prd-taskmaster — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited prd-taskmaster (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Smart PRD generation with deterministic operations handled by script.py. AI handles judgment (questions, content, decisions); script handles mechanics.
Script location: ~/.claude/skills/prd-taskmaster/script.py All script commands output JSON.
Activate when user says: PRD, product requirements, taskmaster, task-driven development. Do NOT activate for: API docs, test specs, project timelines, PDF creation.
python3 ~/.claude/skills/prd-taskmaster/script.py preflightReturns JSON: has_taskmaster, prd_path, task_count, tasks_completed, tasks_pending, taskmaster_method, has_claude_md, has_crash_state, crash_state.
If `has_crash_state` is true: Present resume options to user:
Then proceed to Step 2.
Use preflight JSON: if prd_path is not null and task_count > 0, an existing PRD is found.
If existing PRD found, use AskUserQuestion:
script.py backup-prd --input <path>)If no PRD found: Proceed to Step 3.
Use preflight JSON field taskmaster_method: mcp, cli, or none.
If `none`: Block and show installation instructions:
npm install -g task-master-aiscript.py detect-taskmasterNo proceeding without taskmaster detected.
Ask detailed questions to build comprehensive PRD. Use AskUserQuestion for structured input.
Essential (5):
Technical (4):
TaskMaster-specific (3):
Open-ended (1):
Smart defaults: If user provides minimal answers, use best guesses and document assumptions.
Only if .taskmaster/ doesn't exist (check preflight has_taskmaster).
python3 ~/.claude/skills/prd-taskmaster/script.py init-taskmaster --method <cli|mcp>For MCP: use the returned params to call mcp__task-master-ai__initialize_project. For CLI: script runs taskmaster init directly.
Load template:
python3 ~/.claude/skills/prd-taskmaster/script.py load-template --type <comprehensive|minimal>Returns JSON with content field containing the template.
AI judgment: Fill template with user's answers from Step 4:
Write completed PRD to .taskmaster/docs/prd.md.
python3 ~/.claude/skills/prd-taskmaster/script.py validate-prd --input .taskmaster/docs/prd.mdReturns JSON: score, max_score, grade, checks (13 items), warnings.
Grading: EXCELLENT (91%+), GOOD (83-90%), ACCEPTABLE (75-82%), NEEDS_WORK (<75%).
AI judgment: If warnings exist, offer user three options:
If grade is NEEDS_WORK, strongly recommend fixing before proceeding.
Calculate task count:
python3 ~/.claude/skills/prd-taskmaster/script.py calc-tasks --requirements <count>Returns recommended task count.
For MCP:
mcp__task-master-ai__parse_prd: input=".taskmaster/docs/prd.md", numTasks=<recommended>, research=true
mcp__task-master-ai__expand_all: research=trueFor CLI:
taskmaster parse-prd --input .taskmaster/docs/prd.md --research --num-tasks <recommended>
taskmaster expand-all --researchpython3 ~/.claude/skills/prd-taskmaster/script.py gen-test-tasks --total <task_count>Returns array of USER-TEST task definitions with title, description, dependencies, template.
For each task in the array:
mcp__task-master-ai__add_task with title, description, details=template, dependencies, priority=hightaskmaster add-task --title="..." --description="..." --dependencies="..." --priority=highpython3 ~/.claude/skills/prd-taskmaster/script.py gen-scripts --output-dir .taskmaster/scriptsCreates 5 scripts: track-time.py, rollback.sh, learn-accuracy.py, security-audit.py, execution-state.py.
Pre-check: Use Glob to check if ./CLAUDE.md exists. If it exists, skip.
If generating:
script.py load-template won't work here -- use Read tool on ~/.claude/skills/prd-taskmaster/templates/CLAUDE.md.template{{PROJECT_NAME}}, {{TECH_STACK}}, {{ARCHITECTURE_OVERVIEW}}{{KEY_DEPENDENCIES}}, {{TESTING_FRAMEWORK}}, {{DEV_ENVIRONMENT}}, {{TEST_COMMAND}}./CLAUDE.mdcodex.md, write identical copyUse AskUserQuestion:
Question: "PRD and tasks ready. How to proceed?"
If Autonomous Execution selected, ask execution mode:
AI judgment: Recommend mode based on context:
If Handoff: Display PRD location, task counts, key requirements, validation score, task phases, user test checkpoints, and TaskMaster commands. Then exit skill.
If Autonomous: Display same summary plus execution mode, then begin execution using the selected mode's rules.
python3 .taskmaster/scripts/track-time.py start|complete <task_id> [subtask_id]python3 ~/.claude/skills/prd-taskmaster/script.py log-progress --task-id <id> --title "..." --duration "..." --subtasks "..." --tests "..." --issues "..."task-{id}-{slug}), sub-branch per subtask, merge to main with checkpoint tagbash .taskmaster/scripts/rollback.sh Xpython3 .taskmaster/scripts/execution-state.py start|complete|checkpoint <task_id>Execute tasks one-by-one. For each task:
Same as sequential but launch up to 3 concurrent independent tasks. Handle merge conflicts automatically. Stop at USER-TEST.
Maximum parallelization (up to 5 concurrent). Auto-complete USER-TEST tasks. Only stop when ALL tasks complete.
Wait for user commands: "next task", "task {id}", "status", "parallel {id1,id2}".
script.py validate-prd at any time to re-check PRD quality~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.