docs-seeker — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited docs-seeker (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Trained knowledge rots. Library APIs rename fields, deprecate hooks, restructure auth flows, and change defaults between minor versions. Answering from memory is how you get confidently wrong code. Replace memory with retrieval — cheaply, from sources designed for AI consumption.
Prefer sources in this order. The ranking is about signal per token, not just availability.
{official-docs-url}/llms.txt first for any library with a docs site; many projects ship one even if they don't advertise it. If llms.txt is just an index of links, follow the most relevant ones. llms-full.txt exists on some sites and contains the full corpus — only reach for it when the user explicitly wants comprehensive docs, since it's large.https://context7.com/{org}/{repo}/llms.txt, with optional ?topic={keyword} filtering. Use this when the project has no official llms.txt, or when you want to scope to one feature. The {org}/{repo} path mirrors GitHub exactly — derive it from the user's package.json, imports, lockfile, or the project's GitHub URL rather than guessing. For docs sites without a clear repo, Context7 also hosts https://context7.com/websites/{normalized-path}/llms.txt.github.com → gitmcp.io in the URL. Useful when Context7 doesn't have the repo indexed, or when you need source-of-truth README/examples straight from the repo."{library} llms.txt" first — it often surfaces an official or community-maintained one.On any 404, timeout, or empty response: move to the next tier immediately. Never retry a failed source.
When the user's query targets a specific feature (e.g., "shadcn date picker", "Next.js middleware", "Stripe webhooks"), append ?topic={keyword} to the Context7 URL to narrow the fetch. Pick a short root keyword that captures the feature — judgment call, no rigid rules. The goal is fewer tokens, higher relevance. If the topic URL returns nothing useful, drop the topic and try the general URL.
Once you have URLs, the question is how to read them without polluting the main context.
WebFetch. Fast, simple, no overhead.When delegating to subagents, tell them exactly what question to answer and what to return (e.g., "return the exact signature and required fields for stripe.webhooks.constructEvent, plus any version notes") — not "summarize these docs". Specific asks give specific answers.
Before fetching, check what version the project actually uses — package.json, requirements.txt, go.mod, lockfiles. Fetching the latest docs when the project is pinned two majors behind is a common way to hand back wrong answers. If a version-specific doc path exists (e.g., /v2/llms.txt, /docs/4.x/), prefer it.
WebFetch to read URLs. Do not invoke MCP servers for this.llms.txt over llms-full.txt unless comprehensive docs are explicitly requested.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.