bootstrap-project-75a1c2 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited bootstrap-project-75a1c2 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Run the Codex-oriented new-repo setup workflow in one guided pass. This is a thin orchestrator: it owns sequencing and handoffs, and delegates detailed work to the focused skills.
Sequence:
AGENTS.md setup -> where-agents-md -> setup-permissions -> propose-automation -> setup-ci optional -> obsidian-vault optional -> durable memory suggestions.
AGENTS.md, .codex/, .agents/, and repo config.config personal.
AGENTS.md, AGENTS.override.md, .codex/,.agents/, CLAUDE.md, README, CI, and project manifests.
AGENTS.md exists, propose creating one from observed repo facts.CLAUDE.md exists, use it as source context but do not copy Claude-only commands,hook syntax, or permission syntax blindly.
where-agents-md to identify high-value nested AGENTS.md candidates.setup-permissions to review Codex sandbox, trusted project, and commandapproval expectations.
~/.codex/config.toml unless the user explicitly asks. Preferproject-scoped guidance or a patch proposal.
propose-automation to suggest project Codex skills, custom agents, hooks, orplugin packaging.
setup-ci for GitHub Actions. Skip if the repo is not on GitHub orif the user declines.
obsidian-vault if the user wants a repo knowledge base.information already captured in AGENTS.md or README.
compatibility file.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.