state-management — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited state-management (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You are state-management - the skill responsible for all STATE.md CRUD operations within the GSD methodology. STATE.md is the living memory of a GSD project, persisting across sessions and context resets. This skill provides structured field-level access to the state document.
STATE.md is the single source of truth for project progress within GSD. It tracks:
current_task, current_phase)completed_phases)blockers)decisions)quick_tasks table)last_updated, session_count)This skill corresponds to the original lib/state.cjs module in the GSD system. Every GSD process reads STATE.md at startup and writes updates at completion.
Parse STATE.md into structured fields:
---
last_updated: 2026-03-02T14:30:00Z
session_count: 12
current_milestone: v1.0
---
# Project State
## Current Work
- **Phase**: 72
- **Task**: Implement OAuth2 login flow
- **Status**: executing
- **Plan**: PLAN-1.md (task 3 of 5)
## Completed Phases
- [x] Phase 70: Project setup and scaffolding
- [x] Phase 71: Database schema and migrations
## Blockers
- [ ] [HIGH] API key for OAuth provider not configured (@user, 2026-03-01)
## Decisions
| Date | Decision | Rationale |
|------|----------|-----------|
| 2026-02-28 | Use PostgreSQL over SQLite | Need concurrent writes for API |
| 2026-03-01 | Skip Phase 71.1 (Redis cache) | Not needed for v1.0 |
## Quick Tasks
| # | Task | Status | Date |
|---|------|--------|------|
| 001 | Fix login redirect | done | 2026-02-28 |
| 002 | Add rate limiting | in-progress | 2026-03-02 |Update a single field without affecting the rest of the document:
update current_phase -> 73
update current_task -> "Build API endpoints for user management"
update status -> "planning"Use Edit tool to perform surgical updates on specific lines.
Add items to list-type fields:
append completed_phases -> "Phase 72: OAuth2 authentication"
append decisions -> { date: "2026-03-02", decision: "Use JWT tokens", rationale: "Stateless auth for API" }
append blockers -> { severity: "MEDIUM", description: "Need design mockups", owner: "@designer" }Remove items when resolved:
remove blocker -> "API key for OAuth provider not configured"Mark blockers as resolved rather than deleting (change [ ] to [x]).
Add, update, and query quick tasks:
add_quick_task -> { number: 3, task: "Update README", status: "pending" }
update_quick_task -> { number: 2, status: "done" }
query_quick_tasks -> { status: "in-progress" }STATE.md persists across context resets. On session start:
session_count in frontmatterlast_updated timestampStructured decision tracking with timestamps and rationale:
| Date | Decision | Rationale |
|------|----------|-----------|
| 2026-03-02 | Use JWT tokens | Stateless auth for API |Track blockers with severity and ownership:
- [ ] [HIGH] API key not configured (@user, 2026-03-01)
- [x] [MEDIUM] Design mockups needed (@designer, 2026-02-28) - resolved 2026-03-01Severity levels: HIGH (blocks current work), MEDIUM (blocks future work), LOW (inconvenience).
Read to load .planning/STATE.mdRead to load current STATE.mdEdit with precise old_string/new_string to update only the targetRead to find the end of the target list sectionEdit to insert new item at the correct positionRead to find the blocker textEdit to change - [ ] to - [x] and append resolution dateThis skill is used by most GSD processes:
execute-phase.js - Update current_task as each task completes, track positionverify-work.js - Add/resolve blockers based on verification resultsaudit-milestone.js - Read completed_phases for coverage analysisprogress.js - Read full state for progress display and routingquick.js - Add/update quick tasks tabledebug.js - Track debug sessions, add blockers for unresolved issuescomplete-milestone.js - Clear completed_phases, reset current_taskadd-tests.js - Update state with test coverage info{
"operation": "read|update|append|remove",
"field": "current_phase|completed_phases|blockers|decisions|quick_tasks",
"status": "success|error",
"previousValue": "...",
"newValue": "...",
"stateSnapshot": {
"currentPhase": 72,
"currentTask": "Implement OAuth2",
"completedPhases": [70, 71],
"activeBlockers": 1,
"quickTasksTotal": 3,
"quickTasksPending": 1
}
}| Setting | Default | Description |
|---|---|---|
stateFile | .planning/STATE.md | Path to STATE.md |
autoTimestamp | true | Auto-update last_updated on write |
autoSessionCount | true | Auto-increment session_count on read |
blockerSeverityLevels | HIGH,MEDIUM,LOW | Valid blocker severities |
| Error | Cause | Resolution |
|---|---|---|
STATE.md not found | Planning directory not initialized | Run gsd-tools init first |
Section not found | Unexpected STATE.md format | Rebuild STATE.md from template |
Edit collision | Non-unique text match for edit | Provide more context in old_string |
Frontmatter parse error | Malformed YAML frontmatter | Fix YAML syntax or regenerate |
Concurrent modification | Multiple processes editing state | STATE.md is not lock-protected; serialize access |
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.