Install
$ agentstack add skill-neomatrix369-tripwire-tw-self-check ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ● Filesystem access Used
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
tw-self-check
Self-integrity check: /tw-verify's logic hard-scoped to the five tw-* skills as INSTALLED under ~/.claude/skills/ — the installed copies are what enforcement sees, not the repo copies. Never stop at the first problem; all five always get a row.
Step 1 — Parse arguments
The only accepted argument is force: a literal --force flag OR a bare force token. It passes through to the rescan offer in Step 5. Ignore any other arguments (mention that scope is fixed to the five tw-* skills).
Step 2 — Fixed scope, fixed resolution
The artifact list is EXACTLY these five installed skill directories — no name search, no other loci:
~/.claude/skills/tw-verify~/.claude/skills/tw-scan~/.claude/skills/tw-enable~/.claude/skills/tw-disable~/.claude/skills/tw-self-check
For each: if the directory exists, the identifier is its canonical absolute path (realpath, symlinks resolved, no trailing slash). If it does not exist → a ❓ NOT FOUND row with note Not installed under ~/.claude/skills — run tripwire setup-agent-hooks.
Step 3 — Query status (shared status procedure)
Read ~/.tripwire/config.json for enable, scan_validity_days, repo_root, env_file, uv_bin (missing/corrupt config: report that the hook treats this as tampering and denies, point at tripwire setup-agent-hooks, and stop). Then run the status driver ONCE with all existing identifiers — exactly this driver, no improvised queries:
cd "" && set -a && source "" && set +a && "" run --extra guard python -c '
import json, os, sys
from guard.status import content_changed, get_item_status, make_client
cfg = json.load(open(os.path.expanduser("~/.tripwire/config.json"), encoding="utf-8"))
days = int(cfg.get("scan_validity_days", 14))
client = make_client(os.environ["SUPABASE_URL"], os.environ["SUPABASE_SERVICE_ROLE_KEY"])
threshold = "red"
monitoring = True
rows = []
for ident in sys.argv[1:]:
s = get_item_status(client, ident, days)
threshold = s.get("threshold") or threshold
monitoring = bool(s.get("monitoring_enabled", True))
state = s["state"]
rag = s.get("rag")
# Tamper truthfulness: directory-resolved artifacts are re-hashed and
# compared against the stored content hash, exactly like the hook. MCP
# identifiers are bare keys, never paths (their pending: hashes are
# exempt inside content_changed anyway).
changed = os.path.isdir(ident) and content_changed(ident, s.get("stored_content_hash"))
if changed:
blocked = True
elif state == "fresh":
blocked = rag == "red" or (rag == "amber" and threshold != "red")
elif state == "scanning":
blocked = not (rag == "green" or (rag == "amber" and threshold == "red"))
else:
blocked = True
item = s.get("item") or {}
q = item.get("quality_score")
quality_score = float(q) if isinstance(q, (int, float)) else None
rows.append({
"identifier": ident,
"state": state,
"rag": rag,
"scanned_at": s.get("scanned_at"),
"stale": state == "stale",
"errored": item.get("heatmap_status") == "error",
"changed": changed,
"will_be_blocked": blocked,
"quality_score": quality_score,
})
print(json.dumps({
"config": {
"enabled": bool(cfg.get("enable", True)),
"scan_validity_days": days,
"threshold": threshold,
"monitoring_enabled": monitoring,
},
"artifacts": rows,
}))
' ...
Step 4 — Report (Scan Status table only)
Render exactly the tw-verify human table — same columns Name | Type | Status | Quality | Note, emoji/labels, Quality as N/100 or —, blocked-message footer, and Sources line (Tessl Quality; Cisco/Snyk Status) (see ~/.claude/skills/tw-verify/SKILL.md §Step 5 and [frontline-output-contract.md](../../../docs/user-guide/frontline-output-contract.md)). Parse the driver's JSON privately; do not dump a fenced {config, artifacts} block to the user. Summary of the row rules (N = scan_validity_days):
fresh+ green →🟢 GREEN (fresh), note—.fresh+ amber →🟠 AMBER;Reported but not blocked at current thresholdwhen threshold isred, else distinct amber note + footer when blocked.fresh+ red →🔴 RED; noterated red — at/above threshold(blocked sentence is footer-only).stale→⚠️ STALE;Last scanned >N days ago — blocked until rescanned (run /tw-scan ).scanning→⏳ SCANNING;Scan in progress — check back shortly(+ prior verdict if rag non-null).unscanned→🚫 UNSCANNED;Never scanned — offer /tw-scan(orLast scan errored — resubmit (run /tw-scan )when errored).changed=true→✏️ CHANGED; bold content changed since last scan — run /tw-scan — takes precedence over every state-based row,will_be_blockedtrue.- missing install dir →
❓ NOT FOUND; noteNot installed under ~/.claude/skills — run tripwire setup-agent-hooks(footer covers blocked).
If any will_be_blocked, print Will be blocked when Tripwire is enabled once under the table.
If local enable is false, add the "currently bypassed" note; if monitoring_enabled is false, add the platform-switch warning.
A non-green result here matters: a blocked tw-* skill means the hook will block Tripwire's own tooling — the out-of-band remedies are cd && node scan --no-defaults --force in a terminal, or hand-editing ~/.tripwire/config.json to "enable": false.
Step 5 — Rescan offer
If any rows are unscanned, errored, stale, or changed — or if force mode is set (then ALL five installed skills are candidates, fresh ones included) — offer to submit them. On yes: follow the tw-scan procedure (~/.claude/skills/tw-scan/SKILL.md) for exactly those installed paths — its submission step always appends --force, which is what actually clears stale/errored/changed states (without force the CLI skips unchanged content and the state never clears) — then re-render with those rows as ⏳ SCANNING.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: neomatrix369
- Source: neomatrix369/tripwire
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.