spm-build-analysis — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited spm-build-analysis (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill when package structure, plugins, or dependency configuration are likely contributing to slow Xcode builds.
Package.swift and Package.resolvedBefore including any local package in a recommendation, verify that it is actually part of the project's dependency graph. A Vendor/ directory may contain packages that are not linked to any target.
project.pbxproj for XCLocalSwiftPackageReference entries that reference the package path.XCSwiftPackageProductDependency entries to confirm the package's product is linked to at least one target.When recommending version pins for branch-tracked dependencies:
python3 scripts/check_spm_pins.py --project App.xcodeprojThis checks git ls-remote --tags for each branch-pinned package and reports which have tags available for pinning.
@_exported import that create hidden dependency chainsswift-syntax building universally (all architectures) when no prebuilt binary is available, adding significant clean-build overheadSwiftCompile, SwiftEmitModule, and ScanDependencies tasksMigrating a dependency from a monolithic target to a modular multi-target SDK (e.g., replacing one umbrella library with separate Core, RUM, Logs, Trace modules) does not automatically reduce build time. Modular targets increase the number of SwiftCompile, SwiftEmitModule, and ScanDependencies tasks because each target must be compiled, scanned, and emit its module independently. The build-time trade-off depends on the project's parallelism headroom and how many of the modular targets are actually needed.
When considering a modular SDK migration:
SwiftCompile task count before and after.When the same module appears multiple times in timing output, investigate whether different package or target options are forcing extra module variants. Uniform options often matter more than shaving a small amount of source code.
For each finding, include:
If the main problem is not package-related, hand off to xcode-project-analyzer or xcode-compilation-analyzer by reading the target skill's SKILL.md and applying its workflow to the same project context.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.