init-deep — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited init-deep (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Automatically generates layered context files throughout a project's directory tree, giving AI agents directory-specific knowledge without loading the entire codebase into context.
Create an CLAUDE.md file at each significant directory level:
project/
├── CLAUDE.md # Project-wide: overview, conventions, anti-patterns
├── src/
│ ├── CLAUDE.md # src-specific: architecture, module boundaries
│ ├── api/
│ │ └── CLAUDE.md # API-specific: routes, middleware, auth patterns
│ └── components/
│ └── CLAUDE.md # Component-specific: naming, props, styling
├── tests/
│ └── CLAUDE.md # Test-specific: frameworks, fixtures, patterns
└── infra/
└── CLAUDE.md # Infra-specific: deployment, configs, secretsWhen an AI reads src/api/routes/auth.ts, it automatically picks up context from:
project/CLAUDE.md (project-wide)project/src/CLAUDE.md (source conventions)project/src/api/CLAUDE.md (API patterns).gitignore)Each CLAUDE.md should be:
# PROJECT KNOWLEDGE BASE
## OVERVIEW
[1-2 sentences: what this project is]
## STRUCTURE
[Directory tree with annotations]
## WHERE TO LOOK
| Task | Location | Notes |
|------|----------|-------|
| Add a feature | src/features/ | One dir per feature |
| Fix a bug | src/core/ | Core logic here |
| Add a test | tests/ | Mirror src/ structure |
## CONVENTIONS
- [Naming rules]
- [Pattern rules]
- [Import rules]
## ANTI-PATTERNS
- Do NOT [common mistake 1]
- Do NOT [common mistake 2]
## COMMANDS
[Build, test, lint, deploy commands]--max-depth=N — Limit directory depth (default: 3)--create-new — Only create new files, don't overwrite existingUser: "Set up CLAUDE.md files for this project"
Output: Scans project, generates 6 CLAUDE.md files across the directory tree. Root file has project overview, src/ file has architecture notes, each major subdirectory gets specific conventions and anti-patterns.
Inspired by: oh-my-opencode /init-deep command
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.