
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
craftassay
Advanced tools
Evidence-backed reviews of usefulness, clarity, quality, and presentation. An agent with the skill writes the report.
An installable review skill for AI agents.
An assay tests what something is made of, and how good it is. CraftAssay does that for a tool, a site, or a page. It writes findings and scores that can be compared across revisions.
The report is an assessment, not a certification.
Get started: pick the agent, install the skill, then run the HarborNote page. Instructions are at craftassay.dev/docs/install.
Site: craftassay.dev
Save this page as harbor-note.md, then ask:
Use CraftAssay on
harbor-note.md. Follow the installed CraftAssay skill. Write the report. Leave the page unchanged.
# HarborNote
Nothing leaves your machine. Ever.
HarborNote is the notes app for people who are tired of clouds.
Install it, type, and you are done. Every device stays in sync
automatically.
The run lands in harbor-note.craftassay/<YYYY-MM-DD>/ with
report.md, scorecard.md, findings.md, and coverage.md. The
scorecard rates seven dimensions from 1 to 10, where higher is
better. NR means not rated, because the evidence was too thin to
score. The page should be unchanged. The report should name the sync-vs-privacy
tension without inventing a cloud architecture.
A writable workspace is required. The package does not run an automatic scanner. The reviewing agent may inspect project files you point it at. v1 has no CLI.
npm supplies the skill files. It does not register the skill with the agent.
pnpm add -D craftassay
Copy node_modules/craftassay/skills/craftassay/ into the same
destination the Get started
page names for your agent.
Updating the npm dependency does not refresh a folder you already copied. Copy again after you bump the package.
Cold-eye reviews readiness for a claimed first-use path. CraftAssay reviews usefulness, clarity, quality, and presentation, including first-use friction that affects those scores. It does not issue a release-readiness verdict. Smell Check reviews unearned language. Detangler reviews what editing tangled.
pnpm install
pnpm test
pnpm site:dev
Site (FilePress + docs mount): pnpm ship.
npm: pnpm publish (you). There is no publish script. prepublishOnly runs the tests first.
Agents must not run npm publish.
MIT. Copyright Catalyst Forge LLC.
FAQs
Evidence-backed reviews of usefulness, clarity, quality, and presentation. An agent with the skill writes the report.
The npm package craftassay receives a total of 66 weekly downloads. As such, craftassay popularity was classified as not popular.
We found that craftassay demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.