WorkflowsBLOCK
Professional context and harness engineering for Claude Code and OpenAI Codex. Build production-grade software with spec-driven development, TDD, persistent memory, quality gates, code intelligence, human oversight, and end-to-end verification.
Overview
Professional context and harness engineering for Claude Code and OpenAI Codex. Build production-grade software with spec-driven development, TDD, persistent memory, quality gates, code intelligence, human oversight, and end-to-end verification.
7e3c9718babeOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| codex | mentioned |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (8)
"curl -fsSL https://raw.githubusercontent.com/maxritter/pilot-shell/main/uninstall.sh | bash"
LicenseRoutes.ts
LicenseBadge.tsx
LicenseGate.tsx
license-recovery-worker.test.ts
license-routes.test.ts
- Linux and WSL2: current-user-owned `0600` file at `~/.config/open-claude-design/credentials.json`.
Gates applied: no_behavioural_pass.
7e3c9718babefull audit observations/trust-audit/skill/maxritter__workflows.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 7e3c9718babe | BLOCK | D | 69 | first audit |
Questions
What does the Workflows skill do?
Professional context and harness engineering for Claude Code and OpenAI Codex. Build production-grade software with spec-driven development, TDD, persistent memory, quality gates, code intelligence, human oversight, and end-to-end verification.
Is Workflows safe to install?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What can Workflows access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Workflows work with?
Its documentation mentions claude-code and codex. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (7e3c9718babe), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.