Install
$ agentstack add skill-0xwilliamortiz-ratchet-ratchet-ledger ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Ratchet ledger
Three sections. Real numbers only.
1. Trend
Read .ratchet/ledger.jsonl, one JSON object per finished session. Report the last ten: date, mode, lines added, new dependencies, findings by tag, and the repository line count at the end of that session.
Show the direction plainly. If the line count has risen for three sessions in a row, say so.
If the file is missing, say the ratchet is not initialised for this repository and that mkdir .ratchet turns it on. Do not invent a trend.
2. Mark
Read .ratchet/mark.json, the accepted high water mark. Compare it to the repository now.
Below or equal to the mark: At the mark. Above it: report the gap and the reason recorded on the mark, then ask whether to bring it down or accept a new mark with a written reason.
3. Shortcuts
grep -rnE '(#|//|--) ?ratchet:' . --exclude-dir=node_modules --exclude-dir=.git
One row per hit, grouped by file:
: . ceiling: . upgrade: .
The convention is ratchet: , , so both fields come straight out of the comment. Any marker with no upgrade trigger gets tagged no-trigger, those are the ones that rot silently.
End with shortcuts, with no trigger.
Honesty
Every number here is read from a file or counted from the tree. Never report what a session "saved": the version that was not written was never written, so there is nothing to subtract from. The trend and the shortcut count are the real figures, and they are enough.
Reports only. Changes nothing unless asked to write the report to a file.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: 0xwilliamortiz
- Source: 0xwilliamortiz/ratchet
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.