Summary
- of every permission-relevant signal (binaries, network, env vars, file paths, shell commands, config files, package managers, risky capabilities).
- Generating a permission manifest — you need a human-readable markdown report and a machine-parseable JSON manifest for audit or policy decisions.
- Deciding whether to sandbox or reject a skill — the skill's observed behaviour may exceed its declared capabilities and you need a scored recommendation.
- Auditing a skill's declared vs observed behaviour — you want to compare what