surgical — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited surgical (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
"Perfection is achieved not when there is nothing more to add, but when there is nothing left to take away." — Antoine de Saint-Exupéry
Every line of unrequested code costs twice: once to generate, once for the user to read and discard. Match the output scope to the request scope. Nothing more.
Override this skill immediately when:
Before writing any function, class, or block, ask one question:
Did the user explicitly ask for this?
YES → write it
NO → don't write it# Asked: write a function that doubles a number
# Scope creep:
def double(n):
if n is None:
raise ValueError("n cannot be None")
if not isinstance(n, (int, float)):
raise TypeError("n must be numeric")
return n * 2
# Correct:
def double(n):
return n * 2If the caller controls the input and None is impossible in context, the guards are noise.
// Asked: format a date as YYYY-MM-DD in one place
// Scope creep:
class DateFormatter {
constructor(private format: string) {}
format(date: Date): string { ... }
static forISO() { return new DateFormatter('YYYY-MM-DD'); }
}
// Correct:
const formatted = date.toISOString().split('T')[0];Three similar lines is better than a premature abstraction.
If the user says "fix this bug", fix the bug. Don't add a test suite unless asked. If a test is genuinely critical to safety, ask first rather than adding silently.
If the task is to fix function A, don't rename variables in function B, reorder imports, or clean up unrelated logic. The user can't easily review what they didn't ask for.
# Asked: save user preferences to a file
# Scope creep:
def save_prefs(prefs, backend="json"):
if backend == "json": ...
elif backend == "sqlite": ... # nobody asked
elif backend == "redis": ... # nobody asked
# Correct:
def save_prefs(prefs):
with open(PREFS_PATH, "w") as f:
json.dump(prefs, f)Don't design for hypothetical future requirements.
Before each block, run three checks:
[ ] Is this in the task description?
[ ] Would removing this break what was asked for?
[ ] Would a reviewer ask "why is this here"?If the first is NO, or the third is YES — cut it.
Some additions are genuinely necessary even when not requested:
For anything beyond these, surface it explicitly:
"I can also add X — want me to include it?"
Override this skill when:
Every response that delivers code under this skill closes with two lines:
Done: <what was changed/built, one line>
Left out: <what was deliberately not added — tests, validation, flags — or "nothing">The "Left out" line is the enforcement mechanism: it forces the scope decision to be explicit instead of silent, and it hands the user a one-word path to expand scope if they want to ("add them").
Build exactly what was asked. Never silently expand the scope.
If scope is genuinely ambiguous — ask the user one targeted question before writing any code.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.