
npm install -g @anthropic-ai/claude-code &&
uv self update
uv python install 3.14
uv self update
uv python install 3.14
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
claude-desktopmentioned
codexmentioned
copilotmentioned
cursormentioned
openclawmentioned
04

Trust audit

BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (25)

HIGHSupply chain · supply.pipe_to_shell · CWE-829, CWE-1357
pilot/hooks/license_check.py:72
"curl -fsSL https://raw.githubusercontent.com/maxritter/pilot-shell/main/uninstall.sh | bash"
Why it matters. remote content executed unseen
Fix. download, verify a checksum, then run
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
2026-06-09-claude-fable-5-mythos-5.md:42
The safeguard mechanism is worth understanding precisely, because it changes how the model behaves in practice. Fable 5 does not refuse flagged requests. Instead, a separate set of AI classifiers watc
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
2026-06-09-claude-fable-5-mythos-5.md:75
Access is settled too. On **June 12, 2026**, a US government export-control directive forced Anthropic to disable Fable 5 and Mythos 5 for all customers, on subscriptions and on the API alike. Those c
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
2026-06-09-claude-fable-5-mythos-5.md:83
The hardening numbers are meaningful. An external bug bounty found **no universal jailbreaks in over 1,000 hours** of testing. One external partner found Fable 5's cyber safeguards the strongest of an
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
2026-06-09-fable-5-usage-credits.md:151
Two details are worth carrying forward. The June suspension traced to a non-universal jailbreak, essentially asking the model to read a codebase and patch software flaws, and Anthropic shipped a new c
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
2026-07-24-claude-opus-5-vs-fable-5.md:94
Fable 5 was **disabled worldwide on June 12, 2026** under a US export-control directive that required blocking all foreign nationals, which Anthropic could not verify in real time. Access was **restor
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMInventory / provenance · inv.binary · CWE-1104
console/src/services/worker/http/routes/LicenseRoutes.ts
LicenseRoutes.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
console/src/ui/viewer/components/LicenseBadge.tsx
LicenseBadge.tsx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
console/src/ui/viewer/components/LicenseGate.tsx
LicenseGate.tsx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · skill.no_skill_md · CWE-1104
Why it matters. no SKILL.md at the audited path
Fix. a skill without its instruction file cannot be reviewed as one
LOWInventory / provenance · inv.binary · CWE-1104
console/tests/integration/license-recovery-worker.test.ts
license-recovery-worker.test.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
console/tests/server/license-routes.test.ts
license-routes.test.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWContainer / deploy · priv.container · CWE-250, CWE-16
2026-02-03-sandboxing-guide.md:145
**`allowUnixSockets`**: Controls Unix socket access. Be careful: allowing `/var/run/docker.sock` effectively grants host system access through the Docker socket, bypassing sandbox isolation.
LOWContainer / deploy · priv.container · CWE-250, CWE-16
2026-02-03-sandboxing-guide.md:228
The `allowUnixSockets` setting can inadvertently grant powerful access. Allowing `/var/run/docker.sock` gives the sandboxed process full Docker API access, which effectively means host system access.
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
2026-02-03-sandboxing-guide.md:16
Running an AI agent with unrestricted access to your filesystem and network is a liability you can't afford to ignore. Every `npm install` pulls untrusted code. Every build script executes with your u
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
2026-02-21-worktree-guide.md:72
Three isolated sessions, three branches, zero conflicts. Each session has full access to your codebase history but operates on completely separate file trees.
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
2026-03-06-scheduled-tasks.md:23
Desktop scheduled tasks are the primary way to automate recurring work in Claude Code. They run locally on your machine, each firing a fresh session at the time and frequency you choose. Every run has
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
2026-03-20-claude-code-channels.md:27
Send "add the --coverage flag to the test script in package.json" from Telegram. Claude reads the message, makes the change, and replies in your chat. Your session keeps running locally with full acce
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
2026-03-20-claude-code-channels.md:49
| **Local tools** | Full access (filesystem, MCP, git) | Full access (filesystem, MCP, git) | Cloud sandbox only |
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
2025-12-07-infraops-vps-guide.md:42
Start with a fresh Ubuntu server. Most providers give you root access via password. Your first job is making it secure.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
2026-01-24-session-lifecycle-hooks.md:219
Setup hooks also have access to `CLAUDE_ENV_FILE` for persisting environment variables.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
2026-02-03-sandboxing-guide.md:16
Running an AI agent with unrestricted access to your filesystem and network is a liability you can't afford to ignore. Every `npm install` pulls untrusted code. Every build script executes with your u
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
2026-02-03-settings-reference.md:54
- Security policies (deny access to credentials, block destructive commands)
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
2026-02-03-settings-reference.md:81
- Global permission rules (like always denying access to `~/.ssh`)
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
2026-02-16-openclaw-vs-claude-code.md:117
curl -fsSL https://claude.ai/install.sh | bash  # macOS/Linux

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 7e3c9718babefull audit observations/trust-audit/skill/maxritter__blog.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-087e3c9718babeBLOCKD66first audit
06

Questions

What does the Blog skill do?

Professional context and harness engineering for Claude Code and OpenAI Codex. Build production-grade software with spec-driven development, TDD, persistent memory, quality gates, code intelligence, human oversight, and end-to-end verification.

Is Blog safe to install?

No — not without reading the findings first. The audit graded it D (66/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What can Blog access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Blog work with?

Its documentation mentions claude-code, claude-desktop, codex, copilot, cursor and openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (7e3c9718babe), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement